OcxlyDev · Field Guide

The 10-layer home lab stack for 2026: what you actually need

A home lab is best understood as a stack of layers, each one addressing a problem created by the layer below. This walks through the whole stack for 2026, from the foundation to security, with the reasoning for each choice.

OcxlyDev Published 14 August 2026 ~6 min read Sources linked throughout

Many home-lab guides are parts lists: buy this box, flash this image, done. But what turns a machine in a closet into a realistic environment for learning is not the hardware; it is the architecture running on top of it. If you think in layers, each one solving a problem the previous layer created, a home lab becomes a place to practise the same skills a data centre needs. This guide works through the stack from the bottom up.

01The foundation: your hypervisor

Everything sits on a hypervisor, the layer that turns one physical machine into several isolated virtual ones. In 2026 the common home-lab choice is Proxmox VE, a Debian-based, open-source platform that runs full virtual machines (via KVM) and lightweight system containers (via LXC) from one web interface.1 It is free, scriptable, clusters across several nodes, and is close to a community standard.

The main alternative is TrueNAS, the product formerly called TrueNAS SCALE, rebranded TrueNAS Community Edition with the 25.04 "Fangtooth" release in 2025.2 TrueNAS leads with ZFS storage and adds virtualisation and apps on top. A simple rule: if your lab is compute-first, start with Proxmox and add storage; if it is storage-first (a serious NAS that also runs a few apps), start with TrueNAS. Many labs end up running both, TrueNAS as the storage box and Proxmox as the compute cluster.

02Identity: single sign-on for the lab

Once you run more than a couple of services, you have a login problem: several apps, several passwords, and no consistent way to enforce two-factor. The usual answer is single sign-on, and you can run it at home. Authelia is a lightweight authentication and two-factor portal that sits in front of your apps and puts them behind one login,3 while Keycloak is a full open-source identity and access-management server that speaks OpenID Connect and SAML, the same protocols companies use.4 Start with Authelia for a forward-auth gate, and move to Keycloak when you want to learn OIDC and SAML properly. Either way, you have built an identity layer of the kind companies run with dedicated teams.

03The data layer: a 3-2-1 backup strategy

Self-hosting makes you responsible for the data, and a home lab without backups is a data-loss incident waiting to happen. The standard practice is the 3-2-1 rule: keep 3 copies of your data, on 2 different types of media, with 1 copy off-site.5 It was coined by photographer Peter Krogh and is endorsed by CISA as a baseline for resilient backup.5 In practice: your live data, a local backup on a different disk or NAS, and one copy off-site (a friend's house, a rotated drive, or encrypted cloud). Ransomware has pushed many professionals to 3-2-1-1-0, which adds one immutable or air-gapped copy and zero restore errors, but a 3-2-1 setup you have actually tested is what separates a lab from a liability.

A backup only counts once you have restored from it. An untested backup is a hope, not a plan.

04The security lab: vulnerability scanning and a SIEM

This is where a home lab is useful for security practice. Two layers turn your network into a practice range. First, vulnerability management: a scanner like OpenVAS / Greenbone Community Edition checks your hosts for known weaknesses and reports them the way an enterprise scanner would, so you learn to read and fix findings.6 Second, a SIEM (Security Information and Event Management), which collects logs from across your lab, correlates them, and raises alerts. Wazuh is a free, open-source SIEM/XDR platform that does this and is widely used to learn blue-team skills at home.7 Running both against your own infrastructure is one of the more employable skills a home lab can teach.

05The remaining layers, briefly

The stack does not stop there, and later parts of this series cover the most important ones in depth. In short, the other layers are:

06Where OcxlyDev lands

We treat a home lab as an inexpensive way to develop professional skills: for the price of a used mini PC and some evenings, you can run the same layers a mid-size company runs — hypervisor, identity, backup, vulnerability management, SIEM — and break them safely. Build the stack from the bottom up, add each layer only when the one below is stable, and avoid installing everything at once. The goal is not the largest pile of services; it is a stack you understand well enough to rebuild from scratch, which, as part five shows, is what Infrastructure as Code makes possible.

About this piece. This is part one of a five-part OcxlyDev field guide on building a home lab — the 10-layer stack, zero-trust networking, de-Googling with self-hosted apps, mini-PC hardware, and Infrastructure as Code with Ansible. Project names and hardware move quickly, so treat specifics as a snapshot rather than a fixed rule.

References

  1. Proxmox — Proxmox VE: open-source virtualization with KVM virtual machines and LXC containers
  2. TrueNAS — "Meet TrueNAS Community Edition": TrueNAS SCALE rebranded as Community Edition (25.04 Fangtooth, 2025)
  3. Authelia — official site: an open-source authentication and two-factor SSO portal
  4. Keycloak — official site: open-source identity and access management (OpenID Connect, OAuth 2.0, SAML)
  5. CISA / US-CERT — "Data Backup Options": the 3-2-1 rule (3 copies, 2 media, 1 off-site)
  6. Greenbone — Community Edition (OpenVAS): open-source vulnerability scanning and management
  7. Wazuh — official site: a free, open-source SIEM and XDR platform
  8. Docker Documentation — "Docker overview": containers as the standard packaging unit for self-hosted apps
  9. Prometheus Documentation — "Overview": open-source metrics monitoring (paired with Grafana dashboards)