The lab
A small Kubernetes cluster at home, run the way I'd want production to be run: everything declared in git and reconciled automatically.
How a change reaches the cluster
I push to GitHub. Actions builds a container image and publishes it to GHCR, then updates the image tag in the homelab repository. Argo CD sees the new commit and syncs the cluster to match. I don't run kubectl apply by hand. If something isn't in git, it doesn't exist.
This page is served that way. So is my CV. The manifests are in gabridinu/homelab.
The stack
| Layer | What | Why |
|---|---|---|
| Compute | k3s, single node, on an Ubuntu VM in Synology Virtual Machine Manager | Full Kubernetes API on hardware I already own. |
| GitOps | Argo CD, App-of-Apps | Git is the only way in. Manual changes self-heal back to the committed state. |
| CI | GitHub Actions to GHCR | Every push builds an image; the cluster never builds anything. |
| Ingress | Traefik | Ships with k3s and handles routing for every public site. |
| TLS | cert-manager, Let's Encrypt DNS-01 via Cloudflare | Certificates are issued with no inbound port needed for validation. |
| Secrets | Sealed Secrets | Credentials are encrypted, so they can live in the repo. |
| DNS and edge | Cloudflare, Full (strict) TLS | Proxied public records and dynamic DNS for a home connection. |
| Remote access | Tailscale subnet router | Admin access from anywhere without opening router ports. |
| Storage | local-path provisioner and a Synology NAS | Simple volumes in the cluster, bulk storage on the NAS. |
Changelog
- Sep 2026
Moved the apex domain from WordPress to this Astro site, deployed the same way as the CV.
- Sep 2026
Migrated k3s from a bare-metal ThinkCentre to a VM on the Synology NAS.