Home Lab · Cross-platform infrastructure operations

A working lab for Windows, macOS, Linux, identity, networking, and virtualization practice.

I built this personal lab to practice systems administration safely. It combines Proxmox virtualization, pfSense routing, Windows Server and Active Directory, a Windows client, Linux01 on VLAN 30, and MACVM01 as a macOS domain member with SSH and VNC administration.

Environment overview

One lab, multiple operating systems, shared infrastructure services.

The environment supports bounded practice with virtualization, routing, identity, name resolution, endpoint integration, remote administration, backup operations, troubleshooting, and evidence-based documentation.

HOST

Virtualization platform

Proxmox hosts the firewall, domain controller, Windows client, Ubuntu server, and macOS guest with documented compute, storage, bridge, and lifecycle context.

NET

Network services

pfSense provides routing and segmentation. DC01 supplies DNS and DHCP. Linux01 uses VLAN 30, while MACVM01 is placed on the pfSense-managed LAN through vmbr1.

IAM

Identity services

DC01 provides Active Directory Domain Services, DNS, DHCP, Group Policy, Global Catalog, and FSMO roles for Windows, Linux, and macOS integration practice.

OPS

Operations

Remote administration, service checks, backup review, isolated restore procedures, integrity records, and technical documentation support repeatable operations.

Systems

Cross-platform systems directly represented in the lab.

Each system demonstrates a different part of the infrastructure relationship.

Virtualization

Proxmox VE

VM inventory, virtual hardware, storage, bridges, backup coverage, guest placement, and approved lifecycle operations.

Identity services

DC01 · Windows Server

AD DS, DNS, DHCP, Group Policy, Global Catalog, FSMO ownership, domain identity, and infrastructure service validation.

Windows endpoint

WS01

Windows domain membership, secure channel, captured network state, and workstation integration with the lab domain.

Linux endpoint

Linux01 · Ubuntu

VLAN 30 placement, DNS, routes, SSH, Kerberos, realmd, SSSD, domain identity resolution, logging, updates, and remediation validation.

macOS endpoint

MACVM01 · macOS

Proxmox deployment, corrected bridge placement behind pfSense, Active Directory binding, computer account, mobile domain user, DNS, SSH, VNC, hostname, and network-time validation.

Routing and segmentation

pfSense

Firewall and routing context, LAN and VLAN paths, OpenVPN management access, and bounded isolated restore validation.

Skills demonstrated

The lab connects endpoint work to the services behind it.

ID

Cross-platform identity

Windows domain membership, Linux realmd and SSSD integration, macOS Active Directory binding, computer objects, mobile accounts, Kerberos-aware configuration, and identity resolution.

DNS

DNS and service access

Forward and reverse lookup validation, domain-qualified hostnames, DNS assignment, TCP reachability, gateway review, and troubleshooting across routed paths.

VM

Virtualization and networking

VM resources, OVMF and Q35 guest configuration, Linux bridges, VLAN placement, pfSense routing, guest isolation, and lifecycle management.

CLI

Remote administration

PowerShell, SSH, VNC, macOS Screen Sharing, local and domain account administration, and evidence capture from management systems.

BKP

Backup and restore operations

Scheduled backup review, archive inventory, preboot NIC isolation, bounded restore tests, cleanup, and conservative result classification.

DOC

Documentation and evidence

Runbooks, validation output, screenshots, manifests, SHA-256 hashes, public-safe sanitization, explicit limitations, and reviewer-oriented case studies.

Isolated restore validation

Selected backup archives were exercised without connecting temporary guests to normal lab networks.

Temporary Proxmox VMs were created with preboot NIC isolation, checked only within authorized scope, shut down, and removed. The results remain deliberately bounded.

Linux01 · PASS

Scoped restore objectives passed.

The restored Ubuntu guest booted, responded through the guest agent, supported bounded identity and system checks, and was cleaned up.

pfSense · Narrow PASS

Local isolated objectives passed.

The restored firewall booted with both NICs isolated. Live routing, NAT, firewall policy, DHCP, DNS forwarding, and VPN behavior were not tested.

WS01 · INCONCLUSIVE

Restore and boot succeeded; in-guest validation was unavailable.

The VM reached the Windows sign-in screen, remained isolated, shut down cleanly, and was removed.

DC01 · INCONCLUSIVE

Selected services passed; LDAP-dependent checks remained inconclusive.

NTDS, SYSVOL, NETLOGON, and selected core services were observed, while strict network isolation limited local LDAP validation.

Reviewer artifacts

Stable routes for deeper technical review.

Evidence boundary

What this lab does not prove.

This personal nonproduction lab does not prove enterprise production ownership, high availability, enterprise Apple fleet administration, Apple Business Manager, MDM, full firewall assurance, full security assurance, complete disaster recovery, RTO, RPO, SLA performance, or continuous availability. Each result applies only to the system, action, and observation documented in its case study.