Zero trust at home
Proxmox with containers, a reverse proxy, local DNS and SSO in front of the services.
default drop- Problem
- A homelab grows one service at a time, and each one handles login its own way.
- What I did
- I audited every service for real auth, put SSO via OIDC in front and set the firewall to default drop.
- Result
- One sign-on for the services and a default-drop firewall, rolled out with a dead-man switch.

