Journal — J. Choo Portfolio Ed.
in progress planned shipped > migrated

Jocelyn Choo

Solutions Engineer DevOps

runs a family media platform and a DevOps lab off three machines in the same rack.

Building a 3-node Proxmox homelab, GitOps pipelines, and infrastructure-as-code. Solutions Engineer by day, DevOps by night.

family-prod · uptime 99.9%
Jocelyn Choo pg. 01 — profile

Collection · pg. 02

Great things are yet to be done

Journal Entry

Currently a Solutions Engineer in Hong Kong, building homelab-infra on the side — a 3-node Proxmox cluster that's both my family's private cloud and a production-grade DevOps playground: Terraform, Ansible, K3s, ArgoCD, and CI/CD, all as code.

"Live like no one else today, so that you can live like no one else tomorrow." — Dave Ramsey

Experience 2+ yrs System Engineering 1+ yr Backend Development
Education B.Sc. Internet & Multimedia Technologies Associate of Arts in Computer Science

Collection · pg. 03

The toolchain

DevOps Tools

Core stack

  • Linux — experienced
  • Shell & Bash scripting — intermediate
  • Build tools — intermediate
  • Python — experienced
  • Docker — experienced
  • GitOps · ArgoCD — basic
CI/CD Automation

Pipeline & cloud

  • Jenkins — intermediate
  • AWS Cloud — intermediate
  • AWS EKS — basic
  • Kubernetes — basic
  • Terraform — intermediate
  • Ansible — intermediate
  • Prometheus & Grafana — intermediate
  • GitLab CI — basic

Collection · pg. 04

homelab-infra

A 3-node Proxmox homelab, built in public — a family media platform and a Kubernetes/DevOps playground, everything as code. Phase 1 is live: the family tier runs on a single node with a zero-downtime cutover already behind it. Core infra and the disposable K3s lab — torn down and rebuilt on purpose, monthly — are next: if it isn't in git, it doesn't exist.

Proxmox VE 9 Terraform Ansible + Vault Docker Compose Cloudflare Tunnel Tailscale K3s ArgoCD Jenkins · JCasC GitLab CI Prometheus · Grafana · Loki
GitHub Repo Design Decisions (ADRs)
Diagram

Architecture pg. 05

Homelab architecture diagram

Traffic enters through a Cloudflare Tunnel (no open ports) straight to Jellyfin and Nextcloud — the only two services made public. Proxmox and every other admin plane are reachable over Tailscale only, never publicly. Core infra (G11) and the disposable K3s lab (the MacBook) are the next two nodes to join the cluster.

○ planned

5-Minute Demo Video pg. 06

One git push travels through CI, security scanning (Trivy), and ArgoCD to a live Kubernetes rollout — recorded end to end.

○ phase 2

Live Proof pg. 07

Public Grafana snapshot / Uptime Kuma status page showing the real cluster, really running — landing once observability is migrated.

○ phase 5

The AWS Party Trick pg. 08

./demo.sh up stands up a mini k3s lab on AWS spot in ~4 minutes and prints a live URL; ./demo.sh down tears it down — a few cents per run, nothing left behind.

Collection · pg. 10

Let's build something

Index jocelyn_cys@jchoo.me LinkedIn GitHub