My experience is similar. I no longer use dedicated NAS, firewall, or other exotic distributions. I run plain Debian, and add what I need through standard repo packages. My "NAS" is simply a Samba daemon. The same box runs countless other services including hostapd (WiFi), DNS (Unbound), an email stack (Postfix/Dovecot), multiple game servers, and Podman.
> everything else in Docker Compose
I would suggest Podman instead. It is far more secure by design (rootless) and is unable to silently alter the firewall's configuration.
These days you can buy 4 bay USB-C hard drive enclosures which let you make a nas out of any mini pc. I 3D printed a 10 inch rack to put the mini pc, hard drive enclosure and switch in which keeps it all neat and looks kinda cool.
Or even go nuts and do something like this: <a href="https://grabcad.com/library/10-bay-hard-disk-drive-cage-for-phanteks-enthoo-primo-case-1" rel="nofollow">https://grabcad.com/library/10-bay-hard-disk-drive-cage-for-...
I used btrfs raid0 on USB drives for more than a year. Every month or so, a drive would disconnect from the bus and immediately redetected as another device (sde->sdf). Btrfs does not auto-recover from this. The choices are 1) reboot and scrub, which recovers the missing drive without doing a full resync, but it needs a reboot (any hosted site is offline for 3 minutes) and scrub takes a long time reading in the background, or 2) run btrfs replace which doesn't need a reboot, but the full resync takes even longer than a scrub and increases wear if it's a ssd because it wipes everything and writes all data again.
I will point out that if you use ZFS instead of btrfs, you can specify drives to be detected via their serial number names rather than their attachment points, so a reconnect will not require a reboot.
Still, don't depend on USB for anything meant to be permanently connected.
USB is unreliable but it's working for me. I've had zero disconnects in a couple of years of using a Terramaster USB-C DAS. I've heard of the problems enough I've even searched logs for it.
I've wondered if my experience is different because I'm using single disks (but still ZFS) instead of any RAID. There is rarely transfer happening across all of the disks.
Can't say. The power source for the drives is also important. I do use a USB 2.5" HDD without an external power source for one of the SBCs I have, and that's stable, but that SBC is powered directly from the GPIO pins, not USB.
Unfortunately, where I need it the most - the router which is also a NAS - can't use directly-powered USB HDDs. Not enough ports. I had to use a hub. I tried 4 models, two self-powered and two powered by router's USB, and none of them was stable. I also tried 3 models of USB-SATA adapters. Two self-powered, one powered by hub (connected to the hubs that had separate power - didn't work otherwise). None of them was stable. It was always the USB-SATA adapters/racks that disconnected, not the hubs.
Then I bought a mPCIe 4-port SATA controller, Marvell chip. Didn't work. It freeze randomly and woudn't even unfreeze with a router reboot. Possibly too much power draw. Then I put a 2-port SATA, ASM1062 and a port replicator. That one works. 2 years and not one disconnect. The cables are a complete mess.
I'm using RAID on my Terramaster DAS and it's been working fine for me. I think it's less "USB is unreliable" and more "Some SATA-USB adapters are unreliable".
The Terramaster one is pretty widely used in home setups and seems perfectly fine.
I have not had this issue myself. Drives connected for around 6 months in raid without issue. But also, you should mount your drives using partition UUID rather than whatever linux decides to name them which is not stable as you'd noticed.
I find Proxmox to be a great host. It's Debian with a bunch of helper scripts/GUI to run containers and VMs. I manage ZFS outside the Proxmox bubble and run a privileged SMB server container to access it.
Though I really don't use the server anymore and it's probably worth several thousand dollars with the RAM in it. Been thinking of using a spare laptop with external HD bays to do the same job.
Don't know what it is with Proxmox, but I always somehow managed to break it in such a way that I can't remove the container/VM or start it...
> is unable to silently alter the firewall's configuration
I'd like more informations about this as I'm not too familiar with firewall setup but every time I tried to setup iptables / nft it was indeed bypassed by docker. Recently I found out in the docs that docker adds a DOCKER-USER table, isn't it enough to put your rules in it to prevent the outside world to reach containers ?
drnick1 · · focus · HN ↗
My experience is similar. I no longer use dedicated NAS, firewall, or other exotic distributions. I run plain Debian, and add what I need through standard repo packages. My "NAS" is simply a Samba daemon. The same box runs countless other services including hostapd (WiFi), DNS (Unbound), an email stack (Postfix/Dovecot), multiple game servers, and Podman.
> everything else in Docker Compose
I would suggest Podman instead. It is far more secure by design (rootless) and is unable to silently alter the firewall's configuration.
sotilrac · · focus · HN ↗
Gigachad · · focus · HN ↗
magarnicle · · focus · HN ↗
drnick1 · · focus · HN ↗
rkagerer · · focus · HN ↗
M95D · · focus · HN ↗
I used btrfs raid0 on USB drives for more than a year. Every month or so, a drive would disconnect from the bus and immediately redetected as another device (sde->sdf). Btrfs does not auto-recover from this. The choices are 1) reboot and scrub, which recovers the missing drive without doing a full resync, but it needs a reboot (any hosted site is offline for 3 minutes) and scrub takes a long time reading in the background, or 2) run btrfs replace which doesn't need a reboot, but the full resync takes even longer than a scrub and increases wear if it's a ssd because it wipes everything and writes all data again.
dsr_ · · focus · HN ↗
I will point out that if you use ZFS instead of btrfs, you can specify drives to be detected via their serial number names rather than their attachment points, so a reconnect will not require a reboot.
Still, don't depend on USB for anything meant to be permanently connected.
doubled112 · · focus · HN ↗
I've wondered if my experience is different because I'm using single disks (but still ZFS) instead of any RAID. There is rarely transfer happening across all of the disks.
M95D · · focus · HN ↗
Unfortunately, where I need it the most - the router which is also a NAS - can't use directly-powered USB HDDs. Not enough ports. I had to use a hub. I tried 4 models, two self-powered and two powered by router's USB, and none of them was stable. I also tried 3 models of USB-SATA adapters. Two self-powered, one powered by hub (connected to the hubs that had separate power - didn't work otherwise). None of them was stable. It was always the USB-SATA adapters/racks that disconnected, not the hubs.
Then I bought a mPCIe 4-port SATA controller, Marvell chip. Didn't work. It freeze randomly and woudn't even unfreeze with a router reboot. Possibly too much power draw. Then I put a 2-port SATA, ASM1062 and a port replicator. That one works. 2 years and not one disconnect. The cables are a complete mess.
Gigachad · · focus · HN ↗
The Terramaster one is pretty widely used in home setups and seems perfectly fine.
M95D · · focus · HN ↗
Gigachad · · focus · HN ↗
unethical_ban · · focus · HN ↗
Though I really don't use the server anymore and it's probably worth several thousand dollars with the RAM in it. Been thinking of using a spare laptop with external HD bays to do the same job.
marysol5 · · focus · HN ↗
Oxodao · · focus · HN ↗
I'd like more informations about this as I'm not too familiar with firewall setup but every time I tried to setup iptables / nft it was indeed bypassed by docker. Recently I found out in the docs that docker adds a DOCKER-USER table, isn't it enough to put your rules in it to prevent the outside world to reach containers ?