CASE STUDY / INFRASTRUCTURE & SECURITY

Home Lab Infrastructure.

A continuously evolving Proxmox-based environment where I operate real services, automate maintenance, validate recovery, troubleshoot failures, monitor systems, and practice secure infrastructure administration.

PLATFORMPROXMOX VE
MANAGEMENTLINUX + ANSIBLE
STORAGETRUENAS + ZFS
FOCUSOPERATIONS + SECURITY
01

Overview

Zaman Labs is the environment I use to turn cybersecurity and infrastructure concepts into operating experience. The lab combines virtualization, Linux systems administration, storage, DNS, reverse proxying, monitoring, infrastructure automation, backup validation, and controlled remote administration.

Rather than treating the lab as a collection of isolated services, I use it to practice the full lifecycle of infrastructure: deployment, maintenance, troubleshooting, security review, documentation, recovery planning, and verification after changes.

The environment is intentionally iterative. Services, automation, and controls are improved as I identify operational weaknesses, failure modes, and opportunities to make the system more repeatable and easier to recover.

02

Architecture & operations

01 / VIRTUALIZATION

Proxmox platform

Proxmox VE hosts isolated virtual machines and Linux containers for management, DNS, monitoring, media, dashboards, secure ingress, and other internal services.

02 / STORAGE

TrueNAS & ZFS

TrueNAS provides bulk network storage using ZFS, with SMB/CIFS and NFS supporting workloads that need persistent shared storage.

03 / AUTOMATION

Ansible maintenance

An AlmaLinux management VM centralizes administrative workflows. Ansible standardizes updates, health checks, service validation, backup checks, and controlled reboots across 11 managed hosts.
Verification: Reviewed execution results and identified failed services for follow-up.
playbook documentation

04 / OBSERVABILITY

Monitoring stack

Prometheus and Grafana provide infrastructure metrics and dashboards, while Uptime Kuma tracks service availability and Homepage provides a centralized internal service view.

03

Security, recovery & troubleshooting

SECURITY REVIEW

Linux access controls

Reviewed sudo, firewall, and SSH configurations across two Linux VMs to identify overly broad administrative access.
Verification: Configuration review uncovered unrestricted passwordless root access and overly broad SSH permissions, establishing specific findings for remediation.
SSH documentation

BACKUP VALIDATION

11 of 11 guests verified

Checked guest backups and documented disaster-recovery readiness and remaining recovery risks.
Verification: Completed integrity checks for 11 of 11 guest backups. This result records backup integrity, not a completed restore test.
backup setup documentation

SERVICE RECOVERY

systemd dependency failure

Resolved a startup failure by correcting systemd dependencies and adding authenticated SMB/CIFS storage checks.
Verification: A successful reboot confirmed recovery from the startup failure.
SMB setup documentation

DNS TROUBLESHOOTING

Forwarding-loop recovery

Identified a forwarding loop and added the required authoritative record to restore internal DNS resolution.
Verification: Successful DNS server and router responses confirmed that resolution had recovered.
DNS setup documentation

SECURE ACCESS

Nginx reverse proxy

Migrated Jellyfin access behind an Nginx reverse proxy on Ubuntu Server.
Verification: Verified HTTPS using a valid Let's Encrypt TLS certificate.
security documentation

04

Automation & controlled operations

01 / INFRASTRUCTURE AS CODE

Terraform

Terraform is used for repeatable Proxmox workload provisioning so infrastructure definitions can be reviewed, reproduced, and maintained as code.
workflow documentation

02 / CONFIGURATION

Ansible

Ansible reduces one-off administrative work by applying repeatable maintenance and validation workflows across heterogeneous Linux systems.
playbook documentation

03 / AI OPERATIONS

Hermes Agent

Hermes Agent runs on a dedicated Ubuntu Server VM and connects to the management environment for read-only-first investigation, documentation, and approval-gated maintenance workflows.
setup documentation

04 / CHANGE DISCIPLINE

Verify after changes

Changes are treated as operational work: investigate first, preserve rollback options, make scoped modifications, and verify service health afterward.

05

Technology stack

Proxmox VELinuxAlmaLinuxDebianUbuntu ServerTrueNASZFSSMB/CIFSNFS
AnsibleTerraformBashGitPrometheusGrafanaUptime KumaTechnitium DNSNginxCloudflare Tunnel