Step-CA: Build a Private Certificate Authority for Your Homelab
Stop accepting self-signed certificate warnings. Deploy Smallstep's step-ca as a fully automated internal PKI — complete with ACME support, Traefik integration, and browser trust.
Hands-on projects to build your skills and infrastructure
What You'll Need
Each project lists prerequisites and hardware requirements
Estimated Time
Projects range from 1 hour to multi-day builds
Stop accepting self-signed certificate warnings. Deploy Smallstep's step-ca as a fully automated internal PKI — complete with ACME support, Traefik integration, and browser trust.
Build a production-grade security incident response platform using TheHive 5, Cassandra, Elasticsearch, and MinIO — then integrate it with Wazuh alerts...
Build an automated vulnerability scanning pipeline using ProjectDiscovery's Nuclei and companion tools — subfinder, httpx, and naabu — to continuously...
Deploy a self-hosted phishing simulation platform using Gophish in Docker. Build real-world phishing campaigns, track user engagement, and run security...
Aggregate, deduplicate, and track security findings from 100+ scanners in a unified dashboard. Build a production-grade vulnerability management pipeline...
Deploy OpenCTI to aggregate, correlate, and visualize threat intelligence from MISP, NVD, AlienVault OTX, and Shodan — all in a self-hosted Docker stack.
Deploy Shuffle, the open-source SOAR platform, to automate security workflows and orchestrate your homelab tools — from Wazuh alerts to enrichment lookups...
Deploy Teleport's open-source privileged access management platform to replace static SSH keys with short-lived certificates, enforce MFA, record every...
Deploy a full Wazuh stack in Docker to gain host-based intrusion detection, file integrity monitoring, vulnerability scanning, and active response across your…