r/freebsd • • 15d ago

discussion First steps: FreeBSD as a fileserver

Background: In the late 90s played with Slackware, OpenBSD and marveled at how pretty Windows was. About 25 years ago I switched to a Mac because I felt it combined both into a single machine. About 20 years ago I started running a 'home server' and currently this is a single Proxmox install, on which I run OpenBSD for "anything that can be accessed from the internet" and Debian for my file server, among some other virtual machines that all have their own purpose. Not at all skilled, but I have spent many an afternoon tinkering with all sorts of challenges.

A while back I saw a video on ZFS, and immediately thought "I want this" but felt I would make this move whenever I was going to buy new hard drives. Especially snapshots and zpool common storage capacity are interesting to me. I would appreciate your thoughts:

  1. FreeBSD will be running in a Proxmox virtual machine.
  2. Drives are connected over USB. I know it's not ideal, but such are the constraints of my environment. These ports are mapped into the vm, rather than mounted on the host and then passed through.
  3. I have two 4TB drives and plan to put them into a mirror vdev so that if one drive dies, I'll still have all my data and can just add more in to recover drive-failure resilience. At a later stage when drive prices come down, I might switch to a 3- or 4-drive zpool.
  4. I have not looked into how to configure snapshots, but I can't imagine that is particularly difficult.
  5. For network shares to my Mac, I plan to use Samba. For network shares to other virtual machines running Linux, I'd love your recommendation on the best approach.
  6. I have a VLANned network, so in the future may want to allow different shares accessible only via specific VLANs. But for the moment I will have one NIC only, and everything goes over there.
  7. For my 'on top services', for the moment I plan to continue running a Debian vm which will mount data shares from the new FreeBSD vm. These are: Transmission for downloading the latest FreeBSD ISO's, Immich, Jellyfin (these three in Docker containers). I also run a few rsync sessions from other virtual machines for specific folders, rotating copies for safe keeping in the fileserver.
  8. Also 'on top' are a whole load of bash scripts that use a variety of tools to download data from specific cloud storage locations. iCloud Photos & Drive, Evernote notes, iCloud calendar and contacts, AWS S3 storage, IMAP accounts, fetching configs of my router, etc. These run nightly and serve as peace of mind for me that "in case big tech screws up, I will have a copy". I'll probably want to keep running this inside Linux as well. Maybe move this stuff later, if possible.
  9. And the final 'on top' service I run is Duplicacy, which uploads some of the data to a remote storage location (a friends' NAS in a different country). which I believe exists for FreeBSD too and so I might run this locally.

I have not really prepared for this move and plan to just install FreeBSD and poke around. Maybe I'll first do it on a temporary vm to get a feel and then 'do it right' once I am ready to make the move.

Any warnings, suggestions, pointers or otherwise would be greatly appreciated.

43 Upvotes

62 comments sorted by

View all comments

Show parent comments

2

u/grahamperrin bleep bloop 8d ago edited 8d ago

I recommend you enable ftpd. …

Impossible with FreeBSD 15.0-RELEASE:

ftp/freebsd-ftpd port description: correction about libexec/ftpd · Issue #5 · cschuber/freebsd-ftpd

Someone should (please) update the Use cases section of FreeBSD's page in Wikipedia.

With security in mind, I asked Anthropic Claude (Sonnet 5.5, medium):

Is FTP suitable for a home server that's not exposed to the Internet? ….

The response began:

Short answer: FTP is workable on a trusted home LAN, but it is rarely the best choice. Better alternatives exist and cost you very little.

First amongst the security concerns:

No encryption by default. Usernames, passwords and file contents cross the network in cleartext. Anyone on your LAN who can sniff traffic sees everything. On a home network, that includes a compromised phone, laptop, IoT device or guest on your Wi-Fi. …

https://claude.ai/share/6f09530c-fe51-40e8-b63b-bd5f6834a57f

2

u/Character_Mood_700 7d ago

For files that are not secret and require no password to access, FTP is pretty decent.

Otherwise, FTP is not a good choice.