homelab-as-code
A two-machine cybersecurity homelab, entirely Ansible-managed: an isolated libvirt pentest range (Kali attack box, DVWA, Juice Shop, Metasploitable2) reachable only from inside the mesh, a scaled-down detection stack (Suricata IDS + CrowdSec + Loki/Grafana), fleet-wide observability (Prometheus, Uptime Kuma), and a public status dashboard served over a Cloudflare Tunnel. Everything reproducible from a bare Ubuntu install.