custom built 5600ge with lots of extra 10Gb NICs, systemd-networkd /w bridges, vlans, policy routing, nftables fw, coredns + blocky for dns, dnsmasq for dhcp, runs some extra/misc nspawn containers due to extra capacity, also a locked down caddy which fronts all the misc access point, managed switch etc. web interfaces so they are easier to access (including from my wireguard)