The monthly homelab security checklist

Saturday morning, ninety minutes, coffee. This is the monthly routine that keeps a homelab from drifting into the "we'll get to it" swamp. Print it, bookmark it, set a recurring calendar event — whatever makes it actually happen.

Patching

CVE status review

SSH

TLS

Firewall and exposure

Backups

Secrets

Hardware + power

Documentation

The meta-rule

The monthly checklist doesn't need to be perfect. It needs to happen. Ninety minutes of consistent attention beats six hours every six months, because the stuff in the list is easier to fix when there's one month of drift to undo, not six.

Noxen automates most of the scan-and-diff parts of this list nightly, so the monthly review becomes "read the diff report, apply the patches, check the boxes." That's the intent — less maintenance, more actual reviewing.