ProxMox
Standalone node proxmox (proxmox.lan.podval.org, 192.168.1.40).
PVE 9.2.21 (packages updated 2026-10-07). Running kernel 7.0.14-20-pve
(booted 2026-10-07). Installed kernels: 7.0.14-20, 7.0.14-15, 7.0.14-12, and 7.0.14-5. apt now offers to autoremove 7.0.14-5. Leave that kernel installed. ZFS 2.4.4-pve1, including the module
shipped with 7.0.14-20. Hardware: i9-12900K (24 threads), 64G RAM, boot NVMe KINGSTON SKC3000D2048G. Bridge vmbr0 on enp3s0, 192.168.1.40/24, gw 192.168.1.1. Host iGPU is Intel AlderLake-S GT1, /dev/dri/renderD128 on the hypervisor (not passed to the docker VM) — see [[Frigate]] § iGPU passthrough.
PVE storage: local (dir /var/lib/vz, ISO/backup) and local-lvm
(thin pool pve/data on the NVMe).
Guests
| ID | Type | Name | LAN IPv4 | Role |
|---|---|---|---|---|
| 100 | VM | haos | 192.168.1.209 | [[Home Assistant]] OS. ssh
ha. 4G RAM, 2 cores, 32G disk |
| 101 | VM | docker | 192.168.1.187 | [[Docker]] / [[DevPod]] / [[Frigate]]. ssh docker. 32G RAM,
16 cores (cpu: host), 100G disk |
| 103 | LXC | cloudflare-ddns | 192.168.1.235 | Dynamic DNS (k39.podval.org). 3G disk |
| 105 | LXC | unifi-os-server | 192.168.1.184 | [[UniFi]] OS (controller). Not the switch at 192.168.1.101 |
| 106 | LXC | tailscale | 192.168.1.237 | Tailscale subnet router for 192.168.1.0/24. 1G RAM, 1 core, 4G disk, Debian
13 |
LXC 104 (cloudflared, .236) was destroyed 2026-09-16. Its
UniFi fixed-IP reservation was removed 2026-10-07. The remote path is LXC 106 (tailscale, static 192.168.1.237). Tailscale 1.102.5 is on the tailnet as tailscale (100.82.39.37, tailscale.tailc87f26.ts.net). It advertises
192.168.1.0/24 only. That route is not enabled yet. Peers cannot use it until it is turned
on for this machine in the Tailscale admin console. It does not run Grok, is not an exit node, and does
not use Tailscale SSH. See [[Domains]].
All guests: onboot: 1, vmbr0. 103 and 105 carry the community-script tag.
LXC 103/105/106 are unprivileged with nesting. 106 also has keyctl=1 and /dev/net/tun so Tailscale can open its tunnel. No snapshots when last inventoried.
On 2026-09-01 12:45 EDT the host itself came back from an unclean
stop (no reboot in the journal, EFI dirty bit, journal “uncleanly shut down”, guest ext4
recovery). Same kernel as before (7.0.14-12-pve). No UPS/NUT/IPMI log, no qmreboot. startall then started 100/101/103–105. Docker/Frigate fallout: [[Frigate]].
HAOS USB passthrough (do not steal these off VM 100):
0bda:2832Realtek RTL2832U (rtl_433)303a:831aNabu Casa ZBT-2 (Zigbee)303a:4001Nabu Casa ZWA-2 (Z-Wave)
Docker VM hostname docker. Does not use virtiofs (no virtiofs / fsN in 101.conf). Do not attach it — it
hangs UEFI boot. Frigate is NFS from /mnt/data/apps/frigate to 192.168.1.187
only; guest mounts /frigate.
Community Scripts
There is a lot of extremely helpful scripts for installing various things on ProxMox: https://community-scripts.github.io/ProxmoxVE/scripts.
Post-install
# bash -c "$(wget -qLO - https://github.com/community-scripts/ProxmoxVE/raw/main/misc/post-pve-install.sh)"
Dynamic DNS
I use cloudflare-ddns LXC (103). Binary /usr/local/bin/cloudflare-ddns +
/etc/cloudflare-ddns.env (mode 600). Do not restore go run
…@latest — that filled the 3G disk.
Running Docker Containers
As recommended, I use a [[Virtual Machines]] to run [[Docker]] containers.
In ProxMox shell, run the community script:
$ bash -c "$(wget -qLO - https://github.com/community-scripts/ProxmoxVE/raw/main/vm/docker-vm.sh)"
I use this VM to run [[DevPod]] workspaces locally - and to run docker compose stacks like [[Frigate]].
Passing the host iGPU into that VM for Frigate VAAPI is planned (not done): see [[Frigate]] § iGPU passthrough. It needs a PVE reboot. Do not start it until I ask.
TODO in July 2026 suddenly this VM started hanging up on start! - possibly because of the virtfs?
Terminal
To make arrow keys etc. work when connected to the container over SSH and such, inside the container
make the symbolic link from /bin/sh to /bin/bash.
File Store
In ProxMox shell:
# lvcreate -V1T -T pve/data -n store
# mkfs.ext4 /dev/mapper/pve-store
# mkdir /mnt/store
In ProxMox /etc/fstab, add:
/dev/pve/store /mnt/store ext4 0 1
And then mount:
# mount /mnt/store
That LV sat on the same thin pool as the VMs. Filling it could make the pool
read-only and stall guests. Media (Audio, Books, Music, OpenTorah, Pictures, Videos) moved to /mnt/data. On 2026-08-21 the empty filesystem was unmounted, the fstab line dropped, and pve/store removed (lvremove). Thin pool pve/data dropped from ~50% to ~3%. There is no /mnt/store anymore. Do not recreate
it.
RAID File Store
I added a bunch of hard disks to my ProxMox box and created a BTRFS RAID; this is where I want to store my photographs and other media.
I perused:
If at some point I decide to add my RAID as storage to ProxMox:
If needed, get rid of the stale madm RAID membership metadata: in ProxMox shell:
# wipefs -af /dev/sdc
# wipefs -af /dev/sdd
## reboot for ProxMox to re-read disks metadata
In ProxMox shell:
## make the RAID filesystem
# mkfs.btrfs -draid1 -mraid1 /dev/sdc /dev/sdd -L "Big Data"
## get UUID etc.
# btrfs filesystem show /dev/sdc # or /sdd
## create mountpoint
# mkdir /mnt/data
In ProxMox /etc/fstab, add:
UUID=<UUID> /mnt/data btrfs defaults 0 1
And mount:
# systemctl daemon-reload
# mount /mnt/data
/mnt/data is Btrfs RAID1 label Big Data on /dev/sdc+/dev/sdd (2×4T WD Red). Photo/media (including Calibre under Books/) + [[Frigate]] NFS source. ~25% used. Pictures/originals uses the
gphoto-sync layout YYYY/MM/DD (renamed from YYYY/YYYY-MM/YYYY-MM-DD on
2026-08-21).
sda/sdb (2×2T WD): leftover md127 superblocks from the old
/mnt/data. Array is stopped; /etc/mdadm/mdadm.conf has ARRAY <ignore> UUID=dbc353c9:9eddf842:f209850f:8c30d5ea and AUTO -all. Do not
start it. Superblocks not wiped.
sde (500G) old backup disk; not mounted. No vzdump/PBS jobs; /var/lib/vz/dump is empty. Later: scheduled vzdump of 100/101/105 (and the small
LXC if wanted) onto sde or PBS — not onto local-lvm next to the guests.
Mount
To mount a directory from the host in an LXC container:
- in the ProxMox shell:
$ pct set <container id> -mp0 /path/on/host,mp=/path/in/container
For additional mounts use -mp1 etc.
To mount a directory from the host in a virtual machine (see post):
- in the ProxMox UI
Datacenter | Directory Mappingsadd a mapping from name/tag to the path on the host - in the settings of the virtual machine
Hardware | Virtiofspass it in - in the guest virtual machine, create a mountpoint
- in the guest:
sudo mount -t virtiofs <tag> <mountpoint> - in the guest
/etc/fstab, add:<tag> <mountpoint> virtiofs defaults,nofail 0 0
Backlinks
Domains4
- k39.podval.org A record is not in Pulumi. [[ProxMox]] LXC 103 (cloudflare-ddns) updates it. Keep it that way.
- DDNS on [[ProxMox]] LXC 103: DNS Edit on podval.org only. Keep zone-scoped; acc...
- ...e Assistant]] can do it also - but why bother? I am running [[ProxMox]] , so adding a dedicated Dynamic DNS client seems the way to...
- ...t use Cloudflare Tunnel for admin SSH. The subnet router is [[ProxMox]] LXC 106 (tailscale, 192.168.1.237, tailnet 100.82.39.37). I...