Infrastructure

Albgott — Private Lab

From “is it up?” to knowing before anyone asks. Albgott is the private infrastructure my projects run on — a self-managed cloud, isolated and monitored, where every service has its place and every failure leaves a trail. I've kept it at home since 2023 and run it as if it had clients behind it, even though I'm the only one an alert ever wakes up.

  • Self-hosted
  • Proxmox
  • Docker
  • Jenkins
  • Prometheus
  • Grafana
  • WireGuard
A Raspberry Pi, a Dell Micro, a Dell tower and a laptop, stuffed into a cabinet. That's the whole data centre.

This has probably happened to a lot of people: you join a company that has everything automated. You open a pull request and a server spins up on its own so the team can try the new version of the API while they argue about whether it should go in. If it does, it's built and shipped to production; if not, it disappears. All of it in minutes, without anyone lifting a finger.

And that's where you get curious: how is this done? What would I need to build a small version of it myself? So you start playing with AWS and a few third-party services, and it's genuinely fun, right up until you leave a couple of machines running and get a €300 bill for a month of sloppy experiments.

The takeaway wasn't to stop learning this, it was to stop paying for it by the hour. I put together the hardware I already had lying around the house, set it up in a cabinet, and started again — this time somewhere a mistake costs electricity, not money.

If I break it, I break it alone

There's no server room here. This lives in a flat, hanging off the same internet line as everyone else I live with. So the first thing I did was cut the network into pieces, so that if I mess up it doesn't drag anyone else down with it. The lab runs on its own isolated zones, the home Wi-Fi has no business in there, and a container going wild with the bandwidth or a firewall rule I get wrong at 1am stays in its corner. Nobody loses Netflix because I was tinkering.

Eight isolated zones instead of one flat network. The home Wi-Fi is just one of them, and it can't reach the rest.

A junk laptop with an infrastructure behind it

I work off whatever cheap laptop is around and I don't much care what happens to it, because there's nothing on it anyway. Files, photos, code, notes, a password manager… all of that is on Albgott, and I get in through a WireGuard tunnel. I connect from wherever and it's like sitting in front of the rack. If the laptop gets lost, falls in the toilet, or just dies, I grab another one, bring the tunnel up, and ten minutes later I'm back where I was.

Two tunnels, not one: a normal one for the apps and a separate, more privileged one just for the hardware. Neither can slip into the other.

I run it like production

The website has all the technical detail; here's the short version. I treat an outage at home the way I'd treat one at work. Every service puts out metrics and logs, and something separate keeps an eye on whether it's actually still up. A git push builds, deploys, and checks itself. And when something breaks — it does — I get a message on my phone before I've had a chance to look.

Checkout to a live health check in under three minutes, nothing done by hand.
Every deploy announces itself: commit, author, the files that changed, and the live URL.

What's inside

Facing outward, Albgott runs a handful of websites. This one, albertomoran.dev, comes from here; so does albgott.com and the Montes del Acebo demo (the contact form you'd write to me with is an n8n workflow on the same box). Underneath that is everything that holds it up:

  • JenkinsBuilds, deploys and health-checks every push
  • HarborPrivate registry for the container images
  • AuthentikSingle sign-on in front of everything
  • InfisicalSecrets, kept out of config files
  • PrometheusMetrics and the rules that page me
  • GrafanaDashboards over metrics and logs
  • LokiLog aggregation for every container
  • Uptime KumaIndependent uptime checks and status pages
  • PortainerA window into the Docker hosts
  • PostgreSQLShared database for the applications
  • RustFSS3-compatible object storage
  • n8nAutomations and webhooks — this site's contact form
  • ImmichPhoto backup and library
  • OpenCloudFiles and documents, self-hosted
  • BookOrbitReading tracker and ebook library
Part of what's running, roughly grouped by topic. Nowhere near all of it.

And a few of them from the inside:

n8n handling this site's contact form, Portainer over the Docker hosts, plus BookOrbit and OpenCloud.
The start page: every node, service and shortcut in one place. It's the first thing I open in the morning.

The three nodes are named Brokkr, Eitri and Thor, after the dwarves who forged Thor's hammer. This has cost me a scattered handful of weekends, and building it and fighting with it has taught me more than any course: how networks really behave, how much work it is to operate something properly, and how much easier you sleep knowing your stuff is safe whatever happens to the laptop.