Standalone node proxmox (proxmox.lan.podval.org, 192.168.1.40). PVE 9.2.21 (packages updated 2026-10-07). Running kernel 7.0.14-20-pve (booted 2026-10-07). Installed kernels: 7.0.14-20, 7.0.14-15, 7.0.14-12, and 7.0.14-5. apt now offers to autoremove 7.0.14-5. Leave that kernel installed. ZFS 2.4.4-pve1, including the module shipped with 7.0.14-20. Hardware: i9-12900K (24 threads), 64G RAM, boot NVMe KINGSTON SKC3000D2048G. Bridge vmbr0 on enp3s0, 192.168.1.40/24, gw 192.168.1.1. Host iGPU is Intel AlderLake-S GT1, /dev/dri/renderD128 on the hypervisor (not passed to the docker VM) — see [[Frigate]] § iGPU passthrough.

PVE storage: local (dir /var/lib/vz, ISO/backup) and local-lvm (thin pool pve/data on the NVMe).

Guests

ID Type Name LAN IPv4 Role
100 VM haos 192.168.1.209 [[Home Assistant]] OS. ssh ha. 4G RAM, 2 cores, 32G disk
101 VM docker 192.168.1.187 [[Docker]] / [[DevPod]] / [[Frigate]]. ssh docker. 32G RAM, 16 cores (cpu: host), 100G disk
103 LXC cloudflare-ddns 192.168.1.235 Dynamic DNS (k39.podval.org). 3G disk
105 LXC unifi-os-server 192.168.1.184 [[UniFi]] OS (controller). Not the switch at 192.168.1.101
106 LXC tailscale 192.168.1.237 Tailscale subnet router for 192.168.1.0/24. 1G RAM, 1 core, 4G disk, Debian 13

LXC 104 (cloudflared, .236) was destroyed 2026-09-16. Its UniFi fixed-IP reservation was removed 2026-10-07. The remote path is LXC 106 (tailscale, static 192.168.1.237). Tailscale 1.102.5 is on the tailnet as tailscale (100.82.39.37, tailscale.tailc87f26.ts.net). It advertises 192.168.1.0/24 only. That route is not enabled yet. Peers cannot use it until it is turned on for this machine in the Tailscale admin console. It does not run Grok, is not an exit node, and does not use Tailscale SSH. See [[Domains]].

All guests: onboot: 1, vmbr0. 103 and 105 carry the community-script tag. LXC 103/105/106 are unprivileged with nesting. 106 also has keyctl=1 and /dev/net/tun so Tailscale can open its tunnel. No snapshots when last inventoried.

On 2026-09-01 12:45 EDT the host itself came back from an unclean stop (no reboot in the journal, EFI dirty bit, journal “uncleanly shut down”, guest ext4 recovery). Same kernel as before (7.0.14-12-pve). No UPS/NUT/IPMI log, no qmreboot. startall then started 100/101/103–105. Docker/Frigate fallout: [[Frigate]].

HAOS USB passthrough (do not steal these off VM 100):

  • 0bda:2832 Realtek RTL2832U (rtl_433)
  • 303a:831a Nabu Casa ZBT-2 (Zigbee)
  • 303a:4001 Nabu Casa ZWA-2 (Z-Wave)

Docker VM hostname docker. Does not use virtiofs (no virtiofs / fsN in 101.conf). Do not attach it — it hangs UEFI boot. Frigate is NFS from /mnt/data/apps/frigate to 192.168.1.187 only; guest mounts /frigate.

Community Scripts

There is a lot of extremely helpful scripts for installing various things on ProxMox: https://community-scripts.github.io/ProxmoxVE/scripts.

Post-install

# bash -c "$(wget -qLO - https://github.com/community-scripts/ProxmoxVE/raw/main/misc/post-pve-install.sh)"

Dynamic DNS

I use cloudflare-ddns LXC (103). Binary /usr/local/bin/cloudflare-ddns + /etc/cloudflare-ddns.env (mode 600). Do not restore go run …@latest — that filled the 3G disk.

Running Docker Containers

As recommended, I use a [[Virtual Machines]] to run [[Docker]] containers.

In ProxMox shell, run the community script:

$ bash -c "$(wget -qLO - https://github.com/community-scripts/ProxmoxVE/raw/main/vm/docker-vm.sh)"

I use this VM to run [[DevPod]] workspaces locally - and to run docker compose stacks like [[Frigate]].

Passing the host iGPU into that VM for Frigate VAAPI is planned (not done): see [[Frigate]] § iGPU passthrough. It needs a PVE reboot. Do not start it until I ask.

TODO in July 2026 suddenly this VM started hanging up on start! - possibly because of the virtfs?

Terminal

To make arrow keys etc. work when connected to the container over SSH and such, inside the container make the symbolic link from /bin/sh to /bin/bash.

File Store

In ProxMox shell:

# lvcreate -V1T -T pve/data -n store
# mkfs.ext4 /dev/mapper/pve-store
# mkdir /mnt/store

In ProxMox /etc/fstab, add:

/dev/pve/store /mnt/store ext4 0 1

And then mount:

# mount /mnt/store

That LV sat on the same thin pool as the VMs. Filling it could make the pool read-only and stall guests. Media (Audio, Books, Music, OpenTorah, Pictures, Videos) moved to /mnt/data. On 2026-08-21 the empty filesystem was unmounted, the fstab line dropped, and pve/store removed (lvremove). Thin pool pve/data dropped from ~50% to ~3%. There is no /mnt/store anymore. Do not recreate it.

RAID File Store

I added a bunch of hard disks to my ProxMox box and created a BTRFS RAID; this is where I want to store my photographs and other media.

I perused:

If at some point I decide to add my RAID as storage to ProxMox:

If needed, get rid of the stale madm RAID membership metadata: in ProxMox shell:

# wipefs -af /dev/sdc
# wipefs -af /dev/sdd
## reboot for ProxMox to re-read disks metadata

In ProxMox shell:

## make the RAID filesystem
# mkfs.btrfs -draid1 -mraid1 /dev/sdc /dev/sdd -L "Big Data"
## get UUID etc.
# btrfs filesystem show /dev/sdc # or /sdd
## create mountpoint
# mkdir /mnt/data

In ProxMox /etc/fstab, add:

UUID=<UUID> /mnt/data btrfs defaults 0 1

And mount:

# systemctl daemon-reload
# mount /mnt/data

/mnt/data is Btrfs RAID1 label Big Data on /dev/sdc+/dev/sdd (2×4T WD Red). Photo/media (including Calibre under Books/) + [[Frigate]] NFS source. ~25% used. Pictures/originals uses the gphoto-sync layout YYYY/MM/DD (renamed from YYYY/YYYY-MM/YYYY-MM-DD on 2026-08-21).

sda/sdb (2×2T WD): leftover md127 superblocks from the old /mnt/data. Array is stopped; /etc/mdadm/mdadm.conf has ARRAY <ignore> UUID=dbc353c9:9eddf842:f209850f:8c30d5ea and AUTO -all. Do not start it. Superblocks not wiped.

sde (500G) old backup disk; not mounted. No vzdump/PBS jobs; /var/lib/vz/dump is empty. Later: scheduled vzdump of 100/101/105 (and the small LXC if wanted) onto sde or PBS — not onto local-lvm next to the guests.

Mount

To mount a directory from the host in an LXC container:

  • in the ProxMox shell:
$ pct set <container id> -mp0 /path/on/host,mp=/path/in/container

For additional mounts use -mp1 etc.

To mount a directory from the host in a virtual machine (see post):

  • in the ProxMox UI Datacenter | Directory Mappings add a mapping from name/tag to the path on the host
  • in the settings of the virtual machine Hardware | Virtiofs pass it in
  • in the guest virtual machine, create a mountpoint
  • in the guest: sudo mount -t virtiofs <tag> <mountpoint>
  • in the guest /etc/fstab, add: <tag> <mountpoint> virtiofs defaults,nofail 0 0