Raspberry Pi recovery architecture · 2025

Home Lab

Designed and tested a resource-constrained home-lab stack with private administration, public access, and encrypted offsite recovery.

Case snapshot

Problem
Operate multiple services on one 8GB Raspberry Pi behind CGNAT while keeping administration private and recovery practical.
My role
System architect and operator.
What I changed
  • Separated public application traffic from private administration.
  • Budgeted memory explicitly across more than eleven containers.
  • Documented and tested encrypted offsite recovery.
Result
A full restore completed in 1 hour 45 minutes; 96GB of backup storage cost $2.82 per month at the recorded point in time.

One small machine had production-like responsibilities

The lab hosted public and private services on a Raspberry Pi 4 with 8GB RAM, a 1TB external drive, consumer internet, and no available port forwarding.

Resource and recovery constraints shaped every decision

The design had to preserve operating-system headroom, remain below a small external-service budget, and recover without depending on the failed node.

Simple orchestration fit the actual topology

Docker Compose avoided single-node Kubernetes overhead. Cloudflare Tunnel and Caddy served public traffic, Tailscale handled private administration, and container memory limits made capacity explicit.

Recovery was tested rather than assumed

Encrypted rclone backups went to Backblaze B2. The documented restore playbook completed a full test in 1 hour 45 minutes, while the recorded 96GB backup cost was $2.82 per month.

Architecture evidence includes operations

The useful proof is not the number of services. It is the connection between constraints, decisions, measurable limits, and a recovery process that was actually exercised.

Technical depth

Original project pages, reports, and technical writing remain available as source material.

← All work