Hi
I’m a watcher of the YouTube Homelab show of Tom’s.
Quite enjoy it
Stopping in here looking for ideas / sympathy with a big block of text (probably in the wrong place) and the hopes someone may have faced a similar challenge.
I have been solely managing my residential networks across multiple locations for a long while. There is a large shared estate in a remote location involved and other buildings locations. I have 2 to 7 lans at 3 locations frequented by mostly the same people but rarely at the same time.
For a small group of people the tech needs are high. Currently I have a great deal of L2 networking with some L3 a tiny bit L4 across multiple isp’s. Everyone is Tech field or adjacent in respective fields without a lot of “networking” overlap.
When everyone is in the same place at the same time it’s more like a medium sized lab than a residence.
The younger generation Data analysis.. Quant, electrical engineer, computer science has interest in spinning off their own segments now and I don’t mind passing the reigns.
Still I think I’m going to adopt some guard rails hence an interest in using something like Infisical for keys and secrets in containers. I get it’s overkill. I’d like to set them up with their own git tea / lab servers, I’ve read of PKI support? but am honestly unsure of support for self hosting that feature and across physical locations
It’s (infisical) what I’d consider a doable but larger Homelab project for myself, if I can learn from the experience of someone b4 me it would be appreciated.
Apologies for the blast of text.. I am also not opposed to using a Smallstep CA pi tutorial with some webhooks as outlined in the related Smallstep Ca with device attestation write up for distributed FIDO keys I have found. I liked the idea of handling site management that way with some Authentik as needed along with a certificate aware proxy. That is my preference of how I’d like to handle it. I have plenty of parked domain names suited for various resources and have played with the idea of multiple CAs
However
Recently I have decided it is time to unhappily begrudgingly accept Unify into my life. All my subnets and out buildings are filling up with Ubiquiti so much it’s time.
I would like to take advantage of some SSO to allow guests and visitors amounts of administrative network access / limited servers access and physical entry control access.
This is the sort of thing I did for a living for quite a long while and normally I’d say Entra ID, public key, Okta the usual suspects all 4.99 up per user per month as far as I can tell and I’m considering a dozen IDs used sporadically. To complicate matters no three people use the same current identity or verification methodology.
While Planning my new Unify deployment I was happy to see options for unlocking doors with cellphones and onboarding off boarding users but how can I host a solution for this type of access not for myself for the people who are there at any given time without incurring the identity provider costs for a dozen people who I want to enjoy and break and use what has been left there for them to do just that. It’s the identity management I can’t figure out. I’d tell myself Domain Controller / Azure directory / Cloud IAM.. but I don’t want to hear that
