Enterprise Architecture Case Study

Enterprise-Grade
Self-Hosted Hybrid Cloud

A distributed, high-availability virtualization and autonomous AI laboratory engineered to enterprise reliability standards. Combining bare-metal hypervisors, distributed event queuing, zero-trust edge proxies, multi-terabyte storage pooling, and closed-loop automated self-healing.

Proxmox VE 8.x GitOps & Ansible Vault Traefik v3 & Authelia SSO LangGraph & Local LLMs MergerFS NAS Pool Homelab Central App Topology & Service Flows Roadmap & Backlog

4

Physical Compute Nodes

20+

Managed Microservices

6.9 TB

Hybrid Storage Fabric

100%

Automated Self-Healing

Architectural Philosophy

Core Engineering Pillars

GitOps & Single Source of Truth

All configurations, Docker Compose stacks, Traefik dynamic routes, and Ansible automation playbooks are version-controlled in Git. The infrastructure is tracked by a master executable lab specification and an indexed knowledge graph, eliminating configuration drift across all physical and virtual nodes.

Declarative Compose Ansible Vault Master Spec

Zero Trust & Perimeter Edge Ingress

A centralized perimeter reverse proxy powered by Traefik v3 and Authelia enforces Forward Authentication, OIDC (OpenID Connect), and Multi-Factor Authentication (TOTP / WebAuthn). Cloudflare DNS challenges manage automated wildcard SSL certificates, ensuring no internal administrative dashboard is directly exposed.

Traefik v3 Edge Authelia MFA/SSO Wildcard SSL

Distributed AI & Secure Sandboxing

Distributed workflow execution across multiple compute nodes via a RabbitMQ message bus. An asynchronous n8n cluster leverages dedicated, isolated LXC sandboxes to safely execute AI-generated Python and shell code. Multi-agent DAGs run on LangGraph with LangSmith tracing, complemented by local Ollama/DeepSeek inference.

RabbitMQ Broker LXC Code Sandbox LangGraph DAGs

Closed-Loop Automated Self-Healing

Full telemetry ingestion with Prometheus, cAdvisor, and Loki. When a service degradation is detected by 24/7 edge probing, an automated remediation pipeline pulls the trailing log buffer, performs LLM root-cause triage, and triggers target Ansible playbooks to self-heal without human intervention.

Prometheus & Loki LLM Triage Ansible Self-Heal
Bare-Metal Fleet

Physical Hardware Inventory

Four dedicated bare-metal computing nodes operating in synchronized orchestration across physical compute, NAS storage, and edge resilience.

NODE 1 AMD Ryzen 6C/12T

Mini PC Primary

Proxmox VE 8.x • Core Host

  • Memory: 24 GB DDR4
  • Boot/Root: Dual 512GB NVMe
  • Bulk Storage: 4TB + 2TB NAS HDDs
  • Role: VMs, NAS, Edge LXC
Hosts Core Docker, PostgreSQL, RabbitMQ, and Storage Pool.
NODE 2 Intel Core 8C/8T

OptiPlex Compute

Proxmox VE 8.x • AI Cluster

  • Memory: 16 GB DDR4
  • Storage: 512 GB High-Speed NVMe
  • Execution: Privileged Sandboxes
  • Role: AI DAGs, LangGraph
Dedicated AI execution sandboxes and multi-agent DAGs.
NODE 3 BCM2711 4C ARM64

Raspberry Pi 4B

Debian • Edge Diagnostics

  • Memory: 4 GB LPDDR4
  • Storage: 120 GB SSD (USB 3.0)
  • RAM Disk: log2ram 256MB
  • Role: Primary DNS, Probing
AdGuard Home, 24/7 Uptime Kuma probing, WatchYourLAN ARP.
NODE 4 BCM2711 4C ARM64

Raspberry Pi 4B

Debian • Mesh VPN & UX

  • Memory: 4 GB LPDDR4
  • Storage: 120 GB SSD (USB 3.0)
  • VPN: Tailscale WireGuard
  • Role: Dashboards, IoT Mock
Unified telemetry portals, WireGuard mesh, and IoT simulation.
Central Control Plane • Bespoke Full-Stack Gateway

Homelab Central: The Unified Command App

While Proxmox VE governs bare-metal hypervisors and Portainer handles raw container sockets, Homelab Central was custom-engineered from the ground up as a bespoke Next.js 16 & React 19 command center. It unifies operations across all 4 compute nodes, 20+ microservices, autonomous AI agents, and custom IoT hardware into a single intuitive control interface.

Homelab Central v1.0 Production

Unified Gateway • Next.js 16 App Router • React 19
ALL SYSTEMS NOMINAL • 4 NODES ONLINE
Overview App Catalog Plant Manager Hermes AI Agent API Keys & Quotas Telemetry Metrics

App Catalog & Service Directory

Dynamic inventory indexing 30+ services across Docker, LXC, and VMs. Categorized by tier (Infrastructure, AI, Security, Storage, Telemetry) with real-time health pings and single-click authenticated deep-links via Traefik & Authelia.

Zero-Trust SSO Live Health Checks

Plant Manager & Hardware IoT

Direct telemetry ingestion from custom-designed ESP32 microcontroller nodes. Visualizes soil moisture capacitive curves, ambient temperature, humidity, and triggers automated solenoid irrigation valves with safety shut-off limits.

ESP32 Telemetry MQTT Automated Valves

Project Hermes AI Operations

Mission control for the autonomous Hermes agent VM. Tracks active web intelligence scraping jobs, recurring agent tasks, LLM execution pipelines, and displays real-time execution logs and Telegram dispatch notifications.

Autonomous Agents Playwright Scraping

AI Model & Token Consumption

Real-time observability of token velocity, context saturation, and API credit ceilings. Monitors local Ollama inference clusters (Llama 3, DeepSeek) and cloud routing gateways (OpenRouter) to prevent quota starvation.

Ollama Local Tokens OpenRouter Quota Caps

Consolidated Resource Telemetry

Aggregates Prometheus time-series metrics, cAdvisor container load, and node-exporter telemetry across all 4 bare-metal hosts. Displays live CPU load, DDR4 saturation, NVMe flash IOPS, and network throughput graphs.

Prometheus & cAdvisor Uptime Kuma Probes

Automations & Self-Healing Triggers

Direct execution tracking for n8n workflow queues and RabbitMQ event pipelines. Features manual dispatch triggers for Ansible self-healing playbooks, maintenance wave reboots, and storage scrubbing jobs.

n8n Execution Queue Ansible Manual Dispatch
Architectural Blueprint & Service Topology

System Topology & Service Flow Architecture

An end-to-end interactive blueprint detailing how traffic flows from edge ingress, through the Homelab Central command plane, across bare-metal compute hosts, isolated Virtual Machines (VMs), lightweight LXC containers, and Docker microservices.

Zero-Trust Perimeter Ingress

Edge Gateway & TLS 1.3 Termination
INGRESS TIER
Traefik v3
Reverse proxy with automated Let's Encrypt wildcard SSL
Authelia SSO
Forward-Auth multi-factor single sign-on boundary
Tailscale Mesh
End-to-end WireGuard zero-trust private subnet mesh

Homelab Central Control Plane

Next.js 16 • React 19 • Telemetry Gateway
CONTROL TIER
Central App
Bespoke full-stack command deck on Port 3010
n8n Core
Automated workflow engine & incident triage orchestrator
RabbitMQ
Asynchronous message broker & worker event distribution
Distributed Compute & Storage Matrix (4 Bare-Metal Nodes)
VM LXC Docker
NODE 01

Skullsaints Mini PC

Proxmox VE 8.x • AMD Ryzen 6C/12T • 24GB DDR4 • NVMe + 6TB SATA
Core Manager
Virtual Machines (VM)
main-server VM • 6GB

Core Automation & Local AI Docker Host

n8n core n8n worker ollama cadvisor promtail docksentry
hermes-agent-vm VM • 4GB

Hermes Autonomous AI Agent Platform

hermes-gateway task-scheduler
home-assistant VM • 2GB

Home Assistant Supervised OS Core

zigbee / z-wave mqtt broker
omv-node1 (NAS) VM • 4GB

5.4TB Unified MergerFS Storage Pool

mergerfs pool snapraid samba
LXC Lightweight Containers
edge-router-lxc
Traefik v3 & Authelia SSO
1GB RAM
database-lxc
PostgreSQL 17 & Redis 7
1GB RAM
monitoring-lxc
Prometheus, Grafana, Loki
1.5GB RAM
NODE 02

Dell OptiPlex Compute

Proxmox VE 8.x • Intel Core 8C/8T • 16GB DDR4 • 512GB NVMe
AI & Sandboxes
Virtual Machines (VM)
utility-vm VM • 5GB RAM • 3 vCPU

Compute & Interface Docker Workloads

open-webui portainer-server meshcentral flowise ai cadvisor
Isolated Execution LXCs
n8n-sandbox-lxc
Privileged AI Code Execution Sandbox (Python / Shell)
4GB RAM • 4 vCPU Zero Host Access
dsh-lxc (DeepSeek)
Dedicated DeepSeek Harness Agent Runtime
2GB RAM • 2 vCPU dsh-webui
NODE 03

Raspberry Pi 4B #1

Debian Bookworm • 4C ARM64 • 4GB LPDDR4 • SSD Boot • log2ram
Edge Diagnostics

Dedicated, low-power edge guardian running 24/7 network inspection, primary recursive DNS, and health probing.

AdGuard Home
Primary HA recursive DNS & adblocking
Uptime Kuma
24/7 edge health probes & heartbeats
WatchYourLAN
ARP scan & rogue device discovery
UpSnap
Wake-on-LAN cluster management
MySpeed
Automated ISP bandwidth telemetry
OliveTin
Shell execution webhook dispatcher
NODE 04

Raspberry Pi 4B #2

Debian Bookworm • 4C ARM64 • 4GB LPDDR4 • SSD Boot • log2ram
UX & Mesh Node

Host for the primary Homelab Central control plane application, WireGuard mesh routing, and telemetry dashboards.

Homelab Central
Next.js 16 fleet control dashboard
Tailscale Mesh
Subnet router & WireGuard mesh exit
Homepage & Homer
Static fallback service portals
Portainer Agent
Node telemetry socket forwarder
Node Exporter
ARM64 CPU/RAM Prometheus metrics
Autoheal
Local unhealthy container recycling

Inter-Service Data, Control & Telemetry Flows

Event Loops • Authentication Paths • AI Pipelines
4 Active Pipelines
FLOW 01: Secure Ingress & Zero-Trust Authentication

Client requests hit Traefik v3 over TLS 1.3. Traefik triggers a Forward-Auth query to Authelia in edge-router-lxc. Once 2FA is validated, requests proxy to target services across Node 1, 2, or 4 over internal isolated virtual bridge networks.

User → Traefik v3 → Authelia SSO (Verify) → Target VM/LXC Service
FLOW 02: Central Control & Fleeting Fleet Telemetry

Homelab Central (hosted on Node 4) queries the Proxmox VE cluster API, Prometheus TSDB, and Docker sockets via Portainer agents. Aggregates live system health, manages IoT plant sensor queues, and controls AI agent task schedules.

Homelab Central → Proxmox API + Docker Sockets + Prometheus → Real-Time Telemetry
FLOW 03: Autonomous AI Agent Execution & Sandbox

Hermes agent or n8n dispatches tasks to RabbitMQ. Code execution workloads run in the privileged n8n-sandbox-lxc container, while inference requests stream to local Ollama (Llama 3/DeepSeek) on hot NVMe storage.

Hermes / n8n → RabbitMQ Bus → Isolated LXC Sandbox ↔ Local Ollama LLM
FLOW 04: Closed-Loop Telemetry & Autonomous Remediation

Uptime Kuma or Alertmanager flags non-200 responses. Webhook dispatches to n8n Lab Medic, which pulls Loki logs, runs LLM root-cause triage, and triggers target Ansible playbooks to recycle containers with MTTR < 45s.

Edge Probe Alert → n8n Lab Medic → Loki Log Extraction → Ansible Self-Healing
Virtualization Architecture

Proxmox VE Guest Topology

Segmentation between isolated Virtual Machines (VMs) for heavy workloads and unprivileged LXC containers for zero-overhead performance.

VM

Core Automation Host

4 vCPU • 6 GB RAM • NVMe

Primary Docker host running n8n Core orchestrator, RabbitMQ enterprise message broker, AnythingLLM, Promtail, and cAdvisor metrics.

n8n Core RabbitMQ AnythingLLM
VM

Enterprise NAS Storage

2 vCPU • 2 GB RAM • Direct SATA

OpenMediaVault 8 with hardware SATA controller passthrough (4TB Seagate IronWolf + 2TB WD Red). Pooled via MergerFS into a unified 5.4TB net share.

MergerFS Pool SMB/CIFS Shares Zero RAID Lock-in
LXC

Perimeter Gateway

2 vCPU • 512 MB RAM • Fast Boot

The security perimeter. Traefik v3 reverse proxy with Let's Encrypt wildcard SSL automation and Authelia Forward-Auth Single Sign-On.

Traefik v3 Authelia MFA Zero-Trust Boundary
LXC

Telemetry & Logs

2 vCPU • 1 GB RAM • TSDB

Prometheus 2.x time-series engine, Grafana 10.x visualization dashboards, and Grafana Loki log ingestion with a 28-day retention window.

Prometheus Grafana 10 Grafana Loki
LXC

AI Execution Sandbox

4 vCPU • 4 GB RAM • Isolated

Privileged, dedicated container sandbox runtime. Allows AI agents to generate, test, and execute arbitrary Python and shell scripts without touching host filesystems.

Isolated Sandbox Python Runner Secure Runtime
LXC

LangGraph DAG Runtime

1 vCPU • 1 GB RAM • Tracing

Stateful Python multi-agent orchestration engine executing multi-step reasoning DAGs with LangSmith instrumentation for step-by-step token and latency auditing.

LangGraph LangSmith Tracing Autonomous DAGs
Storage Engineering

Multi-Tier Storage Architecture

Separating ultra-low latency flash compute from resilient, expandable bulk storage.

Tier 1: Hot NVMe Flash

1.5 TB Total Across PVE Hosts
< 0.5ms I/O

High-throughput solid-state flash backing all virtual machine root disks, PostgreSQL relational databases, Redis memory stores, and active Docker volumes. Ensures instantaneous container startup and database query execution.

  • Proxmox VM and LXC root partitions
  • High-IOPS PostgreSQL 16 & Redis caches
  • Active container state and telemetry databases

Tier 2: Warm/Cold Bulk NAS

6.0 TB Raw / 5.4 TB Net MergerFS
Zero Vendor Lock-in

Rather than using fragile hardware RAID or rigid ZFS that mandates identical drive sizes, MergerFS combines a 4TB Seagate IronWolf and a 2TB WD Red into a single unified mount point. If any single drive ever fails, files on remaining drives stay 100% readable.

  • 4TB Seagate IronWolf + 2TB Western Digital Red NAS
  • Unified MergerFS mount exposed via SMB/CIFS
  • Raspberry Pis utilize 256MB log2ram disks to protect flash memory
Autonomous Incident Remediation

Closed-Loop Self-Healing Pipeline

Observe → Alert → Analyze → Remediate. An automated event loop powered by LLMs and Ansible that diagnoses and fixes incidents autonomously.

STAGE 01

Detection & Probing

24/7 edge health probes via Uptime Kuma and Prometheus Alertmanager detect service degradation or non-200 HTTP responses.

STAGE 02

Event Dispatch

Alert triggers a webhook to the n8n "Lab Medic" orchestrator, which immediately pulls the last 50 log lines from Grafana Loki.

STAGE 03

LLM Log Triage

A local LLM evaluates the error buffer to distinguish between transient network timeouts and fatal application crashes.

STAGE 04

Ansible Remediation

If resolvable, n8n invokes Ansible's self_heal playbook to recycle target containers; otherwise, escalates to Telegram and Gotify.

ansible-playbook -i inventory.ini self_heal.yml --extra-vars "target=service"
Mean Time To Recovery: < 45 Seconds
Operational Rigor

Zero-Downtime Two-Wave Maintenance

System reboots and kernel upgrades are orchestrated via Ansible in a strict two-wave dependency chain. Wave 1 cycles stateless workers, proxy caches, and edge nodes. Wave 2 safely coordinates database checkpoints, storage unmounts, and hypervisor maintenance, eliminating deadlock states.

1 Wave 1: Worker LXCs, telemetry forwarders, edge DNS nodes
2 Wave 2: Storage pools, PostgreSQL primary, core orchestration hypervisor
repo-structure.txt 100% Declarative
├── ansible/
│   ├── inventory.ini        # Target node registry
│   ├── playbooks/           # deploy.yml, self_heal.yml, reboot.yml
│   └── vault.yml            # Encrypted credentials & secrets
├── docker-compose/          # Master declarative service manifests
├── terraform/               # Proxmox VM & LXC provisioning specs
└── LAB_SPEC.md              # Master executable lab specification
Active Horizons & Next-Gen Architecture

Engineering Roadmap: In-Progress & Future Work

The homelab operates as an active production laboratory. Beyond deployed infrastructure, here is the active engineering backlog and high-priority initiatives currently undergoing development, testing, and deployment.

IN ACTIVE SPRINT Target: AI Utility Cluster

LangGraph Autonomous Agent Swarm & FastMCP

Multi-Agent State Machines • FastMCP Protocol

Orchestrating an autonomous 4-bot agent swarm consisting of specialized personas (Manager, Monitor, Reviewer, and Executor) running cyclic LangGraph state machines in Python. Integrating FastMCP (Model Context Protocol) servers to provide sandboxed local LLMs with secure schema-validated tool-calling directly into homelab diagnostics, metrics, and Docker APIs over Telegram and Discord.

LangGraph DAGs FastMCP / Model Context Role-Based Agents Secure Sandboxed Exec
PLANNED ARCHITECTURE Target: Edge ARM64 Fleet

Zero-SPOF Secondary High-Availability DNS

Redundant Recursive Resolver • adguardhome-sync

Eliminating the single point of failure in network name resolution. Currently, edge DNS runs on a primary node; implementing a mirrored secondary AdGuard Home recursive DNS resolver onto a secondary ARM64 node. Incorporating adguardhome-sync for bi-directional blocklist replication and configuring dual-resolver DHCP dispatch so client machines fail over seamlessly with zero downtime during maintenance reboots.

Secondary DNS Mesh adguardhome-sync Zero-SPOF High Availability Dual DHCP Dispatch
IN ACTIVE DEVELOPMENT Target: Hermes Autonomous Agent

Autonomous Web Intelligence & Market Arbitrage

Playwright Stealth • Hermes Agent • Real-Time Scraping

Engineering a stealth Playwright browser automation tool and reverse-engineered API scraping client integrated directly into the Hermes autonomous agent VM. Designed to periodically scrape and cross-compare multi-vendor product catalogs and rapid-commerce pricing data, identifying pricing discrepancies and pushing instant event alerts via RabbitMQ and Telegram.

Playwright Stealth Hermes Autonomous Bot Automated Scraping Event-Driven Alerts
TESTING & VALIDATION Target: Core GitOps Pipeline

Automated Proxmox Provisioning & Pre-Commit CI

Terraform Proxmox Provider • Pre-Commit Hooks • Auto-Docs

Advancing from declarative service configuration to full lifecycle infrastructure automation. Finalizing one-click Proxmox LXC/VM provisioning via Ansible and Terraform providers, integrating strict Git pre-commit hooks to lint Docker Compose and Ansible YAML syntax prior to commit, and auto-generating human-readable architecture documentation directly from machine-readable JSON topology specifications.

Terraform Proxmox Ansible Provisioning Pre-Commit Linter Living Documentation
Additional Evaluated Integrations on Backlog

Visual agent canvas (Langflow, Sim Studio) • Code structure indexing (CodeGraph AST) • High-throughput MCP agents (mcp-agent)

14 Tracked Backlog Items