← Home District

HOME LAB

Pixel City Infrastructure

Active Self-Hosted Kali Linux Proxmox VE Docker

The physical backbone of Pixel City — a growing private lab for self-hosted services, security research, radio observation, creative tools, and virtualisation.

The lab started as a single machine running a few Docker containers and grew into a multi-machine platform with dedicated roles — a Kali box for security tooling and Docker services, a Proxmox node for virtualisation, a managed switch for network control, and more hardware in the pipeline.

Everything is built around controlled access and deliberate isolation. Vulnerable training systems stay separated from everyday devices, while dedicated WiFi, Bluetooth and radio hardware turn the lab into a practical wireless research platform.

It's not finished — it never will be. That's the point.

35+ Services Running
3 Physical Machines
3 Active VMs
40TB+ Storage (planned)
💀
Kali Box
Live — Docker host + security platform
CPUIntel Core i5-3470 @ 3.2GHz (4c/4t)
RAM8GB
Storage120GB SSD
OSKali Linux 6.x
WiFiAlfa AWUS036ACH — monitor mode + injection
RadioSDRplay RSPdx + dedicated RTL-SDR
RoleContainers, wireless research and radio services
⚙️
Proxmox Node
Live — VM host
CPUAMD FX-8350 Eight-Core @ 4.0GHz (8c/8t)
RAM16GB
OS Drive238.5GB SSD — Proxmox OS + ISO storage
VM Drive931.5GB HDD — LVM thin pool (all VM disks)
OSProxmox VE 9.2.2
VirtualisationAMD-V enabled
🔀
HP ProCurve 1810G
Live — managed switch
TypeManaged Layer 2 Gigabit switch
RoleCore switch — all lab devices
FutureVLAN tagging once pfSense/OPNsense is live
🛡️
Dell OptiPlex SFF
Planned — OPNsense firewall router
StatusBoots fine — needs dual-port Intel NIC
RolepfSense/OPNsense — VLAN firewall, VPN, DMZ
Next stepBuy low-profile Intel NIC, install, configure
💾
HP MicroServer Gen8
Planned — NAS (TrueNAS SCALE)
StatusNot yet purchased
OSTrueNAS SCALE
Target40TB+ RAIDZ2 — SMB + NFS + backups
🖥️
Main PC — Spectra Indigo
Live — daily driver
CPUIntel i9-12900KF (16c / 24t)
RAM32GB
OSWindows 11
Storage~30TB across JBOD caddy + externals
📶
Alfa AWUS036ACH
Live — WiFi adapter
ChipsetRealtek RTL8812AU
BandsDual band — 2.4GHz + 5GHz (AC1200)
CapabilityMonitor mode + packet injection confirmed
Driver88XXau DKMS — monitor-mode capable
Used forOn-demand wireless monitoring and KaliDash
📡
RTL-SDR Dongle
Live — software defined radio
ChipsetRTL2832U + R820T tuner
Range~24 MHz to 1.766 GHz
AntennaRTL-SDR Blog V3 Dipole Kit (arrived Jun 2026)
Primary roleRTL-TRNG physical entropy source
📡
SDRplay RSPdx
Live — primary wideband receiver
CoverageDC to 2 GHz wideband receive
Current workADS-B aircraft + weather satellites
AntennasAdjustable dipole + wideband discone
SharingManaged hand-off between radio workloads
🛰️
Skyscan Wideband Antenna
Live — discone receiver antenna
Coverage25–2000 MHz
RoleGeneral radio discovery and satellite testing
Connected toSDRplay RSPdx antenna input
🟦
Bluetooth Research Pair
Live — passive RX + controlled TX
ReceivernRF52840 BLE sniffer
TransmitterRTL8761BU Bluetooth adapter
Used bySÉANCE Bluetooth observatory
📟
Raspberry Pi
Owned — not yet configured
Planned rolePi-hole DNS ad-blocking for the whole network
StatusSetup pending

The lab runs a mixed collection of private Docker services, monitoring tools, radio pipelines and creative applications. Most stay local-only; this public list deliberately leaves out addresses, ports and deployment details.

Service What it does Status
Portainer CEDocker management UI — all containers, stacks, volumesLive
Nginx Proxy ManagerReverse proxy — friendly hostnames + HTTPSLive
Uptime KumaService monitoring — uptime checks, alertsLive
HomarrHome lab dashboard — tiles linking to all servicesLive
GiteaSelf-hosted Git server — private reposLive
DashdotLive server stats — CPU, RAM, disk, networkLive
Prometheus + GrafanaMetrics collection, dashboards and long-term observabilityLive
InfluxDBHistorical time-series storage for radio and aircraft observationsLive
Service What it does Status
KismetOn-demand wireless monitoring and device researchStandby
NtopngLive LAN traffic analysis — flows, bandwidth, protocolsLive
KaliDashRemote control surface for authorised network, radio and security-lab workflowsLive
OWASP Juice ShopDeliberately vulnerable web app — web security practiceStandby
DVWADamn Vulnerable Web App — SQL injection, XSS practiceStandby
Wazuh SIEMCentralised security logs from all machines + alertingPlanned
T-Pot HoneypotDecoy system — logs attack attempts in real timePlanned
System What it does Status
Pixel RadarCustom aircraft radar with a synchronised aircraft workspace, trails, coverage, insights, alerts and receiver healthLive
ADS-B Receiver StackRSPdx receiver, Beast feed, decoding, live mapping and historical flight loggingLive
Radio ManagerSafely hands the shared receiver between aircraft and satellite workloadsLive
Weather Satellite LabSchedules passes, records reception attempts and returns the receiver to ADS-B afterwardsTesting
OpenWebRXBrowser-based wideband radio receiver for live signal explorationOn demand
RTL-TRNGTurns radio noise into a physical entropy and passphrase experimentLive
SÉANCETwo-radio Bluetooth observatory for capture, presence, fingerprinting and controlled researchLive
Service What it does Status
Password VaultPrivate self-hosted credential managerLive
WhooglePrivate self-hosted Google search — no trackingLive
KavitaeBook / manga / comic / PDF reader and libraryLive
MealieRecipe manager — import, organise, and plan mealsLive
AdventureLogTravel tracker and trip plannerLive
BentoPDFPrivacy-first PDF toolkit — merge, split, compress, convertLive
n8nWorkflow automation platformLive
NextcloudPrivate file sync and personal cloudLive
FreshRSSSelf-hosted RSS reading and filteringLive
MemosLightweight private notes and quick captureLive
The DepotLocal software and archive libraryLive
The BazaarPersonal marketplace watchlist and deal trackerLive
Mind Dump TerminalPrivate guided brain-dump and organisation toolLive
Fandom Card StudioBrowser-based collectible card designer and rendererLive
Crafty ControllerMinecraft server manager — Java Edition 1.21.4 vanillaLive
JellyfinMedia server — stream Sonarr/Radarr contentPlanned
ImmichGoogle Photos replacement — auto-backup from phonePlanned
Paperless-ngxDocument scanning + OCR — searchable archivePlanned
Pi-holeDNS ad-blocking for the whole networkPlanned

VM Lab

The Proxmox node runs an isolated lab network on a separate internal bridge with no external access — a clean environment for attack and defence practice. Lab VMs can't reach the real LAN; they only talk to each other.

A Windows 10 VM on the main bridge handles general Windows testing with full internet access. The isolated lab currently holds a Metasploitable 2 target and a dedicated Kali attack VM.

The next major expansion is a full Active Directory lab — Windows Server domain controller, workstations with deliberate misconfigurations, and a Wazuh SIEM to see every attack from the blue side in real time.

VM LAB — PUBLIC VIEW
Proxmox virtualisation
  │
  ├── General test systems
  │     Controlled network access
  │
  └── Isolated security range
        Attacker workstation
        Vulnerable targets
        No route to home devices

Next
  Active Directory practice range
  Defensive monitoring
  Repeatable attack/detection labs

The network design is evolving toward stronger separation between administration, private services, research systems, everyday devices and deliberately vulnerable training targets. Exact addressing and firewall rules are intentionally not published.

M
Management
Firewall, Proxmox, TrueNAS — admin access only
S
Servers
Docker services, Plex/Jellyfin, self-hosted apps
L
Lab / VMs
Proxmox VMs with controlled access rules
X
Offensive Security
Fully isolated — no outbound except controlled rules
H
Home LAN
Daily driver PCs — normal internet access
I
IoT
Smart plugs, TVs, consoles — isolated from lab
FUNCTIONAL LAYERS
Internet │ ▼ [Network Boundary] │ ├── Everyday devices ├── Private services ├── Virtualisation └── Isolated research range
DEFENCE IN DEPTH
External traffic │ ▼ [Firewall + policy] │ ├── Management zone ├── Private service zone ├── Home-device zone ├── IoT zone └── Research zone — isolated by default
📡
Next Radio Experiments
  • Improve weather-satellite reception and decoding
  • Signal Hub — one interface for shared radio workloads
  • AIS ship tracking — 161–162 MHz
  • ACARS — real aircraft data-link messages
  • POCSAG pager decoding — 153 MHz
  • rtl_433 — decode IoT devices on 433 MHz
  • RF band scanner — build a local signal catalogue
🟣
Purple Team AD Lab
  • Windows Server 2022 DC with deliberate misconfigurations
  • BloodHound + SharpHound — graph AD attack paths
  • Kerberoasting, Pass-the-Hash, DCSync practice
  • Wazuh SIEM — see every attack from the blue side
  • Write detection rules for the attacks just run
🏠
IoT Research
  • Inventory and isolate authorised smart-home devices
  • Explore local control without cloud dependencies
  • Analyse what devices phone home — block telemetry
  • rtl_433 research with owned compatible devices
  • Home Assistant — unified smart home control
🍯
Deception Lab
  • Isolated decoy services for defensive learning
  • Centralise and visualise captured events
  • Write detections from observed behaviour
  • Keep research separated from private services
💾
NAS + Storage
  • HP MicroServer Gen8 — TrueNAS SCALE
  • 4× 10–12TB drives in RAIDZ2
  • SMB + NFS shares, iSCSI for Proxmox
  • ZFS snapshots every 4–6 hours
  • Offsite backup to Backblaze B2
🔧
Infrastructure as Code
  • Ansible — automated config across all machines
  • Terraform + Proxmox — spin VMs up/down as code
  • Extend existing metrics, alerting and recovery checks
  • k3s Kubernetes cluster across Proxmox VMs