Personal lab
Hybrid on-prem infrastructure & secure remote access lab
Proxmox cluster, Active Directory and a WatchGuard perimeter, linked to AWS over IPsec with automatic DR failover. Legacy client VPN replaced by Cloudflare Zero Trust.
- Proxmox
- Active Directory
- WatchGuard
- IPsec VPN
- Cloudflare Zero Trust
- Terraform
- Ansible
Why a lab
Most of my day job is cloud-native, but a lot of real infrastructure is still hybrid: identity in Active Directory, a physical firewall at the edge, VPNs into a VPC, and a remote-access story that has to work for people who aren’t engineers. I built this lab to run that whole stack end to end, from bare-metal virtualization up to identity-based access.
Compute & storage
- A Proxmox VE cluster on ZFS storage, with cloud-init VM templates.
- VMs provisioned with Terraform and configured with Ansible, so rebuilding a host is a pipeline run, not a checklist.
- Scheduled backups to Proxmox Backup Server.
Identity
- Active Directory on Windows Server with two domain controllers, plus DNS, DHCP, OUs, GPOs and security groups.
- Linux hosts joined to the domain with realmd / SSSD, so there’s one identity source for both Windows and Linux.
Perimeter & VPN
- A WatchGuard Firebox as the perimeter firewall: VLAN segmentation, NAT and firewall policies.
- Mobile VPN (IKEv2) for users, authenticated against AD through RADIUS / NPS.
- A site-to-site IPsec VPN (WatchGuard BOVPN) from on-prem to an AWS VPC.
- A DR tunnel to a secondary region with automatic failover. The failover runbook is documented and tested.
Zero Trust remote access
The legacy client VPN for internal apps was replaced with Cloudflare Zero Trust:
- WARP client enrollment for users.
- Cloudflare Tunnel (
cloudflared) for internal apps. The tunnel is outbound-only, so the firewall exposes no inbound ports. - Identity-based Access policies through Okta.
- Gateway DNS filtering.
Stack
Proxmox VE · Proxmox Backup Server · ZFS · Terraform · Ansible · Windows Server / AD DS · realmd / SSSD · WatchGuard Firebox · IPsec (BOVPN) · RADIUS / NPS · Cloudflare Zero Trust (WARP, Tunnel, Access, Gateway) · Okta · AWS VPC