The 10-layer home lab stack for 2026: what you actually need
A home lab is best understood as a stack of layers, each one addressing a problem created by the layer below. This walks through the whole stack for 2026, from the foundation to security, with the reasoning for each choice.
Many home-lab guides are parts lists: buy this box, flash this image, done. But what turns a machine in a closet into a realistic environment for learning is not the hardware; it is the architecture running on top of it. If you think in layers, each one solving a problem the previous layer created, a home lab becomes a place to practise the same skills a data centre needs. This guide works through the stack from the bottom up.
01The foundation: your hypervisor
Everything sits on a hypervisor, the layer that turns one physical machine into several isolated virtual ones. In 2026 the common home-lab choice is Proxmox VE, a Debian-based, open-source platform that runs full virtual machines (via KVM) and lightweight system containers (via LXC) from one web interface.1 It is free, scriptable, clusters across several nodes, and is close to a community standard.
The main alternative is TrueNAS, the product formerly called TrueNAS SCALE, rebranded TrueNAS Community Edition with the 25.04 "Fangtooth" release in 2025.2 TrueNAS leads with ZFS storage and adds virtualisation and apps on top. A simple rule: if your lab is compute-first, start with Proxmox and add storage; if it is storage-first (a serious NAS that also runs a few apps), start with TrueNAS. Many labs end up running both, TrueNAS as the storage box and Proxmox as the compute cluster.
02Identity: single sign-on for the lab
Once you run more than a couple of services, you have a login problem: several apps, several passwords, and no consistent way to enforce two-factor. The usual answer is single sign-on, and you can run it at home. Authelia is a lightweight authentication and two-factor portal that sits in front of your apps and puts them behind one login,3 while Keycloak is a full open-source identity and access-management server that speaks OpenID Connect and SAML, the same protocols companies use.4 Start with Authelia for a forward-auth gate, and move to Keycloak when you want to learn OIDC and SAML properly. Either way, you have built an identity layer of the kind companies run with dedicated teams.
03The data layer: a 3-2-1 backup strategy
Self-hosting makes you responsible for the data, and a home lab without backups is a data-loss incident waiting to happen. The standard practice is the 3-2-1 rule: keep 3 copies of your data, on 2 different types of media, with 1 copy off-site.5 It was coined by photographer Peter Krogh and is endorsed by CISA as a baseline for resilient backup.5 In practice: your live data, a local backup on a different disk or NAS, and one copy off-site (a friend's house, a rotated drive, or encrypted cloud). Ransomware has pushed many professionals to 3-2-1-1-0, which adds one immutable or air-gapped copy and zero restore errors, but a 3-2-1 setup you have actually tested is what separates a lab from a liability.
A backup only counts once you have restored from it. An untested backup is a hope, not a plan.
04The security lab: vulnerability scanning and a SIEM
This is where a home lab is useful for security practice. Two layers turn your network into a practice range. First, vulnerability management: a scanner like OpenVAS / Greenbone Community Edition checks your hosts for known weaknesses and reports them the way an enterprise scanner would, so you learn to read and fix findings.6 Second, a SIEM (Security Information and Event Management), which collects logs from across your lab, correlates them, and raises alerts. Wazuh is a free, open-source SIEM/XDR platform that does this and is widely used to learn blue-team skills at home.7 Running both against your own infrastructure is one of the more employable skills a home lab can teach.
05The remaining layers, briefly
The stack does not stop there, and later parts of this series cover the most important ones in depth. In short, the other layers are:
- Networking — VLANs and a capable router/firewall (pfSense or OPNsense) to separate trusted, IoT, and lab traffic.
- Secure remote access — a zero-trust layer so you never forward a port to the internet (covered in part two).
- Reverse proxy — Traefik, Caddy, or Nginx Proxy Manager to give services clean HTTPS names instead of
ip:port. - Containers — Docker (and Compose), the format most self-hosted apps ship in.8
- Monitoring — Prometheus collecting metrics and Grafana drawing the dashboards, so you can see the lab's state.9
- Automation — Infrastructure as Code with Ansible, so the whole stack is reproducible (covered in part five).
06Where OcxlyDev lands
We treat a home lab as an inexpensive way to develop professional skills: for the price of a used mini PC and some evenings, you can run the same layers a mid-size company runs — hypervisor, identity, backup, vulnerability management, SIEM — and break them safely. Build the stack from the bottom up, add each layer only when the one below is stable, and avoid installing everything at once. The goal is not the largest pile of services; it is a stack you understand well enough to rebuild from scratch, which, as part five shows, is what Infrastructure as Code makes possible.