KWS BUILD PATHS · 01 — BUILD MY HOMELAB

One spare computer.
A guided path to your private home server.

Build My Homelab is a self-paced Build Path from spare machine to a private home server you actually understand: real apps for your home and family, safe remote access, backups you have restored with your own hands — with your own AI agent doing the building, and not a single open port. When it's running, you own more than apps: a foundation for everything you build next.

No open ports by default Backup before any risky step Works with the AI agent you already use
Rendered scene: a black 3D-printed mini rack on a maker workbench at night, a compact server module glowing warm amber inside it, hand tools on a pegboard behind
FIG. 01 — FROM PRINTED SHELL TO LIVING SERVER
THE PROBLEM

The information exists. The path doesn't.

Search "home server" and fifteen minutes later you're deep in Proxmox versus Ubuntu, contradicting r/homelab threads, and security warnings from people who forgot what starting feels like. And AI will confidently hand a port-forwarding answer to someone who has never tested a backup.

The problem isn't missing information. It's overload — with no order, no context, and no safety net.

LIVED PROOF

Not theory. This is what actually runs at Ilan's home.

Build My Homelab is built by Ilan Kushnir — the maker behind KWS Rack, the printed 10-inch rack system — out of a home server that runs for real, every day:

"AI can build you tools shockingly fast now. But a tool with nowhere to live stays a demo. Your home server is where those tools become part of your life."
— the idea the whole path is built on

These are real, daily uses — not a promise that everything takes ten minutes. Each one is a station on the path you'll walk yourself.

  • A smart home on a stable base

    Home Assistant with backups and private remote access — automations that survive a power cut, not a fragile late-night install.

  • A personal media library

    A folder of files turned into a real service: music and movies at home and on the road, without renting yet another interface.

  • A fitness app built with Claude Code

    Instead of another year of a paid generic app — a tool built for exactly how Ilan trains, running from his own server.

  • A personal Kanban board

    A task board that matches how Ilan thinks — instead of bending his work into someone else's template.

  • Document signing under his own roof

    Signing workflows on open-source, DocuSeal-style tools. For some workflows that's enough, cheaper, and fully yours.

  • KWS Rack — the physical side

    The lab lives in the printed rack Ilan designed. Same philosophy throughout: built deliberately, documented, made to grow.

LIVE FROM THE LAB

Real things, running right now from Ilan's home server

Not promises — workloads. These five run at Ilan's home as you read this, and each one replaced an app, a subscription, or a compromise.

Walk through all five — don't skip. Each takes ten seconds.

CASE 01 · PUMPY

A fitness app that trains the way Ilan trains

Ilan built Pumpy with Claude Code, and it runs from this very server — for him, his friends and his family. It works better for him than any generic fitness app for the simplest reason: it was built around exactly how he trains — and when his needs change, the app changes the same week.

Built with Claude CodeRuns for friends & familyPersonal by design
See Pumpy live ↗
CASE 02 · SMART HOME

The whole house, wired to one calm dashboard

Home Assistant runs the lights, the door lock, the electric blinds and the TV — alongside the routers, access points and a mesh of sensors and automations. And because the brain lives at home, not in a cloud, it keeps working even when the internet doesn't.

LightsDoor lockElectric blindsTVNetwork & sensors
CASE 03 · SELF-HOSTED

A whole catalog of apps — minus the subscriptions

Media, photos, documents, bookmarks, file sync — the self-hosted world has a serious app for almost anything. One home server runs a surprising number of them at once, and each one retires another monthly subscription.

Thousands of open appsOne serverZero subscriptions
Browse the catalog — selfh.st/apps ↗
CASE 04 · KANBAI

Kanbai — a task board that talks to his agent

Ilan's personal kanban. Built around exactly how he plans his work — and wired to his AI agent, so tasks get added, sorted and closed as part of the conversation, not in yet another form.

Built for his own flowConnected to his agentRuns from home
CASE 05 · PERSONAL AI

A private AI partner that actually lives at home

The one that changes everything: Ilan's personal agents — Hermes and Astra — run from this server, connected to his projects, his tools, his task board and a long-term memory. Not a cloud chatbot with amnesia — a partner that knows the house it lives in.

Persistent memoryConnected to home & toolsActually private
This is where the path leads ↓

This is the whole point of the path: not "learn Linux" — end up with things like these, running quietly at your place.

WHAT YOU BUILD

You don't study Docker. You build rooms.

Docker, Linux and networking are just the building materials. These are the rooms they become:

  • R–01 A media library Your family's movies and music as a real home service — not a forgotten folder, not another subscription.
  • R–02 A stable smart home Home Assistant on a reliable, backed-up base that survives a power cut.
  • R–03 Personal apps Tools you build with your own agent — and a real home for them to run from.
  • R–04 One front door A dashboard that gathers everything, reachable from your phone anywhere — via Tailscale, zero open ports.
  • R–05 A backup vault Not "backups configured" — "I broke it on purpose and brought it back myself." The restore drill is part of the path.
  • R–06 Confidence to keep going Knowing what runs on your machine and what is exposed — plus a roadmap for what you build next.

There are thousands of self-hosted apps — which is exactly where beginners get lost. The internet already offers infinite comparison. This path sells its absence: it picks the next win with you, for your goals.

Nobody actually wants Docker. You want a quiet path through the chaos, and something real running at home.

THE BUILD LOOP

Every step of the path is the same precise move

Not video chapters, not articles. One build loop, repeating from the first lesson to the last upgrade:

  1. Brief

    Why this step matters — one mental model, one diagram, two minutes.

  2. Decide

    A recommended default with its reasons. Not ten options — one, and why.

  3. Build with AI

    A ready prompt card for your agent, with context, boundaries and warnings.

  4. Verify

    One check you can see with your own eyes: it works, or it doesn't.

  5. Record

    A field or two in your Server Passport. Your server stays documented, always.

  6. Celebrate

    A capability you didn't have yesterday, stated plainly.

  7. Next

    Exactly one clear step forward. Not a menu. No getting lost.

And from Next — back to Brief. That's how a server gets built: loop after loop, no dangerous leaps.

THE BUILD PATH MAP

Floor by floor, at your pace

Not a dry syllabus, not a deadline — a build map. Every stage ends in something you can see and feel, nothing risky unlocks early, and the pace is set by your goals, hardware and time.

STAGE 01

Foundations: from computer to server

A sane hardware choice for your budget, Ubuntu Server or Proxmox installed to match your profile, and your AI agent wired into the process.

An ordinary machine became a breathing server. You SSH into it from across the room.
STAGE 02

First rooms: the server becomes useful

Docker Compose done properly, a management UI that doesn't scare you, and your first apps per your Blueprint — media, smart home, or a personal tool.

Something that used to live in the cloud, or in chaos, now runs at your place — and you understand how.
STAGE 03

A door and an address

A dashboard as the front door, internal names instead of IP addresses, and Tailscale — private access from your phone, anywhere in the world.

You opened your dashboard from a coffee shop. Without touching a single router port.
STAGE 04

Maturity: monitoring, backup, restore, security

A cockpit that shows everything is alive, real backups, a full restore drill, and a security review that shows exactly what's exposed and what isn't.

You broke it on purpose. You brought it back yourself. From that moment — it's truly yours.
GATED STAGE

Public exposure — an optional, gated stage

A domain, reverse proxy, HTTPS, and deliberately publishing one service to people you chose. Serious, orderly — and only for those who truly need it.

Locked until: restore drill passed + clean security review
NEXT PATHS

The labs that follow

A home AI agent, a personal-apps lab, a physical lab around KWS Rack. Your first server is the beginning, not the end.

Unlock after finishing the first path
YOUR BLUEPRINT

Same path. A different plan for every builder.

The onboarding questionnaire learns what excites you, how much experience you have, and what hardware is already lying around — then generates your KWS Blueprint: a personal build plan with a system path, first apps, your first win, and an honest "not yet" list.

Which one sounds most like you? Click to swap the plan:

KWS BLUEPRINT · PREVIEW DRAFT V0.1
ARCHETYPE Maker / rack builder
SYSTEM PATH Proxmox — one machine that looks and behaves like a real lab
HARDWARE A mini PC inside a 10-inch rack — tidy, cabled, documented
FIRST APPS
  • Homepage — the lab's status board
  • Uptime Kuma — monitoring every unit
  • A living spec page — hardware, wiring and decisions, documented
First win: a physical lab that looks the way you imagined — with a document behind it explaining every part.
NOT YET
Multi-node clusterUPS and power managementPublic exposure
Everything you build is recorded in your Server Passport — so prompts, recommendations and support truly know your server. The real Blueprint is generated from your answers and checked by AI Blueprint Review — a structured review built into the path.
STAGE-AWARE PROMPTS

Your agent does the building. The path does the protecting.

Every stage ships a prompt card written for your agent: with your server's context, the current stage's boundaries, and what must never be pasted. Copy it, run it, come back and verify the result.

  • Stage-aware. The prompt knows what you've built and what's still off-limits.
  • Safe by default. No secrets, no tokens, no suggestions to open ports.
  • Ends in verification. Every card says exactly how to confirm it worked — before you move on.

Works with Claude Code, Codex, ChatGPT and any similar agent — you bring the one you already use.

STAGE 04 · ACCESS — TAILSCALE Goal: reach your dashboard from your phone, anywhere, with zero open ports
Before pasting: no passwords, no keys, no tokens, no public IP. Facts about your server — yes. Secrets — never.
PROMPT · EN
You are my build companion for setting up Tailscale on my home server.

## Context
- OS: Ubuntu Server LTS (fresh install, updated)
- Apps run with Docker Compose under /opt/kws/stacks
- My dashboard (Homepage) works on the local network
- I am a beginner: explain every command in one sentence before I run it

## Goal
Reach my dashboard from my phone, away from home, privately.

## Hard rules
1. Do NOT suggest port forwarding or exposing anything to the internet.
2. Do NOT ask me for passwords, keys, or tokens. If a login is needed,
   tell me to complete it myself in the browser.
3. One step at a time. After each step, tell me exactly how to verify
   it worked before we continue.

Start by checking what we need to install, and wait for my output.

After the run, the card checks with you:

  • Your phone and server appear on the same Tailscale network
  • The dashboard opens on mobile data, not home WiFi
  • No port forwarding was added to the router — verified with your own eyes
SAFETY GATES

Safety isn't a warning. It's the order of the path.

Beginners don't read warnings — they follow the path in front of them. So on this path you physically cannot reach a risky step before its conditions are met. Three gates keep the order:

GATE 01 Always on

The comprehension gate

Before any risky command — formatting a disk, changing a firewall, deleting — the agent is instructed to stop until you explain in one sentence what the command does. You never run what you can't explain.

Built into every prompt card on the path.

GATE 02 Sequence gate

The backup gate

Advanced growth stages stay locked until a full restore drill has passed. Not "backups configured" — you actually restored, with your own hands.

If the server replaces part of your life, it must be restorable.

GATE 03 Locked

The exposure gate

Exposing a service to the internet unlocks only when every condition is met. Try it yourself:

The gate is locked. On the core path, not one port ever opens — and that's exactly the point.

  • Tailscale first. Remote access is private by default. Port forwarding is never presented as a normal step.
  • Secrets never meet AI. From the first lesson, one habit: passwords, keys and tokens are never pasted into a chat.
  • "Not yet" is a respectful answer. Kubernetes, VLANs and public exposure are named honestly — real, interesting, and not your first step.
THE FAIR QUESTION

"Why not just ask ChatGPT?"

Great question — and you genuinely should ask it, a lot. This path is built around your agent, not against it. But a good answer and a build path are two different things:

A smart chat ANSWERS

  • Answers the question you asked brilliantly — even when it's the wrong question for your stage
  • Will happily hand a port-forwarding answer to someone with no backups
  • Forgets between chats what you've built and what things are called on your machine
  • Gives five different approaches across five different chats
  • Leaves you alone with "wait — did that actually work?"

A Build Path SEQUENCES

  • Sequences. Knows what must happen before what, and what's still off-limits
  • Protects. Safety gates live inside the prompts — not in your memory
  • Remembers. The Server Passport records everything built, and every prompt knows it
  • Decides. One reasoned default instead of ten opinions, with a clear why
  • Verifies. Every step ends in a check you can see — before moving on

In short: your agent builds. The path gives it context, boundaries and sequence — and gives you the confidence that you're never one step from an unrecoverable mistake.

THE WAITLIST

The first build group is forming. Get on the blueprint.

Build My Homelab opens with a small first group, and this waitlist is literally how its timing and size get decided. Joining costs nothing and commits you to nothing — and if you're not sure yet, there's a place right here to just ask.

  • First to know when the path opens — before anyone else
  • The Blueprint questionnaire — your personal build plan, before you start
  • AI Blueprint Review — a structured review of your plan and server, built into the path instead of a human helpdesk
  • A real say in the path: during the pilot, your questions and stuck points directly shape what gets built next

Honestly: there's no fake "3 spots left" here. The first group is small because real guidance doesn't scale with a button — and your signup is a real vote for what opens first.

That email address doesn't look right — check it and try again.

No spam. One update when it opens, unsubscribe anytime, and your email is never passed on.

You're on the list. We'll write the moment the path opens — meanwhile, it's worth checking which computer is already waiting in your drawer.

Have a question?

Wondering if this is for you? About your hardware? The pace? Ask away - there are no obvious questions. This is not a support desk for existing servers; it is how you find out whether the path fits you.

That email address doesn't look right — check it and try again.
Write a little more — at least 12 characters, so we can give you a real answer.

The answer arrives by email from KWS Labs, from a kwslabs.com address - no bots, no mailing list.

Got it. We'll reply from a kwslabs.com address - usually within a day or two.
FAQ

The questions everyone asks. Straight answers.

Is this a KWS Rack product? Do I need the rack?

No. Build My Homelab is a separate product — a guided Build Path from the same maker. KWS Rack stays exactly where it lives, and nothing about its published files changes. A printed rack is a beautiful home for your server, and the path includes an optional physical-lab stage — but on day one, a shelf works just as well.

Do I need to know Linux to start?

No. You need technical curiosity and the willingness to run a command after it's been explained to you in one sentence. The path teaches each concept exactly when you need it — not in an intro lecture. If you've ever written code, managed a technical product, or set up a smart home, you have more than enough.

What hardware do I need? How much does it cost?

For most people: a used or new mini PC, or a computer already lying around. The Blueprint questionnaire recommends a hardware path for your budget and goals — including "don't buy anything yet, start with what you have". No hardware at all? There's a supported VPS path. A server closet is not required, promise.

Is it safe? I don't want to open my home to the internet.

Neither do we. On the core path, not a single router port is opened — remote access runs through Tailscale only, private and encrypted. Public exposure is an optional stage, locked behind a passed restore drill and a security review, meant only for people who truly need to publish something.

What exactly is supported — and what isn't?

Full transparency, so you don't find out midway:

  • Fully supported: Ubuntu Server, Proxmox for x86 builders who plan to grow, Docker Compose, a management UI, Tailscale, a curated app catalog, backups to USB, NAS or cloud.
  • Best effort: existing laptops with quirks, Raspberry Pi, Cloudflare Tunnel, apps outside the catalog.
  • Not yet: Kubernetes, multi-node clusters, advanced VLANs, TrueNAS or Unraid as the primary OS.

"Not yet" always means "not now, and here's why" — never a locked door without an explanation.

Who is this not for?

Better to say it here than after you sign up. This path isn't for you if:

  • You want Kubernetes from day one
  • You won't touch a terminal at all, even fully guided
  • You're looking for a service that sets everything up for you
  • You plan to expose services to the internet before backups and security exist

If one of those is you — you'd likely be disappointed, and we'd rather save us both the time.

Which AI tool do I need? Does it only work with Claude?

You work with the agent you already have: Claude Code, Codex, ChatGPT or similar. Stage 0 of the path includes an agent-readiness check before anything else. The prompt cards are written to work in any capable agent, not just one.

What language is the path in?

English. The lessons, the Blueprint and every prompt card are written in English — agents are most precise with English infrastructure prompts, so that's also what you'll paste into yours. A Hebrew edition exists from the earliest pilot and may return later, but the path launches in English.

What happens when I get stuck?

Every stage has an escape lane: a Stuck Report template that produces an orderly failure report — what you expected, what happened, and the relevant log with secrets stripped — ready to paste into your agent or send to support. Getting stuck is part of learning; staying stuck isn't.

And what if I break something?

Early in the path you build a backup and run a full restore drill — you break it on purpose and bring it back. After that, a mistake isn't a disaster, just another lap of the loop. Genuinely risky stages simply don't unlock before that safety net exists.