Show HN: Proxmox VE Helper Scripts
community-scripts.github.io
community-scripts.github.io
We are moving forward in a transparent manner and I am more than happy to answer any questions.
I only recently went down the homelab/selfhosted path and the majority of my containers were setup using tteck's scripts.
Incredibly sad. It’s a real testament to tteck that he took the time to transition the project, and make his wishes known how he wanted us to proceed. Tteck is a legend.
When the shit has really hit the fan personally and yet you still worry about other people: that is the mark of a decent person.
Legend, indeed.
Basically I just wanted to say thanks to everyone involved in making these scripts, it has left me with a great first impression.
- Updates and automatic upgrades between major versions.
- The developer who wrote the software created the container (most of the time), this means its a supported environment. Also, as they have the insight into the application and future upgrades the environment has been setup correctly for each version.
If you want to achieve your goal, I'd suggest an LXC with your favourite Linux distro + docker + app container(s) for each app you have. It gives you the same thing, but with the benefits above.
An LXC running docker with an app containerised inside will basically be the same as if the app is running a level higher in the LXC itself.
Give it a try. Then open top/htop in the host OS (pve shell) and you'll see the apps running in the docker container inside the LXC as native processes.
i'm setting up a new server soon and want to optimize/correct some of the things i've done on my first proxmox setup (like not running truenas in proxmox passing the RAID controller through lol).
i'll give this a shot!
What's the virtualization technology on proxmox?
What's the advantage to using something like this as opposed to terraform or salt stack or Ansible?
For work I'm a firm believer in reproducible environments and IAC. We actually a combination of vagrant, libvirt, and KVM to spin up local clusters for quick testing and development. It works out pretty well, but in my homelab I don't have anything complicated enough to bother setting up terraform/ansible for. Although I imagine if my server crashed I probably wouldn't think that way anymore.
It's not suitable for open sourcing yet (embedded secrets and the like), but if the community wants it, it's pretty solid.
Only issue I see is the Ansible script currently always expects to be building a cluster of Proxmox hosts. I'd need to make some change to customise it so it can build out just one node though.
I've been using it or ~3 years now for my Proxmox cluster home lab which predominantly hosts LLAMA, *Arr stack, deluge, Nginx, Tailscale and a few other services.
It's not quite a one click deployment, but it can build our an entire cluster in 30 minutes after an initial Proxmox install is completed.
[1] https://github.com/bpg/terraform-provider-proxmox/issues/817
Just because someone doesn't use vagrant, libvirt and KVM to spin up local clusters manually, doesn't mean they don't know how.
There is no shortage of Proxmox users who grew up in datacentres from bare metal servers, to virtualization first coming out, and beyond.
If you want to treat your self-hosted applications as "sheep" (1) , then terraform k8s etc. is a better bet.
But if you are happy to manually restore from a backup or snapshot when something goes wrong, or automatically have your LXC container shifted to different hardware if you have a cluster, then Proxmox is for you. The reality is that in a home setup you will spend about as much or less time maintaining your "pets" than than you would your "farm".
(1) I write this from New Zealand
No it does not enforce ZFS or any other filesystem. That's up to you. ZFS or BTRFS are fine when indicated - and you need to know your stuff.
Cephs for clustering (hyperconverged) is very much a first class citizen. I generally only use EXT4 as a filesystem - keep it simple. XFS is lovely too, especially for reflinks if you need them.
(1) Wal and Cooch know how to run a farm (and so do I, in the UK!)
You are correct, it is optional and I should have made that clear. While optional it does have native support for ZFS and takes advantage of ZFS features, like instant snapshotting of LCX containers.
Proxmox only supports linear snapshots using ZFS (so no tree-like snapshots). This might be a deal-breaker for some usages.
You can likely manage the configuration of the VMs themselves through terraform or similar in combination with Proxmox if that's your desire.
- provision VMs with Terraform - configure/maintain your VM with something like Ansible
The provider also allows your to schedule LXC if you'd like to target that instead.
I wanted to do what I think is a very basic and very common setup: Modem > proxmox box > OPNsense VM > physical wifi router via onboard 10Gb NIC + internal network VMs like OMV etc. The goal is to add a full network filter via OPNsense, and allow access to a media sever and backup etc from the internal network.
I see no OPNsense, OMV script is basically contra-indicated because it should be a VM instead of the LXC container, and I don't see any glue scripts to get VMs talking to each other, which is an important part of Proxmox configuration. So it looks like there is room here to get some basic setup scripts for a simple home server either improved or added to the collection.
I'm confused by what you mean here? Don't they just use the network like any other computer?
I haven't had to do any special configuration to get my VMs to talk to each other.
And of course this means that the Proxmox box as a whole should have similar hardening to a typical web server, with minor tweaks to allow residential traffic on various other standard ports. So that hardening would probably be another script I would like to see (I don't know what all the proxmox scripts in the first section do).
Since selecting the bridge for a service's NIC is part of setting up each service, the only thing such a "glue script" would be doing is creating the `vmbr1` bridge. That's already a one-liner.
In the router case, you'd likely want this default one to be the 'internal' network and have a separate interface (either physical or VLAN) for the WAN.
I agree with OMV. It certainly can be used as is, but not usually how people want to use it. A note was added to the script a few days ago.
> I don't see any glue scripts to get VMs talking to each other
There is a Tailscale script which technically helps them talk to each other (over Tailscale) :)
The scripts are designed to setup self contained LCX containers. We are trying to avoid building our own k8s.
I think I will stick to using proxmox virtual ports to create my network so I can more easily only stick to individual device registration in tailscale and save on that overhead when I'm home, but then also add tailscale /headscale into the mix somewhere so I can tap in via VPN when I am out of the house.
Tailscale and OPNsense are more difficult to get working together due to conflicting project goals (one blocks well, the other opens up well), but it looks like it's worth it to me.
The router port to the proxmox machine is set up for tagged packets that isolate incoming/outgoing traffic.
After that my VMs and Containers are easily set up to "live" on one or more networks.
For me the firewall rules on the router determine what traffic can be relayed between vlans through the router.
I'm pretty sure you could set up opnsense running in a container or vm to do the same thing, selectively passing traffic from one vlan to another.
OK, so you want to virtualise a router and firewall. That's fine. I have deployed roughly 200 pfSense firewall/routers as VMs and physical boxes and OPNSense is similar, so I can probably help.
At a minimum you will need two physical interfaces (one will actually do but you will need to know what you are doing!). You need "WAN" and "LAN". OPNSense is still FreeBSD based, I think, so it will not run in a L[inux]XC container for obvious reasons.
Your last paragraph seems rather confused. I don't know what you mean by "glue scripts". VMs communicate via networks
I suggest you try a few experiments to get to grips with virtualisation properly and then move on from there. If you swing by the Proxmox forums with specific issues we'll try to help out but in the end you need to dive in full on ... or not.
I used some of tteck's helper scripts to set up mqtt and zigbee2mqtt LXC containers with a passthrough of the USB zigbee device.
It's also just not amenable to automation or reproducible builds in the same way as an established pod manager like Kubernetes: there's no support that I can find for Terraform, and so you're stuck with regular full-disk backups and maybe some Chef/Ansible/Puppet tooling, which I don't want to invest in [re]learning.
Still, very cool resource management and passthrough model, and it's easy to set up and maintain, with a nice control panel.
For awhile I ran Docker Swarm with a bunch of SBCs, then k8s, then just a big server running Ubuntu + Cockpit, then Proxmox, until I have finally settled on NixOS.
NixOS has decent container support if necessary, but I've found that its declarative nature means I almost never bother with containers. "Uninstalling" something is generally as simple as "remove it from the config file, rebuild", and it's not hard to do cgroupey stuff if you need to manage memory and the like.
Not to mention that I think NixOS's nginx DSL is wonderful. It's so nice being able to have my proxy configs (along with LetsEncrypt) managed directly (and correctly) by the config environment instead of me writing my own scripts and the like.
(I'm not sure if there are any distributed NixOS things, because I could totally see something neat being built on Flakes)
My homelab has never been simpler and I've never been happier with it.
Of course I could install NixOS inside Proxmox, but part of the appeal of NixOS is that everything in the system is managed by the configuration.
However there is a (community) TF module...? https://registry.terraform.io/providers/Telmate/proxmox/late... (I have no experience with it as I typically reach for Ansible).
Also, easy-to-install ZFS makes it hard for me to cajol myself into trying something else. And if I want k8s for play time I can always spin up (a/some) VM(s).
Neither option is particularly complete, and they have some issues; the bpg one does most of the heavy lifting over SSH rather than using the API due to missing features; it also has some annoying quirks with data structure, such as VM IPs are in multi-dimensional arrays, which means you have to write a bunch of logic to drop localhost and secondary IPs (such as those for Docker virtual networks), and then restructure the output, if you want to use the address to setup your DNS for example.
It's doing what I need now, but I would not call them "gold" or "platinum" grade, probably "silver".
I'd suggest seeing if Proxmox is better-supported in some other IaC tool and fallback to Terraform as a last resort.
I'm running a four node cluster on salvaged SFF machines backing up lvm snapshots to home brewed TruNAS storage and it all makes me happy.
----
Incus feels a lot less…legacy? Old school? Something.
Not a lot different when it gets down to it though. It’s easier to work at the CLI with Incus. Backups are a little less straight forward.
Now that Incus has shutdown the image server[0] is there a decent source for LXC images? I've often struggled to find ready-made images for a lot of things I want to deploy on Proxmox, and if I was to move away, I'd probably want something that uses Docker/Podman for when I don't want to deploy a VM.
[0]https://discuss.linuxcontainers.org/t/important-notice-for-l...
As for LXD/Incus itself, I sincerely believe it's good software and I like their CLIs a lot more but for my own purposes i've moved to using proxmox, or lxc directly.
It's relatively trivial to use the pve command line utility to create or modify vms in proxmox.
Still, the originating reason of this post is due to a large number of useful scripts to help make things more manageable and maintainable, and the founder of it having to step away, and there being gratitude for their help to make things much more manageable.
Also makes it very quick to try out an application, arguably less time than even docker.
Docker is a step or two away from packaging installers for the masses.
You do have to treat Proxmox VMs like “pets, not cattle” since they are more difficult to automate, but that’s the same story as if you were managing your k8s host on bare metal too. The benefit with Proxmox-hosted VMs though is that you can use Proxmox for whole-VM backups and migrations, so you can have the best of both proxmox and k8s!
I've also been using a Terraform module for Proxmox at work to deploy stuff, but there's only two, both community modules and neither is gold/platinum tier, good enough for homelab though I'd say.
While qemu is common way of using kvm, but running qemu directly is quite annoying. So you have stuff like libvirt and proxmox as wrappers around qemu.
Very sad state of affairs.
I have been using a combination of docker and lxc/lxd to manage my VMs. But, cockpit (on ubuntu) does not give me a perfect experience for managing running VMS, etc.
I wish there was a good solution for all of this. But, it feels like you need to cobble together a bunch of kibana tools to get true monitoring.
I tried TrueNAS but it's very rigid. Proxmox seems to give you more control over what's installed on the server but it's also quite locked down. Don't remember exactly what was it that pushed me off Proxmox. I think it was that I needed to manage some VMs over LXD API and others over proxmox and I couldn't mix and match, I had to choose one without extra hacks.
Open WebUI which can connect to the OpenAI api or a local Ollama LLM. You can also connect various tools to the LLM like a calculator or web search to augment them. The AI has helped me learn how to configure and debug stuff. Like I got step-ca to setup a local certificate authority and give certificates to my various internal services. I played around with configuring Caddy and Nginx along with ACME to the the step-ca. The LLM was even helping be debug my config files.
I'm also using Hoarder for bookmarking and it can use AI to automatically tag your bookmarks. It can even backup the webpages.
I've been using Mealie to clip and save online recipes.
I'm running Uptime Kuma to check if my computers and services are up and if they are down, I'll get a notification.
- home assistant - Network Video Recorder - Jellyfin - network management such as ubiquiti or omada etc - vault warden/1pass/other secrets servers - tailscale or wire guard server - build server/k8s test environment - private artifactory or mirror (especially useful if you're using the same distro on a bunch of devices but don't want to overload the actual mirror+improves download times) - torrents (someone's gotta seed Wikipedia) - onsite backups - bastion into your home network (see also: wire guard) - some people even use it for their router
You could also take a look at the tteck scripts, there's a bunch of cool stuff in there
OPNSense (as my household's internet interface), Unifi Controller (as my household's primary wifi), Jellyfin, Wireguard, Pi-hole, LMS[0], Frigate NVR (migrating off ZoneMinder, awaiting delivery of a Coral TPU to finalise this), couchdb (as Noteself[1] back-end), nginx (serving a handful of sites for my own entertainment), Mailu[2], Calibre[3], various other in-flight experiments (which Home Assistant will soon become, Bitmagnet DHT scraper).
Most of the above are docker instances hosted on a small number of VMs hosted on two (or sometimes three) physical machines running proxmox.
[0]: https://github.com/epoupon/lms (HN lurker)
[2]: https://mailu.io
[3]: https://fleet.linuxserver.io/image?name=linuxserver/calibre or https://fleet.linuxserver.io/image?name=linuxserver/calibre-... (I can't remember which)
That's all for now but I've just installed Home Assistant but haven't set that up yet. I also intend to try out Jellyfin as a media server and Frigate as a video recorder when I get some cheap cameras.
- Postgres, Maria, Influx, Grafana
- Plex, Arr suite, Transmission
- Ollama, OpenWebUI
- Web change tracker
- Teslamate
- home assistant (just a few currently, more soon) - paperless:absolutely awesome document management system - immich: image management with automatic synchro of my mobile taken images (ML features) - tailscale - StirlingPDF: simple tools for all things PDF
This is probably the worst implemented list view I've ever seen. Completely useless.
I’ve just built my first homelab and have favored OpenMediaVault which seems better suited for my use.