Setting up a Raspberry Pi 4 home server
smalldata.tech
smalldata.tech
howto:
https://jamesachambers.com/raspberry-pi-4-usb-boot-config-gu...
$55 Pi 4 (4gb)
$8 Official USB charger
$25 Argon One case (could also get acrylic + ICE tower)
$10 microSD card
$12 Sata to usb adapter
$40 Kingston 240gb SSD (we can't do over 500mb/s anyway)
$120 Total
You get a significant performance boost switching to a 64-bit OS. aarch64 has better SIMD guarantees, hardware AES (over 10x faster), double the registers, and generally more optimizable due to the more streamlined ISA. I haven't tested it yet, but in-memory compression could potentially help with the 4gb RAM limit.If you don't mind the terrible $/gb ratio, you can even get USB3 thumbdrives that use an SSD.
https://ubuntu.com/blog/updated-images-of-ubuntu-for-the-ras...
At the time of writing however, the pi was an experiment and I figured that I would just have an extra drive to store stuff if the pi did not work out. In any case, since it's not being used as a regular computer, the SD card works fine, even when compiling stuff :)
Regarding DNS, the query string is encrypted on HTTPS. It can still be cached on logs on their side for example. It can be seen on the script, but the credentials would still have to be there somewhere.
I'm not quite sure what you mean by "Additionally out of the box fail2ban won't work with docker containers". fail2ban is installed locally on the pi.
If you had installed for example your web server on a container, the logs will be on the container. Fail2ban on the host won’t be able to parse the ones inside the container (by default, needs more work).
There's also a similar pam module called pam_tally2, which I haven't used.
In fact, here, it's automatically configured on each and every host at install-time (via the post-installation scripts in my kickstart files). I can't remember a time when I ever needed to "touch" it afterwards.
(A few years ago, I evaluated pam_tally2 vs. pam_faillock and settled on pam_faillock but, unfortunately, I can't recall what led me to that choice.)
---
[0]: In reality, though, it doesn't really do much. There's only two Internet-facing servers with 22/TCP open to the world -- the bastion hosts -- and only public-key authentication is permitted on those.
oh snap...because the logs are in the container. Hadn't thought of that. Good shout
Who is "anyone" in this context? At most, it would only be anyone that has access to logs and the Pi itself. A man-in-the-middle wouldn't see them because it's HTTPS.
I had big plans for using a Raspberry Pi as a Plex Media Server once. The set up was easy, I attached my external HDD and let it scan the libraries. My wife and I watched a few movies, it worked perfectly. The next evening when we sat down to watch a movie I saw that Plex couldn't connect to the media server. I went upstairs and attached a monitor to my Raspberry Pi and I saw that Wireless Internet was not working on it. I tried everything and eventually rebooted it and everything worked again. This turned into a daily thing. I followed all sorts of instructions I found on the internet to try and fix the issue, but to no avail. Every day there would come a certain time where the Raspberry Pi would just lose it's Wifi capabilities and a reboot was needed. Sad, because I liked the idea of this small box sitting on the corner of my desk running a media server. This was an older Raspberry Pi, maybe things have improved.
The real answer is that the instability that manifests overnight will eventually manifest while you’re watching a movie.
But the idea that it's WiFi that's unreliable is clearly not the case.
Something is wrong with the RPI WiFi chip, driver or OS configuration.
I had some network lag/dropped frames, turns out my stereo receiver was downloading a quite large firmware update. Had me freaked out a bit, I hadn't recorded the mac address. Didn't figure it out till I turned the TV on and saw a dialog asking if it should upgrade.
So, yes, generally I'd recommend that anything that's going to consume hours of 4k video be put on ethernet if at all possible.
Things like SmartTV, RPi, Solar Panels, Amplifier, etc. I hate it that Chromecast only has a wireless option.
But more on-topic, it shouldn't drop off WiFi just like that.
They're a little pricier, but the Chromecast "Ultra" supports ethernet out of the box. For the base model, you can get an adapter.
From what I've seen about Smart TV's, I'm better off not allowing them to ever connect to the Internet. Forgo all the "smart" features and just use a Fire TV stick, Roku, Chromecast, etc.
My current TV is an 8 year old 46-inch "dumb" TV, but I plan on upgrading to something bigger later this year, and it looks like my only options will have Smart features, but I already use a Fire TV stick and a RPi, so I don't think I need the smart features.
On top of that, it also runs my Pihole and a bunch of other services through Docker.
Bit of a revelation, really.
There are several attractive alternatives to RasPi (Odroid already mentioned, beware though as most of the small boards are 32bit only. Also Khadas VIM3, FriendlyELEC NanoPi, Rock Pi. Many people also seem to like Orange Pi). The earlier generation Raspis are honestly quite disappointing from a performance perspective, mostly because of the shared bus between Ethernet/Wifi/USB/storage. The 4B is actually the first to hold its ground, and still does price/performance-wise compared to the above. Honestly it feels like the market's stagnated a bit around the RK3399 and Allwinner H5/H6, hoping there's going to be a new wave of interesting stuff during 2020.
A really nice feature of some of these ARM boards is that you can go so much more free (as in libre) than with x86 chips. Raspberry Pi excluded, unfortunately.
If you're open to x86 and want a bit more power, Intel NUCs have been around for a good time and AMD is pushing out Ryzen NUCs now. First out is ASROCK. I've also been very happy with the PC Engines APU2 router boards - they are great as small-form-factor servers or NAS builds as well.
Note that even if Raspbian is 32-bit only, you can totally run 64-bit OS's on the 3B+ and 4 series.
For 3B+ there's even a pretty stable UEFI bootloader: https://www.raspberrypi.org/forums/viewtopic.php?f=50&t=2494...
For Raspi 4 you can just rebuild the kernel for aarch64 and change the config a bit. Or if you're lazy, sakaki- is providing weekly builds here: https://github.com/sakaki-/bcm2711-kernel
I have both 3B+ and 4B running vanilla 64-bit Debian Buster.
I just built a new server with a 12c/24t 3900x and bought 3x RPi4-4GB, the goal was to have the Pis and a couple of light-weight VMs run a Kubernetes cluster using K3s (I'm currently running 3 Alpine VMs as a cluster on the server, and planning to add the Alpine aarch64 on the 3 Pis. I was thinking of deploying OpenFAAS to the Pis for serverless functions and have more "heavy" services on the server. I'm a developer so it's more of an academic task than running production services (I have another home server running FreeNAS with my production services in jails).
The alternative would be the Hashi stack, and I want to work with Vault anyway as I'm looking at it for secret management in our infrastructure at work.
And yeah, my requirements in terms of performance are pretty light but my main candidate for whenever I need more power on a single node (though I guess I'd have to get at least two to keep my HA approach, so I want to see how far I can get with horizontally scaling SBCs first) is a mini-ITX with Ryzen 3900.
For internal DNS at least, you can just use consul. I set up dnsmasq to forward to consul on all of my machines which is super convenient (esp when that DNS just points to a docker container ipv6 address on the zerotier network, not port remapping on networking insanity needed)
The only thing I still need to figure out about this setup is that I currently use a single glusterfs volume for most of my nomad tasks, I would love to have a nomad integration that could provision and mount the gluster volume when I specify a volume for a docker task in nomad.
Haven't considered using glusterfs but the rest of those pieces, absolutely.
Only piece I could find similar to the topic is https://www.mockingbirdconsulting.co.uk/blog/2019-01-05-hash....
Integrating these three systems, with Terraform on top, is pretty time-consuming with all the policies and TLS certificates, but it seems pretty smooth to maintain after the initial setup.
I'm learning terraform/consul/nomad/vault as I build this thing, so I think the learning curve for me is extra painful compared to some of y'all.
The docs seem really good if everything is cloud-hosted and really nonexistent if you're running it all on your own metal.
I'm thinking I'll build out my test stack with vagrant. I can use Dropbox or Keybase or something similar to store and sync my terraform state if I need to. Any other hints or helpful readings?
For example, used ASUS Chromeboxes are all over eBay from $50-$120 or so with a real SSD, x86-64, nice enclosure, etc. And they are easy enough to use a SeaBios ROM with for regular Linux instead of ChromeOS.
Edit: not disputing the Pi is king at lower memory / lower storage / lower cost points.
I stuck in a spare ssd and 8TB drive. It is running Ubuntu.
Right now it acts as a pi hole, nextcloud server, Channels DVR server, Plex Media Server, and runs Transmission. It barely breaks a sweat.
I used to just have a Pi 3B+ doing duty as a pihole and nextcloud box.
This works better and overall cost less than the pi once I added in the sd card, case, fan, power supply.
I was sold on it after reading an enthusiastic Ars Technica review.[1] I quite liked the thing. Its specs were a little anemic out of the box, but despite being the size of a tupperware container, I was able to swap out the flash HD for a proper SSD, upgrade the RAM, and even swap out the WiFi card for a better model. It's still holding up as my media center five years later.
[0] http://www.hp.com/hpinfo/newsroom/press_kits/2015/2015CES/St...
[1] https://arstechnica.com/gadgets/2015/02/cheap-functional-upg...
Ryzen 7 2700 are cheap now. If I upgrade the ram and cpu I can make it a nice VM machine for very little.
Fortunately there are a lot of great options for SBCs now that are more powerful than the RPi. For example, I run an NVR for multiple cameras on the ODroid H2 which has a quad-core celeron, dual GbE, and 2x SATA - for only around three times the cost of the rpi 4 B. x86 isn't the best for power consumption but opens up options as far as OS. Due to video encoding rpi-based camera solutions often get close to requiring one rpi per camera!
I replaced my x86-based file server with the Kobol Helios4, an ARM-based SBC with 4x SATA. They've recently announced the Helios64 which will knock it up to 5x SATA with a faster ARM SOC, and comes with a hot-swappable drive enclosure that at least appears to rival the hardware of e.g. QNAP at a far lower price point.
I'd strongly recommend that people look around a bit on e.g. HackerBoards before assuming that an RPi is the best fit for their application. For example, a lot of people are running various 'single-purpose' network applications (e.g. pihole) on RPis when for not much more there are multiple options with multiple GbE ports and faster processors.
I disabled swap memory and overclocked it to 2ghz which was super easy. Switched to a Flirc case because my prio case with a fan was really loud.
For Wireguard I followed this guide: https://www.reddit.com/r/pihole/comments/bnihyz/guide_how_to...
check out homeserver too...more towards the low end of scale rather than "I've got a xeon beast in my basement" homelab
Side note, you can also use cloudflare free for dns, it's easy to setup.
Do you have your origin whitelisted to cloudflares edge ranges? If not it can be hilariously easy to get around cloudflare (ex: Hamas.ps is behind cloudflare but runs on Hetzner https://censys.io/ipv4?q=hamas.ps)
https://www.amazon.com/Geekworm-Raspberry-Storage-Matching-E...
> head to your router settings and port forward 80, 443, 22 and any other ports that you might want.
It's connected to my wifi router via an ethernet cable. I used 32 bit ubuntu as it's only a 1GB pi and 32 bit saves some ram. I had some voltage warnings when booting up, I should probably get a better power supply for it. The Usb drive is non-ssd.
A Raspi-NAS is nice for the learning experience, but if you want a real NAS, just get one. Or build it with proper hardware and FreeNAS or a similar solution.
It’s hard to justify using a Pi for a NAS unless you don’t mind your SD becoming corrupted.
Are you looking to build a real NAS or a Pi NAS? You could by off the shelf but it’s not as much fun.
OpenMediaVault is another Debian based distro I might check out in the future.
Hardware wise I’d go with something that supports ECC and a sever grade mobo, likely intel based. Supermicro has some cool IPMI features I used to setup over LAN, no monitor or keyboard.
Just a reminder to not open up your NAS to the public. I VPN to my home network if I need remote access.
I am planning on "upgrading" it to Ubuntu by using an SSD in one of the bays and create a RAID-Z array using the 3 remaining disks.
Having a NAS is an ever-expanding process. You start off small (a router with DD-WRT and a few services), but then you realize a new way to use it and you hit the limitations of your hardware. Right now, my goal is to DVR a local show that's broadcast OTA, but my USB tuner isn't supported by the heavily-pared down QNAP kernels.
The software is just incredible on that thing. I got one with an Intel CPU and can run Docker on it that way. This replaced my PI where i was previously running a few things for home automation.
You can totally setup a NAS with a pi but IMO it's never gonna be as nice as a Synology NAS and all the trouble you have to go through setting it up.
You pay a little extra up-front but it really is worth it. The box also uses a special BTRFS implementation that is rock solid and easy to manage snapshots for with their own GUI tools.
But I can't shake the feeling that they will turn to the dark side sooner or later - the fact that the software is closed, mostly. Definitely if they get acquired, but also all the nice features are begging to be abused once the MBAs see they can get another $1/year/customer from selling you out.
So far, I only have excellent things to say about Synology. The feeling is from past experience with other vendors - Synology themselves have been amazing.
High quality? Get a Synology. Qnap is nice too, but Synology usually has a little better specs. All other brands are 'just not that good'.
Build your own? Go to https://www.xigmanas.com Just grab some hardware you think might work. Better hardware usually results in better NAS, but it will never be as optimised as a Synology.
Want to tinker with software endlessly? Any system that will support some kind of Linux. Take the word endlessly very literal.
I have a lot of various NAS systems. I don't trust any of them with very important data. Most of them have automated backups to various other systems.
miniboards(RPi, something-Pi) - underpowered for transcoding, no SATA/PCIe ports only USB, so little storage capacity via unreliable USB link. For playing it's OK, but if you're building something expandable, to last a long time , forget it.
Synology/QNAP boxes - expensive, proprietary components, if some part (power brick, motherboard) fails after warranty ends, you're SOL. You can't swap parts, repairing anything is very hard.
Rack mounted server in home - absurdly loud fans and impractical form factor
So what is the golden option that is almost never mentioned? Build a quiet pc in tower box. You can choose the right components for your needs. You can repair/swap them for new ones when they fail. And it is cheaper.
A cheaper option would probably have been to get a proper computer (likely secondhand), which would have been more cost effective but probably take up more space :)