
Tailscale Subnet Router
Make hybrid networking boring: route securely from your Tailscale tailnet into a dedicated homelab VLAN using a Proxmox LXC subnet router, with a least-privilege ACL model, clear failure modes, and a validation checklist.

Make hybrid networking boring: route securely from your Tailscale tailnet into a dedicated homelab VLAN using a Proxmox LXC subnet router, with a least-privilege ACL model, clear failure modes, and a validation checklist.

A pragmatic way to provision a “hybrid” homelab: local Proxmox VMs plus one (or more) Hetzner Cloud nodes acting as public ingress, with clean boundaries and a safe handoff into configuration management.
Descriping my homelab setup, the hardware used, the main components and a short introduction into the Software stack.