Skip to main content
M.ALRASHID
HOME LABNETWORKINGAI SECURITYJune 12, 20265 min read

My home lab: an HP Z440 with a few different jobs

Proxmox, local AI, and Plex on one HP Z440, plus the network around them. What I run and what I want to learn next.

My home lab is built around an HP Z440. It runs my own services and gives me somewhere to experiment without turning every change into a work problem.

The hardware is a mix of workstation parts, storage, and GPUs with different jobs. The security side is what makes it useful to me. I get to decide what can reach what, manage access, and check that I can recover when something goes wrong.

The hardware

The main parts in my setup are:

  • HP Z440 chassis. An older workstation that I use as the base for the lab.
  • Intel Xeon E5-2696 v4. 22 cores with a 2.20 GHz base clock.
  • Two 32 GB DDR4 ECC registered memory modules: a Samsung M393A4K40CB1-CRC and a Kingston KVR24R17D4/32, both rated at 2400 MT/s. The rated speed isn't necessarily what the system actually runs them at.
  • MSI SPATIUM M480 PRO 1 TB NVMe SSD, mounted on a GLOTRENDS PCIe adapter because the Z440 has no native M.2 slot. It replaced my PNY CS900 SATA SSD.
  • WD Red Plus 12 TB drive for bulk storage.
  • Two RTX 3060 12 GB cards, one ZOTAC Twin Edge and one EVGA XC Gaming, for the local AI setup.
  • Sparkle Intel Arc A310 ECO 4 GB for Plex transcoding.

This is my configuration, not a verified compatibility list. The E5-2696 v4 in particular is an E5-2600-series processor, while the Z440 QuickSpecs I have list the E5-1600 v3/v4 family. If you copy a workstation build like this, check the exact board, firmware, cooling, and power requirements for your own system.

The same goes for the NVMe drive. A PCIe 4.0 SSD on an adapter doesn't turn the host slot into PCIe 4.0. The link runs at whatever the host supports.

What runs in the lab

Proxmox is the base. The services include internal DNS with filtering, a reverse proxy with automated TLS renewal, media and file services, scheduled backups, and service health monitoring.

None of that is especially unusual to self-host, but each piece gives me a real problem to understand and maintain. DNS affects whether services can be found, the proxy changes the path to an application, certificates have to renew, and storage has to be recoverable.

The network matters more than the dashboard

I separate the lab, IoT, and management networks with VLANs and firewall rules. The point is to limit access between systems that have different jobs and different trust levels.

The question I care about is whether a device can reach something it shouldn't. An IoT device shouldn't get a path to the management interface just because both live in my house. A test service shouldn't need the same permissions as the system running the lab.

That ties into my interest in zero trust. Segmentation helps control reachability, but it doesn't replace authentication or authorization inside an application. I still need to know which identity is connecting and what it's allowed to do.

When I change a rule, the useful checks go both ways: the connection I meant to allow still works, and the connection I'm trying to prevent actually fails.

Backups have to turn back into something usable

The lab has scheduled backups and restore validation. A completed backup job is useful information, but the result I care about is a service I can bring back and use.

For me, a restore check should include the application and its data, then the dependencies needed to reach it. A recovered VM isn't much help if I don't have the configuration or credentials to operate it.

I also keep snapshots and backups separate in my head. A convenient rollback point on the same system doesn't cover every storage failure or accidental deletion. Proxmox's backup documentation is a good reference for its backup and restore options.

Local AI has its own access questions

The two RTX 3060s give me a place to experiment with local inference and security tooling. Each card has 12 GB of VRAM. They don't automatically behave like one 24 GB card; how a model uses both depends on the software and the workload.

Keeping inference local is useful to me, but it doesn't answer every security question. If I give a model tools, those tools still need restricted access. A model doesn't need the management network or private credentials just because it runs on hardware I own.

That's also why agent permissions have their own post in this notebook.

Where I want to take it

I'm building pentesting skills, and I want the lab to support that with isolated test systems, repeatable exercises, and notes that explain what I observed.

I'd like to get better at connecting the two sides: finding a weakness, understanding the path it opens, putting a control in place, and testing the same path again. Having the hardware is useful. Being able to explain what I learned from it matters more to me.

Mohammed Alrashid

Security Engineer at PassiveLogic. Interested in pentesting, zero trust, and learning through a home lab.

Contact

Keep reading