Bare-Metal Topology & Systems
Kubernetes Homelab
3-node bare-metal Kubernetes cluster (humberto, dosberto, tresberto) managed declaratively via GitOps with Argo CD, Oracle VPS WireGuard hybrid ingress, and resilient ZFS RAID-1 storage.
Bare-Metal Infrastructure
Physical Server Nodes
Live Status
Dedicated Hosts
3 Nodes
100% etcd Quorum
28 vCPUs
Intel 6th • 7th • 13th Gen
3.6 TB
ZFS RAID-1 (2x 4TB HDDs)
#tresberto
03
Compute & Storage Primary
Controller + Worker
Chassis
Custom Tower Server x86_64
13th Gen Intel Core i5-13500 (14C/20T: 6P+8E)
1TB Kingston NVMe + 2x 4TB Seagate IronWolf
#humberto
01
Controller + Worker Intel Core i3-6100U (2C/4T @ 2.30 GHz)
128 GB Kingston SSD (Boot & Local OS)
#dosberto
02
Controller + Worker Intel Core i5-7260U (2C/4T @ 2.20 GHz)
128 GB Kingston SSD (Boot & Local OS)
Silicon Labs Zigbee 3.0 Coordinator
Data Sovereignty & Privacy
Zero Vendor Lock-In: Self-Hosted Cloud Alternatives
Google Photos → Immich
Self-hosted photo and video backup running on bare-metal with local OpenVINO machine learning pipelines for automated face recognition and CLIP semantic search.
Zero cloud telemetry, zero subscription fees, and complete media privacy.
Nextcloud
replaces Google Drive
100% data sovereignty hosted on local ZFS storage pools.
Vaultwarden
replaces 1Password
Master passwords and vaults never touch third-party cloud infrastructure.
MinIO
replaces AWS S3
Standardized S3 API with zero egress bandwidth charges.
CloudNativePG
replaces AWS RDS
Production-grade HA database without managed database lock-in.
AdGuard Home
replaces Cloudflare 1.1.1.1
Blocks trackers across all IoT devices without client configuration.
Storage Subsystem
3-Tier Storage Engine
Durable block storage • NVMe cache • ZFS RAID-1 mirrors
Tier 01 Direct Local SSD
local-path Provisioner Host SSD Folders • Node SSDs
Direct SSD I/O for PostgreSQL & local DBs
Tier 02 HA 3-Replica
Longhorn Block Storage Replicated HA Block • 3-Node Quorum
Synchronous 3-node replica failover & snapshots
Tier 03 3.6 TB ZFS RAID-1
ZFS Mass Storage Pool RAID-1 Mirror (2x 4TB) • tresberto (/media/zfs)
Resilient mass storage for Immich photos & docs
Reliability & Telemetry
Observability as Code
Declarative PrometheusRules • Grafana ConfigMaps • Telegram dispatch
Declarative Grafana Node Exporter • K8s Workloads • ZFS Telemetry
ConfigMap provisioned via GitOps
PrometheusRules & SLOs Node Pressure • Pod CrashLoops • SMART Disks
Standardized declarative Alertmanager
Telegram Real-Time Alerts Instant Delivery • Firing & Resolved States
Direct Telegram bot contact points
Cluster Workloads
Workloads Directory
34 containerized applications in production
Security & Edge Ingress Triple Gateway API (vps-ingress, cloudflare-tunnel & internal) Oracle VPS TCP SNI passthrough bastion Automated Let's Encrypt TLS via DNS-01 webhook Dual sync: Public VPS (Bypass) & Cloudflare Tunnel (Zero Trust) Layer 2 VIPs (.201 external / .200 internal) Bitwarden-compatible self-hosted password vault Network DNS sinkhole & encrypted upstream DoH Asymmetric GitOps secret decryption controller
Data Sovereignty & Storage Local OpenVINO AI face recognition & CLIP search Document sync, calendars, and private file storage High-throughput local S3-compatible object storage High-availability PostgreSQL with S3 WAL archiving Synchronous 3-replica distributed block storage
Observability & Alerting Prometheus & Alertmanager Node & pod metrics with Telegram alerts Centralized dashboards & structured cluster logs Real-time automated service health checks & SLA Direct SMART hard-drive health telemetry
GitOps Lifecycle & Automation Declarative sync-waves & automated reconciliation Bare-metal OS provisioning, microcode & ZFS setup Disruption-free live kernel upgrades & node reboots Automated dependency updates via PR verification © 2026 Carlos Sánchez Páez • cspaez.org