Raspberry Pi recovery architecture · 2025
Home Lab
Designed and tested a resource-constrained home-lab stack with private administration, public access, and encrypted offsite recovery.
Restore tested1h 45m
Case snapshot
- Problem
- Operate multiple services on one 8GB Raspberry Pi behind CGNAT while keeping administration private and recovery practical.
- My role
- System architect and operator.
- What I changed
- Separated public application traffic from private administration.
- Budgeted memory explicitly across more than eleven containers.
- Documented and tested encrypted offsite recovery.
- Result
- A full restore completed in 1 hour 45 minutes; 96GB of backup storage cost $2.82 per month at the recorded point in time.
Context, decisions, and evidence
One small machine had production-like responsibilities
The lab hosted public and private services on a Raspberry Pi 4 with 8GB RAM, a 1TB external drive, consumer internet, and no available port forwarding.
Resource and recovery constraints shaped every decision
The design had to preserve operating-system headroom, remain below a small external-service budget, and recover without depending on the failed node.
Simple orchestration fit the actual topology
Docker Compose avoided single-node Kubernetes overhead. Cloudflare Tunnel and Caddy served public traffic, Tailscale handled private administration, and container memory limits made capacity explicit.
Recovery was tested rather than assumed
Encrypted rclone backups went to Backblaze B2. The documented restore playbook completed a full test in 1 hour 45 minutes, while the recorded 96GB backup cost was $2.82 per month.
Architecture evidence includes operations
The useful proof is not the number of services. It is the connection between constraints, decisions, measurable limits, and a recovery process that was actually exercised.
Technical depth
Original project pages, reports, and technical writing remain available as source material.