Home Infrastructure Cluster & WireGuard Mesh Networking


Data Sovereignty Through Self-Hosting

Built a comprehensive home infrastructure cluster using repurposed MacMini hardware to maintain complete data sovereignty and avoid cloud dependencies. This project represents a complete shift away from cloud services, with self-hosted email, DNS, and over 100 additional services.

Infrastructure Components

Hybrid Cloud Architecture

The infrastructure operates as a hybrid home cloud—combining the security and sovereignty of local hosting with the accessibility of public cloud. At its core is a highly secure controlled data vault, protected by layered security measures that keep sensitive data completely isolated from the public internet.

WireGuard Mesh Networking Innovation

To enable this hybrid architecture, I built a custom mesh networking tool inspired by Docker Swarm's join token approach. Rather than relying on Tailscale or similar services with their coordination servers and account dependencies, this tool provides the same frictionless "join token" experience while keeping all networking completely self-controlled.

The mesh enables secure ingress through a public-facing VPS server—conceptually similar to Cloudflare's Argo tunnels—allowing controlled access to home-hosted services without exposing the internal network. Traffic flows through carefully tuned paths, with the mesh automatically handling peer discovery and connection establishment.

Technical Achievements

Impact

This infrastructure represents a complete commitment to data sovereignty. No monthly cloud bills. No vendor lock-in. No data leaving my control. The cluster runs 100+ services autonomously—I rarely need to think about it.

The best infrastructure is the kind you forget exists. These systems just work, day after day, without demanding attention or generating support tickets.

← Back to Portfolio