Skip to content
DarshBhilwaraPublic

About

A security focused homelab built on Ubuntu Server and Docker, featuring centralized monitoring, log aggregation, intrusion detection, secure networking, and self-hosted services for learning, experimentation, and infrastructure management.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

56 Commits

Folders and files

Repository files navigation

Sisyphus

./dashboard.png

Intro

Sisyphus is a security-first, homelab focused on blue-team detection, monitoring, and incident response, built on Ubuntu Server. The project is named so because of the number of times I had to start over everything while working on this.

The project focuses on:

  • intrusion detection
  • logging and monitoring
  • network visibility
  • secure remote access
  • general homelab things

Current Hardware

  • HP Laptop
  • Intel i5 (8th gen)
  • 240GB SSD (OS)
  • 1TB HDD (data)

Setup

1. Ubuntu Server

  • Refer os-setup for setting up the operating system.

2. Docker Installation and Setup

sudo apt install docker.io docker-compose tmux

Add your user to the docker group:

sudo usermod -aG docker $USER

Move the docker storage to HDD (by default, it stores in /var/lib/docker)

sudo mkdir -p /etc/docker
sudo nano /etc/docker/daemon.json

Add

{
  "data-root": "/data/docker"
}

Restart docker

sudo systemctl restart docker

Reboot and verify

docker info | grep "Docker Root Dir"

should give

Docker Root Dir: /data/docker

3. Set up SSH server with firewall hardening

  • Do this by yourself by finding the best ways to authenticate through SSH and connect it to the internet with atmost security. (this is of the most importance but cannot share it because of obvious reasons)

4. Set up VPN and Reverse Proxy

  • Refer vpn-setup for setting up VPN and reverse proxy..

5. Disable sleep

sudo systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target

Next, we will make the system work even when lid is closed. In the file sudo nano /etc/systemd/logind.conf, add this:

HandleLidSwitch=ignore
HandleLidSwitchDocked=ignore
HandleLidSwitchExternalPower=ignore

6. Setting up directories

mkdir homelab
cd homelab
mkdir core storage monitoring security apps
cd /data 
sudo mkdir docker nas backups logs configs
sudo chown -R $USER:$USER /data

7. Homelab services

To set up homelab services, refer homelab-services

8. Blue Team Stack

Now that we have a fully functional homelab with all applications running, we are gonna install all the blue team softwares required for cybersecurity. Refer blue-team-stuff

Backups, Cron Jobs and Scripts

Now that we have a fully functioning homelab with all the blue team softwares, we will go on to set up backups, cron jobs and scripts..

10. Other Tweaks

Connection

If the connection on SMB is slow,

sudo iw dev wlan0 set power_save off

In the file /etc/samba/smb.conf, add:

[global]
server min protocol = SMB2
socket options = TCP_NODELAY IPTOS_LOWDELAY
read raw = yes
write raw = yes
max xmit = 65535

Comments while making the project

  • 4th March 2026 - This project was supposed to be set up with kubernetes but after I learned the whole thing and installed k3s, the RAM usage went up to 2GB and my current infrastructure cannot support the whole working with kubernetes added to it. So yeah, sadly after wasting two days on it, I have to pivot away from it.
  • 7th March 2026 - I changed the dashboard from Homepage to Homarr because of the ease of setting it up and it generally looks better.
  • 9th March 2026 - I have removed a full-fledged SIEM from my homelab because it was not possible to run on my hardware.

About

A security focused homelab built on Ubuntu Server and Docker, featuring centralized monitoring, log aggregation, intrusion detection, secure networking, and self-hosted services for learning, experimentation, and infrastructure management.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages