Proxmox Firewall Security Hardening — IPSets, Rules, Cluster Firewall

Harden Proxmox VE with datacenter firewalls, dynamic IPSets for trusted management networks, cluster-wide security, fail2ban for web UI brute-force protection, and firewall log auditing.

June 16, 2026 · 8 min · 1497 words · GnTech

Proxmox API Tokens and RBAC — Secure Automation Access

Learn to secure Proxmox API access using API tokens and fine-grained RBAC. Covers token creation, role-based permission separation, Terraform/Ansible integration, and audit logging — all without exposing root credentials.

June 15, 2026 · 7 min · 1364 words · GnTech

Podman Rootless Containers — A Docker Alternative for Homelab

Run containers without a root daemon. Migrate your homelab from Docker to Podman for true rootless operation, systemd-native container management, and drop-in docker CLI compatibility.

June 13, 2026 · 8 min · 1522 words · GnTech

Docker Supply Chain Security — SBOM, Image Signing, and Verification

Practical guide to securing your container supply chain in the homelab: generate SBOMs with Syft, sign images with Cosign, scan for vulnerabilities with Grype, and enforce Docker Content Trust.

June 13, 2026 · 7 min · 1280 words · GnTech

acme.sh Let's Encrypt Certificates for Homelab Docker Services

Automate Let’s Encrypt SSL/TLS certificates in your homelab using acme.sh and Docker. Includes DNS-01 wildcard certs, auto-renewal, and integration with Traefik, Nginx Proxy Manager, and Caddy.

June 11, 2026 · 8 min · 1678 words · GnTech

Linux auditd Security Auditing — Monitor Proxmox and Docker Activity

Configure Linux auditd to watch container starts, file changes, and Proxmox host activity. Includes auditctl rules, ausearch queries, and Docker integration for comprehensive homelab security auditing.

June 11, 2026 · 9 min · 1881 words · GnTech

Docker nftables Firewall Backend — Native Firewall for Containers

Migrate Docker from iptables to the native nftables firewall backend. Configure docker daemon.json for nftables on Debian 13, test port publishing, and troubleshoot common migration issues.

June 6, 2026 · 10 min · 1979 words · GnTech

Docker Hardened Images — Migrate Your Homelab Stack to Near-Zero CVEs

Swap your standard Docker Hub images for Docker Hardened Images (DHI) to cut CVEs by up to 95%. Step-by-step Compose migration for Postgres, Redis, Nginx, and your full homelab stack.

June 5, 2026 · 7 min · 1417 words · GnTech

Gluetun VPN Gateway — Route Docker Containers Through WireGuard

Route specific Docker containers through a WireGuard VPN while keeping the rest of your stack on the local network. Full Gluetun Docker Compose setup with kill switch, qBittorrent integration, and Traefik compatibility.

June 5, 2026 · 7 min · 1355 words · GnTech

Docker Image Security Hardening — Multi-Stage Builds and Distroless

Harden your Docker images with multi-stage builds, distroless base images, and runtime security options. A practical guide to reducing image size and CVEs in your homelab.

June 5, 2026 · 8 min · 1649 words · GnTech