Virtualization platform
Proxmox hosts the firewall, domain controller, Windows client, Ubuntu server, and macOS guest with documented compute, storage, bridge, and lifecycle context.
Home Lab · Cross-platform infrastructure operations
I built this personal lab to practice systems administration safely. It combines Proxmox virtualization, pfSense routing, Windows Server and Active Directory, a Windows client, Linux01 on VLAN 30, and MACVM01 as a macOS domain member with SSH and VNC administration.
Environment overview
The environment supports bounded practice with virtualization, routing, identity, name resolution, endpoint integration, remote administration, backup operations, troubleshooting, and evidence-based documentation.
Proxmox hosts the firewall, domain controller, Windows client, Ubuntu server, and macOS guest with documented compute, storage, bridge, and lifecycle context.
pfSense provides routing and segmentation. DC01 supplies DNS and DHCP. Linux01 uses VLAN 30, while MACVM01 is placed on the pfSense-managed LAN through vmbr1.
DC01 provides Active Directory Domain Services, DNS, DHCP, Group Policy, Global Catalog, and FSMO roles for Windows, Linux, and macOS integration practice.
Remote administration, service checks, backup review, isolated restore procedures, integrity records, and technical documentation support repeatable operations.
Systems
Each system demonstrates a different part of the infrastructure relationship.
VM inventory, virtual hardware, storage, bridges, backup coverage, guest placement, and approved lifecycle operations.
AD DS, DNS, DHCP, Group Policy, Global Catalog, FSMO ownership, domain identity, and infrastructure service validation.
Windows domain membership, secure channel, captured network state, and workstation integration with the lab domain.
VLAN 30 placement, DNS, routes, SSH, Kerberos, realmd, SSSD, domain identity resolution, logging, updates, and remediation validation.
Proxmox deployment, corrected bridge placement behind pfSense, Active Directory binding, computer account, mobile domain user, DNS, SSH, VNC, hostname, and network-time validation.
Firewall and routing context, LAN and VLAN paths, OpenVPN management access, and bounded isolated restore validation.
Skills demonstrated
Windows domain membership, Linux realmd and SSSD integration, macOS Active Directory binding, computer objects, mobile accounts, Kerberos-aware configuration, and identity resolution.
Forward and reverse lookup validation, domain-qualified hostnames, DNS assignment, TCP reachability, gateway review, and troubleshooting across routed paths.
VM resources, OVMF and Q35 guest configuration, Linux bridges, VLAN placement, pfSense routing, guest isolation, and lifecycle management.
PowerShell, SSH, VNC, macOS Screen Sharing, local and domain account administration, and evidence capture from management systems.
Scheduled backup review, archive inventory, preboot NIC isolation, bounded restore tests, cleanup, and conservative result classification.
Runbooks, validation output, screenshots, manifests, SHA-256 hashes, public-safe sanitization, explicit limitations, and reviewer-oriented case studies.
Isolated restore validation
Temporary Proxmox VMs were created with preboot NIC isolation, checked only within authorized scope, shut down, and removed. The results remain deliberately bounded.
The restored Ubuntu guest booted, responded through the guest agent, supported bounded identity and system checks, and was cleaned up.
The restored firewall booted with both NICs isolated. Live routing, NAT, firewall policy, DHCP, DNS forwarding, and VPN behavior were not tested.
The VM reached the Windows sign-in screen, remained isolated, shut down cleanly, and was removed.
NTDS, SYSVOL, NETLOGON, and selected core services were observed, while strict network isolation limited local LDAP validation.
Reviewer artifacts
Evidence boundary
This personal nonproduction lab does not prove enterprise production ownership, high availability, enterprise Apple fleet administration, Apple Business Manager, MDM, full firewall assurance, full security assurance, complete disaster recovery, RTO, RPO, SLA performance, or continuous availability. Each result applies only to the system, action, and observation documented in its case study.