The Disposable Basement Data Center: Inside KourR/homelab-mischa

How one developer uses enterprise GitOps, Talos Linux, and Azure Key Vault to turn an ephemeral home cluster into a bulletproof Quantified Self engine.

8 min read • KourR/homelab-mischa

A pristine server rack suspended by a thread over an incinerator, next to an immovable iron safe bolted to bedrock, illustrating the separation of ephemeral compute and persistent state.
The Jotunheim application cluster is built to be destroyed at a moment's notice, while the Data cluster remains locked down and immutable.
Mischa van den Burg

I've maintained a Kubernetes home lab for 300 days straight. Here's my setup: • 3 worker nodes running Talos Linux • Latest K8s version (always updated) • Full monitoring stack • 7 database clusters with triple redundancy • Cloud backup integration • Custom IoT integration tracking bedroom temperatures • GitOps with Flux CD • Cloudflare tunnel for secure external access Everything is public on GitHub with 1000+ commits. Everything is maintained like a production environment. Everything is documented and automated.

— Mischa van den Burg, LinkedIn
Key Takeaways

The Art of the Disposable Cluster

Most self-hosted homelabs are fragile monoliths. They start as weekend experiments and slowly mutate into indispensable, undocumented pets that require careful feeding and manual upgrades. The KourR/homelab-mischa repository takes the opposite approach. It treats a basement server rack with the operational rigor of a Fortune 500 production environment.

This architecture is built on a philosophy of stateless compute. By physically separating the application layer from the database layer via a multi-cluster GitOps architecture, the main application cluster becomes entirely ephemeral. There are no in-place upgrades. When a major system change is required, the entire cluster can be wiped and restored from a Git repository in minutes.

Two Realms: Jotunheim and Data

The foundation of this setup is Talos Linux, an immutable and API-driven operating system designed explicitly for Kubernetes. But the true architectural breakthrough is the strict multi-cluster boundary.

The repository orchestrates two distinct clusters through FluxCD. The first is "Jotunheim," named after the Norse realm of giants. This is the user-facing application cluster. It runs APIs, dashboards, and ingress controllers. It holds no persistent state. The second is the "Data" cluster, a locked-down fortress running PostgreSQL instances managed by the CloudNativePG operator.

A central "Git Repo" node splits into two distinct deployment pipelines. Path A leads to the "Jotunheim Cluster" containing App pods and Ingress nodes. Path B leads to the "Data Cluster" containing highly available PostgreSQL nodes and Backup CronJobs. When a user clicks "Push Commit (App Update)"

If Jotunheim suffers a catastrophic failure, the owner simply reinstalls Talos Linux on the nodes and points FluxCD back to the repository. The applications spin back up, reconnect to the untouched Data cluster, and resume normal operations without data loss.

A Private Quantified Self Engine

The standard homelab trope usually revolves around media streaming. This repository subverts that expectation. It operates as a highly secure, zero-trust data ingestion engine for personal analytics.

A mechanical hand holding an antique pocket watch connected to a modern data cable, symbolizing the ingestion of human metrics into a digital system.
Instead of serving media files, the cluster ingests continuous telemetry from health devices, smart home sensors, and personal notes.

Instead of Plex and Radarr, the application manifests reveal custom microservices like health-api, shelly-api, and zettelkasten-tracker. These Python sidecars bridge the physical world and the database, ingesting metrics from Apple Health, Oura rings, and local IoT devices.

To keep these custom APIs updated without manual intervention, the repository leverages Flux Image Automation. When a new container image is pushed to the GitHub Container Registry, Flux detects the change and automatically commits the new version string back to the Git repository.

# apps/base/zettelkasten-tracker/deployment.yaml
spec:
  containers:
    - name: zettelkasten-tracker
      # Flux automatically updates this tag via the imagepolicy marker
      image: ghcr.io/kourr/zettelkasten-tracker:v1.2.4 # {"$imagepolicy": "flux-system:zettelkasten-tracker"}
      env:
        - name: DB_HOST
          value: n8n-db.mischavandenburg.net

Enterprise Secrets in the Living Room

Managing secrets is the Achilles heel of most GitOps setups. Many developers resort to storing encrypted secrets directly in Git using tools like SOPS. This repository opts for a cloud-native enterprise pattern using the External Secrets Operator (ESO).

By integrating with Azure Key Vault, the repository ensures that no sensitive data ever touches the Git commit history. Flux manages the YAML definitions of what secrets are required, and the cluster fetches the actual credentials directly from Azure at runtime.

# infrastructure/configs/base/external-secrets/cluster-secret-store.yaml
apiVersion: external-secrets.io/v1beta1
kind: ClusterSecretStore
metadata:
  name: azure-backend
spec:
  provider:
    azurekv:
      authType: ServicePrincipal
      vaultUrl: "https://homelab-vault.vault.azure.net"
      authSecretRef:
        clientId:
          name: azure-creds
          key: ClientID
          namespace: external-secrets

Networking is handled with equal sophistication. Instead of relying on a proprietary router, the cluster uses Cilium, an eBPF-based networking tool. Cilium handles Layer 2 ARP announcements, allowing the Kubernetes services to broadcast their own IP addresses directly to the local home network.

The Homelab Spectrum

The homelab-mischa repository represents the high-complexity, high-resilience end of modern self-hosting. It stands in stark contrast to newer trends prioritizing single-binary simplicity or autonomous AI agents.

Project Architecture Primary Focus Complexity Level
homelab-mischa Multi-Cluster Kubernetes (Talos + Flux) Resilience, strict GitOps, data sovereignty High (Enterprise patterns)
oweibor/homelab Docker + Hardware-optimized Scripts Local AI (Ollama), Intel QuickSync media Low (One-command deploy)
homebutler Single Go Binary + MCP Server Management via NLP and LLM ChatOps Medium (AI integration focus)

This GitOps approach is not for everyone. It requires understanding Kustomize overlays, BGP networking, and automated reconciliation loops. But for developers who want to treat their personal data with the same reverence a bank treats its ledgers, the disposable multi-cluster architecture provides an unmatched blueprint.


Sources: KourR/homelab-mischa Repository, LinkedIn Activity.