Skip to content

thomelab overview

thomelab is a self-hosted homelab. This page lists what it runs. For how it's built, see Architecture. For how Claude Code operates in this environment, see Claude access.

Photos and files

  • Immich — photo and video library, with mobile backup.
  • Nextcloud — file storage and sync, with in-browser document editing via Collabora Online.

Media

  • Audiobookshelf — audiobook and podcast server.

Notes and documents

  • HedgeDoc — collaborative Markdown notes.
  • CryptPad — collaborative office documents (encrypted).
  • Paperless-ngx — document archive with OCR.
  • Karakeep — bookmark manager with AI-assisted tagging (via a local Ollama instance).
  • Joplin — note-taking sync server, with Keycloak SSO.

Finance

  • Actual Budget — personal budgeting, with Keycloak SSO. Supports multiple users and per-budget access control, each with their own login.

AI

  • Ollama — local LLM inference.

Communication

  • Matrix / Element — chat, with bridges to Discord, Signal, Slack, Telegram, and WhatsApp.

Utilities

  • Homepage — dashboard of quick links to the apps on this page, behind oauth2-proxy SSO.
  • Vaultwarden — password manager (Bitwarden-compatible).
  • ntfy — push notifications, used by other services and automation.
  • Gatus — service status monitoring.
  • Keycloak — single sign-on for the apps above that support it.

Development

  • Harbor — private container registry.
  • Devcontainers — browser-accessible development environments (Thomas's and Claude's), each scoped to its own user and access level. See Claude access.

How this is maintained

Most of the code and configuration in this project — application manifests, automation scripts, this documentation — is written by Claude (Anthropic's LLM), run via Claude Code inside a devcontainer with deliberately limited, auditable access. See Claude access for what that access is and isn't.