kawsar-Latitude-5300-2-in-1 · online

A laptop that runs like a VPS.

This page is server-rendered by Next.js on a Dell Latitude sitting on a desk — reachable from anywhere, deployed through a self-hosted PaaS, with no cloud bill.

kawsar@kawsar-Latitude-5300-2-in-1: ~
$ uptime
  up 37h, load 2.96, 2.94, 2.87
$ free -h | grep Mem
  15.4G total, 7.5G used
$ tailscale funnel status
  https://predev-from-kawsar-home-server.tail0fceaf.ts.net (Funnel on)
  |-- / proxy http://127.0.0.1:80
$ docker ps --format '{{.Names}}'
  latitude  coolify  coolify-proxy  coolify-db ...
$ ▍
01 · Live stats

Real numbers, read at render time.

CPU
18%
load 2.96 · 2.94 · 2.87
Memory
7.5/ 15.4 GB
49% in use
Disk
46.4/ 467.9 GB
10% used · NVMe
Uptime
1d 13h 35m
kernel 6.14.0
CPU temp
59°C
cool
Battery (built-in UPS)
80%
not charging
Intel Core i5-8365U · 8 threadsrendered 2026-10-05 21:52:16 UTC · via Tailscale Funnel
02 · Architecture

Two doors in. One public, one private.

Visitors only ever touch the proxy. The dashboard and shell stay inside a WireGuard network that only your devices can join.

LATITUDE 5300 · LINUX MINT 22.3HTTPSDEPLOYSVisitorspublic internetYouphone · laptopTailscale Funnel*.ts.net · TLSTailnetWireGuard VPNTraefik:80 · host/path rulesThis siteYour projectsCoolify:8000 dashboardSSHTailscale SSHDocker enginecontainers · volumesufw · fail2banauto security updates
Public trafficPrivate (tailnet only)
03 · Stack

Everything a VPS has, nothing rented.

OS

Linux Mint 22.3

Ubuntu 24.04 base on a Dell Latitude 5300 — 8 cores, 16 GB RAM, NVMe. Sleep and lid-suspend disabled.

Network

Tailscale

WireGuard mesh VPN. Reach the box from anywhere — no public IP, no port forwarding, works behind a phone hotspot.

Edge

Tailscale Funnel

Publishes the proxy to the internet with automatic HTTPS at a *.ts.net hostname.

PaaS

Coolify

Self-hosted Vercel/Heroku. Deploys from GitHub, manages env vars, databases, logs and backups.

Proxy

Traefik

Routes each request by hostname and path to the right container.

Runtime

Docker

Every app and database runs isolated in its own container and restarts on boot.

04 · Deploy

From git push to public URL.

Push code

Commit to GitHub. Coolify's GitHub App sees the push.

Build

Nixpacks or your Dockerfile builds an image on this laptop.

Route

Traefik picks it up from the domain you set — http://…ts.net/path.

Live

Funnel serves it over HTTPS to the whole internet. Seconds, not minutes.

05 · Security

Hardened by default.

  • Private control planeCoolify dashboard and SSH are reachable only inside the tailnet.
  • Key-only rootPermitRootLogin prohibit-password; Tailscale SSH for humans.
  • Firewallufw default-deny inbound; only the ports the stack needs.
  • fail2banBans IPs that brute-force SSH.
  • Unattended upgradesSecurity patches install automatically.
  • No open router portsCarrier NAT stays closed; all ingress comes through Tailscale.