René Welches

TECH NOTES TO MYSELF

Running Debian 13 in UTM on Apple Silicon

Native ARM64 virtualization with a Debian netinstall ISO — no emulation required

Step-by-step guide to creating a Debian 13 (Trixie) ARM64 virtual machine in UTM on an Apple Silicon Mac using the Virtualize mode for near-native performance.

Running Your Own Root CA for the Homelab

What started as a GitHub README turned into a proper blog post

How to create a self-signed Root CA for your homelab, sign server certificates, and trust them on macOS and Linux — including the git gotcha that the macOS Keychain won't tell you about.

Upgrading My 'Frankenstein-cluster': MOREFINE M8 Replaces the MINIX

A newer, faster node for $120 net after selling the old one

I picked up a MOREFINE M8 mini PC (Intel N150, 16GB DDR4, 1TB NVMe) for $219.99 and sold my old MINIX NEO J50C-4 Plus on eBay for $100, netting a solid upgrade for just $120.

Fixing Twingate DNS Resolution with AdGuard Home

Moving connectors to separate hosts fixed my DNS resolution issues

How to fix Twingate DNS resolution issues when using the Home Assistant connector with AdGuard Home by moving connectors to separate Proxmox hosts.

Automating Docker Container Deployment on Proxmox with Terraform

Using SSH Agent authentication to provision Docker containers in LXC containers - and why Ansible is next

Learn how to use Terraform with SSH agent authentication to automatically deploy Docker containers in Proxmox LXC environments. Includes practical examples and discusses why Ansible is better suited for configuration management.

Expanding My Proxmox Cluster: Minisforum UM700 for $69

Adding a refurbished mini PC to my homelab cluster

A $75 refurbished Minisforum UM700 (Ryzen 7 3750H) makes a perfect second node for a Proxmox cluster. Step-by-step guide on creating a cluster, joining nodes, and understanding quorum with practical command references.

Securing Proxmox API Tokens with Apple Keychain Access for Terraform

Store and retrieve Proxmox credentials securely using macOS Keychain instead of plain text files

Securely manage Proxmox API tokens for Terraform using macOS Keychain Access. Eliminates plain text credential files and integrates seamlessly with automated Terraform workflows.

Starting My Homelab Journey

Building a Proxmox-based homelab with GMKtec NucBox M5 Ultra and setting up SSL certificates

Starting a homelab with a $256 GMKtec NucBox M5 Ultra (Ryzen 7 7730U) and Proxmox VE. Includes setting up self-signed SSL certificates for secure HTTPS across all homelab services including Home Assistant.

Secure Home Network Access with Twingate

Alternative setup to Pi-Hole and Pi-VPN with Twingate, Home Assistant and AdGuard Home

Modern zero-trust VPN setup using Twingate for secure home network access, with AdGuard Home for local DNS resolution. No port forwarding or DDNS required - a simpler alternative to Pi-Hole and PiVPN.