Hybrid-Cloud Homelab Architecture

Monolithic cloud architectures introduce prohibitive egress bandwidth charges and recurring subscription lock-in. To achieve both lightning-fast edge delivery and low-cost multi-terabyte storage, DenverNerd employs a hybrid edge-to-core infrastructure.

1. Edge Ingress Layer (Debian VPS + Caddy)

A budget VPS running hardened Debian Linux handles all public ingress. Caddy terminates TLS with automatic Let's Encrypt certificates and applies strict HTTP headers:

denvernerd.com {
    encode zstd gzip

    header {
        Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
        X-Content-Type-Options "nosniff"
        X-Frame-Options "DENY"
    }

    reverse_proxy 10.100.0.2:5000 {
        header_up Host {host}
        header_up X-Real-IP {remote_host}
    }
}

2. Encrypted Overlay (WireGuard Point-to-Point)

Communication between the public VPS and the local server cluster runs across a dedicated kernel-level WireGuard interface:

[Interface]
Address = 10.100.0.1/24
PrivateKey = <VPS_PRIVATE_KEY>
ListenPort = 51820

[Peer]
PublicKey = <HOMELAB_PUBLIC_KEY>
Endpoint = dynamic.denvernerd.com:51820
AllowedIPs = 10.100.0.2/32
PersistentKeepalive = 25

3. Storage Core (TrueNAS + ZFS Mirror Pools)

At the core resides an 8-bay TrueNAS host with dual 10GbE SFP+ uplinks:

  • Pool Architecture: 4x 16TB Enterprise SAS drives in mirrored vdevs (RAID10 equivalent)
  • Read Cache (L2ARC): 1TB PCIe 4.0 NVMe
  • Synchronous Write Log (SLOG): Optane P1600X for low-latency database syncs
  • S3 Endpoint: MinIO server providing S3-compatible APIs for digital asset fulfillment

Benchmarks & Latency

  1. Edge-to-Core Ping: ~11.4 ms over symmetric fiber
  2. WireGuard iperf3 Throughput: 940 Mbps sustained
  3. Database Read Latency: < 1.2 ms over internal network