The homelab tool map

The map from The Tools Behind My Homelab and How They Fit Together at full width. On a narrow screen, scroll sideways.

How my homelab tools are stitched together Forty-five tools in a map, with labelled connections. Delivery: Renovate opens merge requests in GitLab, which holds the Ansible repository, the cluster repository and the container registry. GitLab is the home of the infrastructure as code: the OpenTofu and Ansible repositories live there, and its CI runners apply the OpenTofu code and run the Ansible playbooks that render the Docker Compose stacks. OpenTofu also manages Cloudflare DNS, the Tunnel and Access apps, and configures Authentik, Grafana and Garage (marked with a square); for the cluster they commit new image tags to the cluster repository, which Flux pulls from GitLab and reconciles into the Kubernetes cluster. Talos Linux is the immutable, API-only operating system of its nodes; OpenTofu defines the Proxmox VMs and the cluster; Ansible renders the Docker Compose stacks. Secrets: Vault feeds External Secrets, which creates the pod secrets in Kubernetes, and Vault is also read by Ansible at deploy time. Identity: Cloudflare Tunnel reaches Traefik, Authentik adds forward auth to Traefik, and GitLab, Vault, Grafana, Immich, Paperless and Linkwarden sign in with Authentik via OIDC. Backups: the apps' stack-back sidecars write restic repositories to Garage at home and GitLab backups go to Garage too; only one rclone sync leaves the house, copying the Garage buckets offsite to Backblaze B2; Observability: Traefik access logs go to Alloy, which ships logs to Loki and metrics to Prometheus; Grafana reads Loki, Prometheus and Tempo. Notifications: Flux, GitLab CI, Uptime Kuma and Grafana alerts all post to Mattermost. Apps: Immich, Paperless, Linkwarden, Solidtime, Home Assistant, Music Assistant, Jellyfin, AudioMuse, RomM, UniFi Network and LiteLLM run in the lab, most of them as Docker stacks. Agents: Claude Code and OpenCode connect to the self-built MCP gateway, which signs in with Authentik and routes to seven MCP servers: Immich, Paperless, Linkwarden, Jellyfin, Observability (Prometheus, Loki and Tempo), Google Workspace (Calendar and Contacts) and Vast (GPU models). Six are my own code, Google Workspace is an upstream project. The gateway reaches the Docker apps and the observability stack. tool calls tool calls routes photos, docs, bookmarks, playlists metrics + logs Claude Codecoding agent OpenCodecoding agent MCP gatewayself-builtone URL, one loginOAuth viaAuthentik MCP servers behind the gateway Immich MCPphotos · search, albums Paperless MCPdocs · search, tag Linkwarden MCPdocs · bookmarks Jellyfin MCPmusic · playlists Observability MCPops · metrics, logs, traces Google Workspace MCPgoogle · calendar, contacts Vast MCPai · GPU models Six are my own code,Google Workspace is upstream. opens MRs IaC code,CI runners IaC code,CI runners git + registry reconciles runs DNS, Tunnel, Access VMs cluster secret store pod secrets deploy lookups Compose stacks Tunnel forward auth deploy notices CI results alerts alerts access logs ships logs logs remote write traces rclone sync restic repo stack-back run as stacks backups Proxmox VEhypervisors Talos Linuximmutable OS Kubernetesagents, apps External SecretsVault to Secrets OpenTofuinfra as code GitLabgit · CI · registry FluxGitOps Vaultsecret store CloudflareDNS · Tunnel Renovateversion bumps Mattermostchat Ansibleconfig Traefikreverse proxy Authentiklogin · SSO Uptime Kumastatus checks DockerCompose hosts Grafana Alloylog + metric agent Lokilogs Grafanadashboards · alerts Prometheusmetrics Tempotraces Backblaze B2B2 · offsite GarageS3 object store resticvia stack-back Apps Immich Paperless-ngx Linkwarden Solidtime Home Assistant Music Assistant Jellyfin AudioMuse RomM UniFi Network LiteLLM signs in with Authentik (OIDC)managed by OpenTofu How my homelab tools are stitched together Simplified for small screens, the full map is in the viewer. Delivery: Renovate opens merge requests in GitLab, GitLab hands git and images to Flux, Flux reconciles the Kubernetes cluster; GitLab CI runners also apply OpenTofu and run Ansible, which renders the Docker stacks. Identity: Cloudflare Tunnel reaches Traefik, which asks Authentik for forward auth. Secrets: Vault feeds External Secrets, which creates the pod secrets in Kubernetes, and is read by Ansible at deploy time. Backups: restic and GitLab write to Garage at home, one rclone sync copies Garage offsite to Backblaze B2. Observability: Grafana Alloy ships logs to Loki and metrics to Prometheus, Grafana reads both and alerts go to Mattermost. Apps: Immich, Paperless, Linkwarden, Solidtime, Home Assistant, Music Assistant, Jellyfin, AudioMuse, RomM, UniFi Network and LiteLLM. Agents: Claude Code calls the self-built MCP gateway, which signs in with Authentik and routes to the MCP servers in front of the apps. One git push to production Renovate opens MRs GitLab git + registry Flux reconciles Kubernetes OpenTofu + Ansible: code in GitLab, run by CI One login for everything Cloudflare Tunnel Traefik forward auth Authentik signs in with Authentik (OIDC) Secrets never in git HashiCorp Vault secret store External Secrets pod secrets Kubernetes HashiCorp Vault deploy lookups Ansible Backups leave the house once restic restic repo Garage rclone sync Backblaze B2 GitLab backups Garage Logs, metrics and alerts Grafana Alloy logs, metrics Loki Prometheus read by Grafana alerts Mattermost Agents and the MCP gateway Claude Code tool calls MCP gateway Apps Docker run as stacks Immich Paperless-ngx Linkwarden Solidtime Home Assistant Music Assistant Jellyfin AudioMuse RomM UniFi Network LiteLLM