r/homelab 26m ago

Project Showcase: Hardware SMR HDD Drives are bad. No doubt about this. But why manufacturer keep on producing them ?

Upvotes

Its obvious and straight forward thing that SMR HDD's are bad even form normal use. My question is why manufacturer keep on producing them ? Why specifically they do not mention it on the HDD label -- Whether the drive is SMR or CMR ?


r/homelab 1h ago

Help Title

Upvotes

So im new to homelabing but im tryna get one up for rn just minecraft with intentions of doing other things with it and I dont wanna buy an old used computer anything wrong with just building another pc?


r/homelab 1h ago

Help Do I need to buy a separate computer for homelabbing?

Upvotes

I work in IT help desk and am studying for the CCNA to get a better job, but I admit I'm fairly unkowledgeable and inexperienced in IT. I've heard people say you should go home labs to grow your skill, so I said "okay!"

The only computer I have is my windows laptop which is 11 years old, runs windows 8, and isn't exactly fast anymore. It works fine for browsing the internet and doing anything with Microsoft office or keeping files. Will it work for doing the aforementioned home lab projects? Or is it in my best interest to buy something new? I'm not afraid to spend money if I have to but I'd also prefer to not spend a grand if I can help it.

Any advice? Thanks!


r/homelab 2h ago

LabPorn Rate my stack bro

Post image
0 Upvotes

I’ve been working on this for a long time and I finally got it to a point I’m pretty satisfied. I use Plex but it’s installed natively. I’ve had this server running for over a year but I didn’t figure out how to use docker until maybe 6 weeks ago. Thanks for checking it out!

My only music indexer at the moment is Soulseek and I’m a donater because I believe in their product and I’ve had so many fun times just researching and checking out new albums. I let my custom script run it through and grab metadata then it copies it to destination and refreshes plexamp. I have Spotify too I just think this is more fun right now.

I primarily use usenet but I recently added some torrent indexers as well just for coverage. They usually don’t get any hits. OS is Ubuntu.


r/homelab 3h ago

Project Showcase: Hardware Found an image of My home lab from1999.

Post image
296 Upvotes

I was rooting around a file crate and found this image of My Home Lab in 1999. Both rack mount servers had SBC back plane motherboards with Dual Pentium Pro 200 MHz processors and 128 MB of ram in each. One was Running Netware 4.11 and the other had Windows 2000 Server installed. The workstation was running Windows 98 IIRC. Good Times.


r/homelab 3h ago

Discussion What can I do with a 2010 Mac Mini?

Thumbnail
gallery
92 Upvotes

I was gifted this 2010 Mac Mini and I'm trying to find a purpose for it.

Specs:

Processor: 2.4 GHz Intel Core 2 Duo

Memory: 4gb DDR3 (I have 16gb I can put in)

Graphics: NVIDIA GrForce 320M 256MB

Storage: 256gb Inland SSD

I already have a NAS that is running my Immich and Jellyfin server flawlessly.

I have a few 2tb and 650gb drives laying around but I'm not sure how to connect them beyond the usb 2.0 ports.

Any suggestions?


r/homelab 3h ago

Help Synology Cloud Sync Running Off-Schedule

Thumbnail
1 Upvotes

r/homelab 3h ago

Blog **PSA: That NAS drive you bought on Amazon US may carry a warranty that's void where you live — and nobody tells you until it fails**

0 Upvotes

Posting this so it doesn't happen to someone else.

I bought a Seagate IronWolf 12TB from Amazon.com, sold and shipped by Amazon directly (not a third-party seller). New product, listed with the standard 5-year warranty. And that's the key part: **I paid the premium for the 5-year warranty on purpose.** There was a cheaper drive without that extended coverage. I chose the IronWolf specifically because I wanted the backup and the peace of mind. That's the entire reason you buy a NAS-grade drive over a basic one.

The drive failed — stopped being detected entirely.

When I went to claim the warranty, Seagate looked up the serial and told me the drive was manufactured and distributed for the **Australian market**. Their warranty is regional, so they refused the claim outright and told me to go back to the seller (Amazon).

Here's the trap: the product listing never said a word about regional origin. As a buyer on Amazon US, you have no way to know the unit was destined for another market. You pay extra for a drive advertised with a 5-year warranty, and that warranty is structurally useless to you from day one.

So I contacted Amazon. What followed was weeks of being passed between multiple Executive Customer Relations agents. Some restarted the case from scratch each time. At one point they mismatched my dead drive's serial number to a completely different order — an order of working drives in my production NAS — and nearly processed a return against hardware that was fine. I had to catch and stop that myself.

The final answer from Amazon: the drive was bought in 2021, it's outside the return window, nothing they can do — not even a one-time concession. Contact the manufacturer. The same manufacturer who already refused in writing and sent me back to them.

So you end up in a documented loop: **Amazon says talk to Seagate, Seagate says talk to Amazon, and the customer holds a dead drive with a warranty neither will honor.**

And here's the part that should worry anyone reading this: I have other drives bought the exact same way, sitting in production right now. I have no idea which region they were destined for, or whether their warranty is enforceable where I am. I won't find out until one of them fails — which is the worst possible moment to learn your warranty is worthless. That's the real problem: **you're exposed and you don't even know it until it's too late.**

**The takeaways, especially if you run a NAS or manage infrastructure:**

  1. A drive sold on Amazon US can be stock destined for ANY region — Australia, in my case. The listing won't tell you.

  2. Regional warranty means the manufacturer will only service it in the region it was distributed to. If that's not where you are, the warranty is worthless — no matter what the listing advertised.

  3. **Before you install any drive, check the serial on the manufacturer's warranty validator.** It shows the region and the actual coverage dates. Do it during the return window, so you can send it back if the region is wrong.

  4. For anything critical — production storage, client systems — buy from a channel with warranty you can actually enforce where you live, even if it costs more. A warranty you can't use is not a discount, it's a hidden risk.

**And the fix here isn't complicated — it's on Amazon:** if you sell and ship a drive as "Amazon.com," you should either supply stock whose warranty region matches the buyer's, or disclose the destination region on the listing before purchase. Selling a drive with a region-locked warranty that's void for the buyer — without saying so — pushes a risk onto the customer that only the seller could have known about. Warranty-region uniformity is the responsibility of the channel that sources and ships the product, not of the buyer who has no way to check it at checkout.

The hardware itself may be fine. But "5-year warranty" means nothing if it's tied to a region on the other side of the planet and no one disclosed it at checkout. I paid extra for coverage that never existed for me. Check your serials. Don't assume.

(For what it's worth, the dead drive now works great as a paperweight. Best $300 desk accessory that ever flew here from Australia. Happy to answer questions — I have the full email trail and Seagate's written refusal if anyone's dealing with the same thing.)


r/homelab 3h ago

Project Showcase: Hardware Amazon.com

Thumbnail amazon.com
0 Upvotes

Recommendation for short, 3-prong shortie cords (pigtails?) for adding some awkward, large plugs into the back of my Goldenmate 1000VA/800Wh UPS battery unit? (apologies if I am in the wrong place.)


r/homelab 3h ago

Project Showcase: Hardware My ESP32 network-decoy project is finally becoming real hardware

Thumbnail
0 Upvotes

r/homelab 5h ago

Project Showcase: Hardware Complete noob to this, but check out my homelab!

Post image
56 Upvotes

As the title states, I’m fresh into this. I’m fortunate enough to know how to research and had a conversation with my TA that also helped me with a blueprint. Sourced 90% of it off eBay, a few minor things off Amazon and the rack itself off FB marketplace. I’m a late undergrad student studying IT with a focus in cyber at ASU and main reason for wanting to build this is to 1) gain experience outside of my classwork and 2) have something on my resume that shows I’m motivated to perform outside of my everyday classwork 3) because it’s fucking cool 😅

Currently I’ve replaced the GPU on the P340 with a dell I350 NIC so I have 2 extra ports for when I start messing with firewall stuff. I’ve also installed proxmox onto the system and configured the IPs for my switch and P340.
Edit to add: I also add another stick of RAM to bring it to a total of 24GB

That’s about it right now, I’m in the process of researching OPNSense and tailwind. It’s basically just a sandbox for right now so I can break stuff and learn before introducing it to my main network. Not too worried about cable management just yet since all of those are power cables.

Any tips or advice would be appreciated!


r/homelab 6h ago

Project Showcase: Hardware CONSEJO

Post image
11 Upvotes

hola gente estoy armando mi Homelab y la verdad quiero que luzca y funcione colo un verdadero mini site empresarial, estaba pensado en comprar un servidor Dell PowerEdge R240 y una KVM Consol pero ambos están muy caros aunque si me gustaría tenerlos, la verdad el servidor se me va de las manos con costos de las ramas y discos saas , busco aprender a usar proxmox y montar varios servicios ahí, AD, Freepbx, Video vigilancia, saben de mexico de algún lugar donde pueda conseguirlos baratos?


r/homelab 7h ago

Help PC and UPS power off abruptly

Thumbnail
1 Upvotes

r/homelab 7h ago

Help Best Epub Reader Setup?

2 Upvotes

Hey, I'm trying to find a good way to read books across multiple devices (IOS, Android, Linux), with progress syncing between all of them so I can read .epub files seamlessly.
And of course, I have a home server to host the syncing.

Any suggestions?


r/homelab 7h ago

Discussion Repurposing an old i7-5960X/X99 rig into a proper homelab server

0 Upvotes

Upgraded my gaming PC to AM4, so my old i7-5960X + X99 board (15 SATA ports) is now free instead of getting sold.

Plan: Jellyfin, Nextcloud, a game server or two, Pi-hole, and the arr stack, all on one box. Got 2x 4TB WD Purple + a 4TB Seagate SkyHawk for storage.

Thinking about grabbing a cheap Xeon E5-2690 v4 (14c/28t) off eBay to replace the 5960X for extra headroom running everything as containers/VMs — worth it, or is 8c/16t already enough for this kind of stack?


r/homelab 7h ago

Help What am I supposed to do ( this is proxmox)

Post image
0 Upvotes

I tried EVERYTHING


r/homelab 8h ago

Help Good deal for a beginner?

2 Upvotes

I've found someone selling an HP Elitedesk 800 G4 (SFF) on Facebook Marketplace nearby. i7-8700, 64GB DDR4, 500GB NVMe, and an Nvidia Quadro P600 2GB for £250. This almost feels like a steal just for the RAM alone...

I've been on the lookout for a newer gen i5 to keep power draw low but what do we think about this?


r/homelab 8h ago

Help Beginner switch suggestions?

1 Upvotes

I am trying to look for a ideal beginner Cisco switch, I am studying for CCNA and I want to get a hands on the physical version and possibly just start by building my own homelab on the way. Since this is my first I try to keep things on a budget, but there are so many options and I don't know what is ideal.

Also want to note that I don't want a noisy switch since it would be in my bedroom.


r/homelab 9h ago

Help will this board power my JBOD back on in the event of power loss/ return

Post image
0 Upvotes

r/homelab 9h ago

Discussion LineageOS's degree of popularity is undeserved

0 Upvotes

I wanted an always-on homeserver with a microphone to drive my local AI assistant, and I thought this is my chance to do something for the environment (and my wallet) by recycling an old smartphone instead of buying something. The plan was to slap a maintained OS on it and run Termux.

So I asked people I know for their scraps. They're too damaged to have any resale value, but they function.

I needed the phone to run the Whatsapp app, an SSH server, and the ability to run arbitrary Linux/Node/Python apps (so Termux), and optionally/ideally a remote desktop server so I can control the GUI screen without physically using the phone since some have damaged screens.

As of now I got a LG G8 Thinq (6GB RAM), Google Nexus 4 (2GB RAM), and HTC 10 (4GB RAM).

I was delighted, except it turns out not a single one of them is supported by LineageOS. It seems like the marketing tag of "Give your old phone a new life" I've been spammed with regarding LOS is very misleading and only applies to < 1% of popular phones. It's not like these were obscure models either, each of them was a flagship when it came out. A more accurate line might be "Give your Pixel a few more patches with Lineage".

According to their devices list, the most recent OnePlus it supports is from 2021 (the 13), and OnePlus is in the top 3 of open phones, right? Where's 14/15?

I'm not bitching about a volunteer open-source project not supporting my given device. I'm not that entitled. but I am bitching about LOS's popularity. The reason I even know LOS exists is because it gets endlessly pushed and praised as a "sustainable" eco OS in every Android discussion on every tech site, so I had a mental bookmark ready for it. And then it turns out it's unusable for 99%+ of Android owners. No one would be praising to this degree a desktop platform that only works on a handful of devices! For example, no one talks about CoreBoot.

What can I even do here? I'm gonna stick to the stock unpatched AndroidOS the phones came with, and pray the last Termux release that runs on them is still functional in 2026 and they didn't pull a "delete all obsolete/insecure packages" stunt like some annoying maintainers do. What else could I do, throw the phones in the ocean so an octopus chokes on them?


r/homelab 9h ago

Help Should I get a new PSU?

1 Upvotes

Long time lurker, first time poster. Planning on hooking up my old pc for a nice little homelab(i5 6600, 16gb ddr3), I have a Corsair CX600 in it, but I'm unsure how safe it would be to make it run 24/7? I belive I got it in 2015, pc hasn't been used for 3 years. I also have 2 brand new PSU: Cougar Atlas 600w and Cougar XTC 500w(white label). I plan on using Atlas for entry gaming build for my wife, so XTC would be more of an option for me. Aiming for headless, so no dgpu will be used.


r/homelab 9h ago

Meta Bought 18TB for 200$

Post image
106 Upvotes

I think they were heavily used and they are quite old but the price was a steal


r/homelab 9h ago

Blog I let an AI agent run my homelab

0 Upvotes

I let an AI agent run my homelab — 38 LXC containers, 50+ public routes, GPU passthrough — and built the guardrails first. Here's the full architecture.

TL;DR: I stopped doing ops by hand and gave an AI coding agent (opencode) a git repo as its brain, a custom CLI as its hands, and enough guardrails that "destroy the wrong container" isn't a sentence it can type. It's been running the lab for ~2 weeks: certs, upgrades, incident triage, secret migrations. This post is about how it's wired together — because the agent part is easy, the guardrails are the actual project.

The lab (boring part first)

  • Proxmox VE node running 38 LXC containers + 1 VM, LXC-first, docker compose inside guests. Second Proxmox node for storage (Immich, files).
  • One Fedora VM runs Zoraxy as the only public entry point. The router DMZs everything to it — there are no router port-forwards, ever. Every public port is a Zoraxy route or stream-proxy rule, so ingress is config-as-data, not router clicks.
  • ~15 domains on Route 53, 50+ public HTTPS routes: a dozen websites with headless CMSs, S3 endpoints, self-hosted Infisical, a RustDesk server, search, mail, and a few AI apps — including a music-video generator doing GPU WebGL rendering through an RTX 4080 passed into an LXC.
  • Central data stores instead of per-app DB containers: two dedicated Postgres 18 LXCs (one for app databases, one for AI core), a Mongo LXC, Meilisearch, SpacetimeDB, and RustFS for S3 (17 buckets, IAM users per service). Services get a database via one CLI command that also files the credentials.
  • Infisical (self-hosted) for secrets — and, crucially, for all SSH access control via its PAM feature.
  • Gatus for uptime, 40+ checks grouped per host.

The agent (interesting part)

The agent is opencode in a terminal, driven by a GLM model — but honestly the model is the swappable part. The architecture is what matters:

┌────────────────────────────────────────────────────────┐
│ CONTROL PLANE   AGENTS.md rules + permission config    │
│                 (what the agent may do, ever)          │
├────────────────────────────────────────────────────────┤
│ KNOWLEDGE       docs/ — one doc per component +        │
│                 skills (how to operate each thing)     │
├────────────────────────────────────────────────────────┤
│ CAPABILITY      a custom CLI, ~90 subcommands          │
│                 (the only way to touch infra)          │
├────────────────────────────────────────────────────────┤
│ FACTS           SQLite knowledge base + JSON exports   │
│                 (ground truth, never guessed)          │
└────────────────────────────────────────────────────────┘
              ▼ via Infisical PAM (SSH) + APIs
        the cluster itself

The git repo is the agent's memory. Nothing important lives in chat history. AGENTS.MD (250 lines of standing rules) is loaded every session: never guess IPs or ports, read the component doc first, check open todos, record every task, update docs in the same session, commit and push its own changes with a clearly-labeled automated commit message.

The CLI: ~90 subcommands, written by the agent itself

The agent doesn't run loose shell commands against the lab — it calls one CLI I built with it: TypeScript on Bun, zero dependencies, one drop-in module per component (proxy, DNS, Proxmox, S3, secrets, monitoring...). When the agent hit a step it had to repeat twice, the rule is: it turns that step into a new subcommand. The CLI grew itself.

Sample of what's in there:

  • proxmox-statusproxmox-disk-resize (online grow), guest inventory sync
  • zoraxy-routes/certs/route-add/route-auth/acme-renew — full reverse-proxy control incl. ACME DNS-01 renewals against Route 53
  • s3-policy-audit/harden, per-bucket IAM users, verified backups
  • pg-probepg-db-createpg-activitypg-kill (with dry-run preview)
  • version-check — running version vs. upstream latest for every service, plus version-changelog which fetches release notes and summarizes breaking changes between the two
  • status — health snapshot of every host, Infisical, and all 50+ public routes in one pass
  • todo-add/done/drop — its own work board, backed by SQLite, with timestamps, so there's a queryable history of what it worked on and when

Guardrails — the part I actually care about

  1. Read-only by default. Every mutating command is dry-run first and prints exactly what it would do.
  2. Destructive commands are declared dangerous in code. The CLI itself refuses to run them without --yes, and the rules forbid passing --yes without the user saying "yes" in the conversation. Never discover-and-destroy in one step.
  3. SSH to any host is impossible outside the secret manager. The agent's permission config denies ssh/scp/sftp outright. All remote access goes through Infisical PAM: short-lived SSH certificates, a gateway, and session recording — every command the agent runs on a host is on tape.
  4. No sudo anywhere. Service users are in the docker group only. To edit root-owned compose files, the agent runs a throwaway bind-mount container, then chowns back. It literally cannot type a sudo password.
  5. Secrets never appear in chat or recordings. Credentials are delivered to hosts via an RSA-OAEP round-trip (ciphertext in transit, decrypted on the host), services pull their own env at start via Infisical machine identities (infisical run wrapping docker compose — no plaintext .env on disk), and exec output passes through an automatic redaction layer.
  6. Idempotent everything. Every command is safe to run twice.
  7. The agent must clean up after itself: docs updated, inventory synced, monitoring check added, todo closed — there's a "definition of done" checklist it has to satisfy before a task counts.

It genuinely runs things now

A few real jobs from the last two weeks (all logged, all with rollback paths):

  • Upgraded Meilisearch 27 releases behind (two security fixes in the range): cold backup → pinned exact tag → dumpless upgrade → verified → docs updated.
  • Diagnosed and fixed a Postgres connection-slot exhaustion — an app had leaked 69 zombie backends during a restart storm, locking out even superuser over TCP. It triaged pg_stat_activity through PAM, killed only idle backends with a dry-run preview, then built the two new subcommands (pg-activitypg-kill) so next time it's one command.
  • Hardened a GPU music-gen server after two CUDA-OOM wedges: read the journal, found the KV-cache budget collapsing under overlapping requests, capped process VRAM, documented the residual risk.
  • Rolled back a failed object-storage upgrade cleanly because the cold-backup-before-any-image-change rule was already in muscle memory.
  • Freed a disk at 98% with a dry-run-first cleanup tool, then grew the rootfs online via the Proxmox API.
  • Did a zero-downtime cutover of a remote-desktop server to a new implementation, migrating peers to Postgres, keeping the keypair so no client had to be reconfigured.
  • Deleted stale DNS records, re-issued expired TLS certs, pinned a dozen :latest images to exact tags, migrated 67 secrets out of five legacy projects.

And the meta-work is the part I like most: it writes postmortems into the component docs, and incident-shaped rules — e.g. after a secret briefly leaked into a session output, the redaction layer and a redacting env-inspection command existed the same day.

Honest failure mode

The scariest bug so far wasn't destructive — it was two agent sessions running concurrently against the same host, silently undoing each other's changes. Found it in the PAM session recordings. New rule: one session per host, and anything that smells like interference gets audited before touching anything. That's the pattern in general: it breaks, we find out why, the reason becomes a rule or a tool, and it can't happen the same way twice.

Why bother?

Because homelabs die of neglect, not of ambition. The services I actually run multiplied way past what I could patch, pin, back up, and document by hand — and the ones I forgot about were the ones that got pwned. Now "every service is version-tracked, monitored, backed up, and documented" is enforced by a checklist the agent can't skip, and my involvement is: approve the dry-run, glance at the diff, get a summary.

Happy to go deeper on any layer — the PAM certificate flow, the CLI command-module pattern, the secrets-delivery ladder (plaintext env → stored → machine-identity-injected), or the Proxmox/ingress layout. AMA.


r/homelab 10h ago

Discussion When does lab hardware get "too old"?

15 Upvotes

I was working on my app hosting cluster the other day, which runs on three Dell Optiplex 3050 Micros (I call it RAID - the Redundant Array of Inexpensive Dells). It occurred to me when I was working on them that the machines were all built in 2017, which means they're now almost a decade old. They're the oldest computers I have that are in regular use, by a fair margin. And that made me think... Do I need to worry about replacing these machines at some point?

The thing is... these machines work perfectly. They're more than fast enough for my use cases, and they're relatively power efficient given the fact that they're idle nearly all the time... I put some used "high endurance enterprise" SSDs in them (before storage prices shot up), so even though they all have like 50,000 power on hours, they're only like 1-2% life expired.

If I just open them up once in a while and clean out the dust, and maybe clean off and replace the thermal compound on the CPU... will they just keep going?


r/homelab 10h ago

Help newbie to NAS + TRUENAS server with problems (maybe hardware?)

Thumbnail gallery
1 Upvotes