VLANs for a Small Homelab Without Unnecessary Complexity
How to introduce VLANs into a small homelab without turning a hobby network into an unmaintainable maze — plus the recovery steps for when segmentation locks you out.
TAG
How to introduce VLANs into a small homelab without turning a hobby network into an unmaintainable maze — plus the recovery steps for when segmentation locks you out.
Exposing SSH or dashboards directly to the internet is unnecessary risk for small deployments. WireGuard gives a cleaner and safer remote access model.
Edge devices frequently run with broad network exposure and weak maintenance. Security hardening has to be practical, repeatable, and automation-friendly.
A long retrospective on how I hardened a Debian 12 VPS for public internet exposure with practical config details and operational lessons.
A practical retrospective on building a reliable WireGuard site-to-site VPN between home lab and VPS environments with routing, MTU, and operational hardening lessons.