<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CLAUDIO</title>
    <description>The latest articles on DEV Community by CLAUDIO (@claudio_f5c23617499305b57).</description>
    <link>https://dev.to/claudio_f5c23617499305b57</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3811673%2F3029dfa9-89d8-4e8c-ba5b-cd26883e45fe.jpg</url>
      <title>DEV Community: CLAUDIO</title>
      <link>https://dev.to/claudio_f5c23617499305b57</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/claudio_f5c23617499305b57"/>
    <language>en</language>
    <item>
      <title>Why I run my home lab like enterprise infrastructure</title>
      <dc:creator>CLAUDIO</dc:creator>
      <pubDate>Sun, 12 Jul 2026 19:51:05 +0000</pubDate>
      <link>https://dev.to/claudio_f5c23617499305b57/why-i-run-my-home-lab-like-enterprise-infrastructure-39a0</link>
      <guid>https://dev.to/claudio_f5c23617499305b57/why-i-run-my-home-lab-like-enterprise-infrastructure-39a0</guid>
      <description>&lt;p&gt;I'm an IT Systems Administrator / Service Desk Team Lead L2 in Torino, Italy. During the day I manage endpoints and infrastructure for a large public-sector IT provider. At night I run &lt;strong&gt;PolarisCore&lt;/strong&gt;, a home lab built with the same standards I use at work: VLAN segmentation, a real reverse proxy, internal DNS, ZFS storage with redundancy, and monitoring — not just a pile of Docker containers on a single box.&lt;/p&gt;

&lt;p&gt;Here's the actual current state of it, pulled live via SSH, not marketing copy.&lt;/p&gt;

&lt;h3&gt;
  
  
  The compute layer — Proxmox
&lt;/h3&gt;

&lt;p&gt;One node left after a migration earlier this year moved the old primary host over to dedicated NAS duty (more on that below).&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;pve-manager/9.2.3 (kernel 7.0.12-1-pve)
Uptime: 10 days
RAM: 4.7 / 7.5 GiB used
ZFS rpool (NVMe mirror): 45.9 GB / 236 GB (19%)
Containers: 14 running / 16 total (LXC)
Load average: 0.05, 0.08, 0.14
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;14 LXC containers handle: a Caddy reverse proxy, internal DNS (PowerDNS + Pi-hole), a self-built deployment tool (more below), a Next.js search frontend, and a handful of smaller services. Everything sits behind VLANs — management, services, IoT, gaming, guest, and VPN are all separated, with the services VLAN carrying most of the public-facing traffic.&lt;/p&gt;

&lt;h3&gt;
  
  
  The storage layer — TrueNAS SCALE
&lt;/h3&gt;

&lt;p&gt;The hardware that used to run Proxmox now runs TrueNAS SCALE full-time:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;TrueNAS 25.10.4 (Fangtooth)
Uptime: 10 days
RAM: 28 / 31 GiB (ZFS ARC, expected)
Pool DATA (RAIDZ1, 4x8TB): 13.4 TB / 21.8 TB used (61%)
Pool APPS (mirror): 23.5 GB / 460 GB used (5%)
Pool boot: 3.47 GB / 236 GB used (1%)
All pools: ONLINE
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;22TB isn't there for the sake of it — it holds a media library (Jellyfin + the *arr stack, running as native TrueNAS apps, not VMs), backups for a few side projects, and a dedicated encrypted share. RAIDZ1 across 4 drives gives me a single-drive failure buffer, which for a home setup with real data on it (not just test VMs) matters more than raw speed.&lt;/p&gt;

&lt;h3&gt;
  
  
  The network layer
&lt;/h3&gt;

&lt;p&gt;FTTH 10Gbps from TIM into a UniFi Cloud Gateway Max, distributed over a 2.5GbE backbone to switches and clients. The 10Gbps WAN isn't about single-stream throughput to the internet — it's headroom so the internal 2.5GbE backbone never bottlenecks against the uplink when multiple services (backups, streaming, syncs) are active in parallel. TLS is wildcard, issued via DNS-01 against DuckDNS, auto-renewing, with zero inbound ports open for cert issuance.&lt;/p&gt;

&lt;h3&gt;
  
  
  The lightweight cloud piece — Oracle Always Free
&lt;/h3&gt;

&lt;p&gt;Not everything lives on-prem. Site analytics run on Umami (self-hosted, replaced GA4 across 5 sites) on an Oracle Cloud Always Free VM:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Ubuntu 20.04.6 LTS
VM.Standard.A1.Flex — 1 OCPU / 6 GB RAM
RAM used: 631 MiB (11%)
Load average: ~0.00 (idle)
Stack: Umami + Postgres 15 + Caddy, Docker Compose
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It's been up for a couple of days since the last restart and barely registers on CPU. For a low-traffic analytics backend, the free tier is more than enough — no reason to spend money on a VPS for this.&lt;/p&gt;

&lt;h3&gt;
  
  
  A side project that came out of daily frustration
&lt;/h3&gt;

&lt;p&gt;The one piece of software here that isn't just infra glue is &lt;strong&gt;NovaSCM&lt;/strong&gt; — an open-source, self-hosted alternative to Microsoft SCCM for zero-touch Windows deployment (PXE boot, autounattend generation, network scanning, WiFi 802.1X certificate management, workflow-based software deployment). I wrote about it in more detail in &lt;a href="https://dev.to/claudio_f5c23617499305b57/i-built-a-free-open-source-alternative-to-microsoft-sccm-3dkh"&gt;a separate post&lt;/a&gt; — it's MIT-licensed, on &lt;a href="https://github.com/ClaudioBecchis/NovaSCM" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;, and it runs as one of the 14 containers above.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why bother with all this at home
&lt;/h3&gt;

&lt;p&gt;The honest answer: because building it the "enterprise" way — with segmentation, real cert automation, redundant storage, and a reverse proxy instead of exposed ports — is the best way I know to actually understand those patterns instead of just reading about them at work. When something breaks at 11pm on my own network, I'm the only one who can fix it, which is a different kind of pressure than a ticket queue.&lt;/p&gt;

&lt;p&gt;More on the project (and a few more services I haven't written up yet) at &lt;a href="https://polariscore.it" rel="noopener noreferrer"&gt;polariscore.it&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>homelab</category>
      <category>proxmox</category>
      <category>sysadmin</category>
    </item>
    <item>
      <title>I built a free open-source alternative to Microsoft SCCM</title>
      <dc:creator>CLAUDIO</dc:creator>
      <pubDate>Sat, 07 Mar 2026 14:18:00 +0000</pubDate>
      <link>https://dev.to/claudio_f5c23617499305b57/i-built-a-free-open-source-alternative-to-microsoft-sccm-3dkh</link>
      <guid>https://dev.to/claudio_f5c23617499305b57/i-built-a-free-open-source-alternative-to-microsoft-sccm-3dkh</guid>
      <description>&lt;h2&gt;
  
  
  Why I built this
&lt;/h2&gt;

&lt;p&gt;Every day as an IT admin I was managing PC deployments, software installs,&lt;br&gt;
  WiFi certificates, network scans... and every day I thought:&lt;br&gt;
  &lt;em&gt;"Why do I have to pay thousands for SCCM to do this?"&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;So I built my own alternative. It's called &lt;strong&gt;NovaSCM&lt;/strong&gt;.&lt;/p&gt;



&lt;p&gt;## What is NovaSCM?&lt;/p&gt;

&lt;p&gt;NovaSCM is a self-hosted fleet &amp;amp; deployment manager inspired by Microsoft SCCM —&lt;br&gt;
  but free, open source, and lightweight.&lt;/p&gt;

&lt;p&gt;It combines:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;WPF desktop console&lt;/strong&gt; (Windows)&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;REST API server&lt;/strong&gt; (Python/Flask)&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;cross-platform agent&lt;/strong&gt; (Windows &amp;amp; Linux)&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;## What it does&lt;/p&gt;

&lt;p&gt;### 💿 Zero-touch Windows deployment&lt;br&gt;
  Generate &lt;code&gt;autounattend.xml&lt;/code&gt; and &lt;code&gt;postinstall.ps1&lt;/code&gt; automatically.&lt;br&gt;
  Copy to USB → boot the PC → go grab a coffee → come back with a fully configured machine.&lt;/p&gt;

&lt;p&gt;### 📡 Network scanner&lt;br&gt;
  Discover all devices by IP, MAC, vendor. One-click RDP and SSH directly from the console.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9pf75cvyrx2bifjk2z2g.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9pf75cvyrx2bifjk2z2g.jpg" alt="Network scanner" width="800" height="466"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;### 📦 Software deployment&lt;br&gt;
  Visual workflow editor with multi-step sequences — &lt;code&gt;winget_install&lt;/code&gt;, &lt;code&gt;powershell&lt;/code&gt;, &lt;code&gt;reboot&lt;/code&gt;, &lt;code&gt;registry&lt;/code&gt;, &lt;code&gt;file_copy&lt;/code&gt; and more.&lt;br&gt;
  Just like SCCM Task Sequences, but free.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fsqwc5ckz7r9ci9np8amb.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fsqwc5ckz7r9ci9np8amb.jpg" alt="Software catalog" width="799" height="475"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;### 🔐 WiFi 802.1X EAP-TLS&lt;br&gt;
  Issue client certificates signed by an internal CA.&lt;br&gt;
  Auto-enrollment agent for Windows, mobileconfig for iOS, QR code for Android.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8b6a1gnr7lv6z5929928.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8b6a1gnr7lv6z5929928.jpg" alt="WiFi certificates" width="799" height="459"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;### 📋 Change Request tracker&lt;br&gt;
  Track every deployment job per machine with status, logs and notes.&lt;/p&gt;



&lt;p&gt;## Tech stack&lt;/p&gt;

&lt;p&gt;| Component | Technology | Platform |&lt;br&gt;
  |-----------|-----------|----------|&lt;br&gt;
  | Console | C# / WPF / .NET 9 | Windows |&lt;br&gt;
  | Server | Python 3 / Flask / SQLite | Linux / Docker |&lt;br&gt;
  | Agent | Python 3 | Windows &amp;amp; Linux |&lt;/p&gt;



&lt;p&gt;## Quick start&lt;/p&gt;

&lt;p&gt;Start the server:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;  &lt;span class="nb"&gt;cd &lt;/span&gt;server
  docker compose up &lt;span class="nt"&gt;-d&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Deploy the agent on a Windows machine:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;iwr&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;http://&lt;/span&gt;&lt;span class="err"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nx"&gt;server-ip&lt;/span&gt;&lt;span class="err"&gt;&amp;gt;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="nx"&gt;9091/agent/install.ps1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;iex&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then download &lt;code&gt;NovaSCM.exe&lt;/code&gt; from Releases, point it to your server and you are ready.&lt;/p&gt;




&lt;p&gt;Links&lt;/p&gt;

&lt;p&gt;👉 GitHub: &lt;a href="https://github.com/ClaudioBecchis/NovaSCM" rel="noopener noreferrer"&gt;https://github.com/ClaudioBecchis/NovaSCM&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;MIT License — free to use, modify and distribute.&lt;/p&gt;

&lt;p&gt;Built by an IT admin, for IT admins. Feedback and stars are always welcome! ⭐&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>devops</category>
      <category>dotnet</category>
      <category>sys</category>
    </item>
  </channel>
</rss>
