The lab

A small Kubernetes cluster at home, run the way I'd want production to be run: everything declared in git and reconciled automatically.

How a change reaches the cluster

I push to GitHub. Actions builds a container image and publishes it to GHCR, then updates the image tag in the homelab repository. Argo CD sees the new commit and syncs the cluster to match. I don't run kubectl apply by hand. If something isn't in git, it doesn't exist.

This page is served that way. So is my CV. The manifests are in gabridinu/homelab.

The stack

LayerWhatWhy
Computek3s, single node, on an Ubuntu VM in Synology Virtual Machine ManagerFull Kubernetes API on hardware I already own.
GitOpsArgo CD, App-of-AppsGit is the only way in. Manual changes self-heal back to the committed state.
CIGitHub Actions to GHCREvery push builds an image; the cluster never builds anything.
IngressTraefikShips with k3s and handles routing for every public site.
TLScert-manager, Let's Encrypt DNS-01 via CloudflareCertificates are issued with no inbound port needed for validation.
SecretsSealed SecretsCredentials are encrypted, so they can live in the repo.
DNS and edgeCloudflare, Full (strict) TLSProxied public records and dynamic DNS for a home connection.
Remote accessTailscale subnet routerAdmin access from anywhere without opening router ports.
Storagelocal-path provisioner and a Synology NASSimple volumes in the cluster, bulk storage on the NAS.

Changelog

  1. Sep 2026

    Moved the apex domain from WordPress to this Astro site, deployed the same way as the CV.

  2. Sep 2026

    Migrated k3s from a bare-metal ThinkCentre to a VM on the Synology NAS.