- 512 GiB of Samsung ECC DDR4
- Lights-out management via Supermicro IPMI
- (2) 4x NVMe to PCIe adapters with many Samsung, Seagate, and Intel Optane SSD on the motherboard
- Dual SAS3 controllers to Supermicro 847E1C-R1K23JBOD with dual SAS3 expanders and 37x 14 TB HGST helium drives. Not using ZFS because of past unrecoverable problems and poor community support. mdadm and XFS are rock solid. I built an md array and SMART drive monitoring tool that tracks the few parameters that are prefailure signals, and also monitors helium levels.
- Intel QuickAssist 9870 - cryptographic accelerator because "Why not?"
- Intel 10 GbE NIC optical to switch
- vSphere Enterprise Plus currently on 7.x (technically unsupported), considering 8.x
- APC SMX2000 and SMX1500 with multiple expansion batteries, NMC3 lights-out, and temp+humidity monitoring
- WiFi: Ubiquiti 6E locally managed without cloud bullshit
- Offbrand POE+ switch firewalled at the router to avoid cloud, telemetry, and backdoor bullshit
- Deciso OPNsense 740 firewall with 10 GbE links to ISP and to the switch running business OPNsense. Wireguard works great with a freebie dyndns to permit remote network access via "VPN". Had to setup a cron with a curl dyndns updater. It's good enough to do remote Steam from mom's internet on an iPad Pro with the Wireguard app VPN in automatic mode.
- 2 Gbps Google Fiber
- VMs standardized on CentOS 9 Stream. A couple of Ubuntu and Windows, along with *BSD and other OS build worker boxes. While the RHEL-compatible CentOS userland needs more work than most, the important bit of RHEL/CentOS is scalable stability, reliability, and security. Make RPMs for whatever you need and vendor dependencies.
- Kubernetes (k8s) and Docker CE on containerd
- Plex Media Server
- Samba setup and enabled as a TimeMachine network disk
- NFS for home directories
- PKI (CA and intermediate CA) for certs on all devices and apps managed by OPNsense (pk not saved)
- SSH: Yubikey GPG-agent backed authorized keys + TOTP + Yubikey FIDO2. (Service accounts are done differently)
- Bitwarden (yes yes, configured correctly and local sync server)
- Obsidian for runbooks and primary documentation
- Also: AWS CloudFront/S3 for YUM RPM repo and EC2 for one-off jobs. Staying below the free tier and using minimal resources is how to be cost efficient.
- Offsite storage: Mega 2TB plan + Apple plan + Google Drive plan (2 is 1, 1 is none)
- Working on: kata-containers and Istio
- Thinking about: ARM server and an HSM
PS: Buy as much as you can used because buying new is usually throwing money away. UPSes must be refurbed with new quality batteries and then refurbed periodically (say, every 7-10 years for the broke home gamer). Schneider Electric bastards (owners of APC) went to a subscription model for NMC3 firmware updates that is cost prohibitive.