All systems operational · ipalm.nl

Willard Palm

Self-hosting the future, one container at a time

6 LXC Containers
4 VLANs
IPv6 Dual Stack
24/7 Uptime

Built on a
solid foundation

A carefully curated homelab stack focused on security, performance and self-sufficiency.

Proxmox
Proxmox VE
Bare-metal hypervisor running on a 12-core i5 with 16GB RAM. All workloads run as LXC containers for minimal overhead.
Proxmox 7 LXC ZFS
UniFi
UniFi ZBF
Zone-based firewall with full VLAN segmentation. IoT, Secure, Guest and VPN zones — each with strict inter-VLAN policies and logging.
UniFi CGU IPv4+IPv6 IDS/IPS
Adguard
Adguard Home
Network-wide DNS filtering with 535k+ block rules. Parallel DoH upstreams via Cloudflare, Adguard DNS and Quad9 with DNSSEC.
DNS-over-HTTPS DNSSEC 535k rules
DockerPodman
Docker + Podman
Containerised services managed through Portainer. Immutable SHA-pinned deployments via the Portainer API for reproducible stacks.
Portainer Docker Podman
Nginx
Nginx Proxy Manager
Reverse proxy with automatic SSL via Let's Encrypt. All services exposed through ipalm.nl with HSTS, access lists and IPv6 support.
Let's Encrypt HSTS Wildcard DNS
AI
AI & Automation
MCP-driven infrastructure management — UniFi, Proxmox and Adguard controlled via AI agents. Hermes Agent orchestrates the homelab.
MCP Protocol Hermes Agent GraphDB

The Homelab

Proxmox pve01 — 12-core, 16GB. Six production LXC containers, one VM running Home Assistant OS.

NPM
Nginx Proxy Manager
CT-01 · 10.x.x.22
Vaultwarden
Vaultwarden
CT-02 · 10.x.x.26
Docker
Docker
CT-03 · 10.x.x.23
Podman
Podman
CT-04 · 10.x.x.25
Jellyfin
Jellyfin
CT-05 · 10.x.x.59
Adguard
Adguard Home
CT-06 · 10.x.x.62
pve01 — system status
willard@pve01:~$ pvesh get /nodes/pve01/status
{
  "cpu": 0.04,
  "memory": {
    "used": "in use",
    "total": "total"
  },
  "uptime": "stable",
  "kernel": "current",
  "ipv6": "xxxx:xxxx:xxxx::/48"
}

willard@pve01:~$ _

VLAN Segmentation

Zero-trust network design with strict inter-VLAN firewall policies, dual-stack IPv4+IPv6 and DNS filtering on every segment.

VLAN 10
Palm-Secure
10.x.x.0/24
Servers · Proxmox · Admin
VLAN 20
Palm-IoT
10.x.x.0/24
Cameras · Smart home · TV
VLAN 30
Palm-Guest
10.x.x.0/24
Guest WiFi · Isolated
VLAN 2
Palm-VPN
10.x.x.0/24
VPN clients · Remote access
adguard — DNS stats
$ curl adguard.ipalm.nl/control/stats
Upstreams: Cloudflare DoH · Adguard DNS · Quad9
Mode: parallel (fastest wins)
Blocklists: 535,828 rules active
DNSSEC: enabled
DoT block: TCP/853 → all VLANs
IPv6: xxxx:xxxx:xxxx::/48 (KPN)

Let's connect

Interested in self-hosting, network security or homelab automation? Always happy to exchange ideas.