tl;dr: Proxmox or bare metal? Containers yes/no? What is your use case?

I used a Dell R710 when I first started self-hosting, it ran ESXi with one VM for each service I wanted. Restarting the server required me to first shutdown each VM in order and then the whole host. When setting up a new service to host I had to create a new VM (allocate RAM, disk etc), install the OS (I ran Debian) and then follow instructions for how to setup the service. This mostly was not a problem but one software I never managed to get working was Apache Guacamole.

Nowadays I have a Dell Optiplex I salvaged for parts, got a new case and all my HDDs from my R710. Because it has much less RAM and an old Intel i5 (6th or 7th generation), I decided to get into Docker. With Docker containers you write your compose file and it will just work. No more need to dig through documentation for which version of a dependency to use, how to handle if two services on the same host need different versions (this was part of the reason for one VM/service). With Docker, I can try out a software in seconds and have it configured to my liking in minutes.

Today I have NixOS (bare metal) and it comes with Podman which uses systemd. Hence restarting my OS (albeit not that often, almost never unless I mess up my config) is a no-brainer because Podman via systemd will manage everything. Adding, stopping or removing containers in general is easy. I have a script running as a service which will stop a container, create a BTRFS subvolume snapshot, start the service again and start borg backup to backup from the snapshot.

For me using Proxmox would just an extra layer of complexity I don’t need. I only have one server and I am the only user.

Questions:

  • Do you use Proxmox instead of a bare metal installation?
  • Do you use containers or do you install manually?
  • What is you use case that requires your setup the way it is?
  • hirihit640@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Security is a big reason to use VMs. Containers share the kernel with the host. That means that any of the kernel vulnerabilities from this year (like DirtyFrag and CopyFail) could have been used to compromise your host. Once the host is compromised, the only way to be safe is to literally buy a new machine. Seriously. Viruses can bury deep and even infect the motherboard firmware to persist indefinitely.

    Kernel vulnerabilities are frequent enough that I find VMs worth it. I still use containers in my VMs though.

  • ferret@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Having to manually start and stop your VMs is very atypical, proxmox can absolutely handle that itself

  • tofu@lemmy.nocturnal.garden
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    I use both. The main benefit of proxmox is having VM snapshots/daily backups, if you mess up, just restore the whole thing. You also have stricter isolation, e.g. put public facing containers in one VM and local only stuff in another.

    Also has high availability if you have multiple nodes but that can be achieved with container orchestration as well.

    • TeaWithDani@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      13 days ago

      Couldnt you just make daily snapshots on baremetal? Like most configs will support a ZFS pool.

      All my stuff is just configs anyway, so my backup is a Git commit. Lighter than a full snapshot. My server can be restarted with like 50mbs of information.

      Docker images are images so disposable. All my files and databases are on my NAS which is a ZFS pool mirrored and with a weekly backup to a secondary NAS also mirrored. Plus I have an offsite cloud backup of everything. There isnt really anything on my server that matters other than some configs, scripts and ymls. Which by commiting to my Gitea, are all on my NAS with the rest of my data.

      I still feel like Proxmox just invites you to tinker and fiddle with stuff that should be set and forget. Or overcomplexify your setup with too many moving parts.

      For public stuff I just use a VPS. Better internet connection than at home, high availability and DDOS protection. Otherwise, an LXC with good firewall rules and a well configured reverse proxy should be sufficient.

      • tofu@lemmy.nocturnal.garden
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        Sure, you can probably build something similar with zfs snapshots, but it’ll likely not be as convenient. Have a VM? Create daily snapshots. Break something and can’t figure it out? Just reset to the last backup to a complete working state.

        Personally, I have the containers’ mounts in the VMs (ergo on the nodes’ disks) and just using the NAS for the backups. Even if both Proxmox nodes catch fire I can just import the snapshot to a new one and have a working VM in the same state again. That’s a whole different level from re-cloning all the compose stacks, mount NFS shares etc. It’s the ease of use.

    • gnuplusmatt@reddthat.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      13 days ago

      trusting an oci repository is the same as trusting a distro repository, if its a dodgey unknown you got from god knows where and you cant verify, dont use it

      • moldy_rice@piefed.keyboardvagabond.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        12 days ago

        Nope. You don’t need to trust a distro Repo’s publishing infrastructure because the packages are cryptographically signed.

        Whereas the oci repo had a ton of vectors for delivering maliciously modified code because they include image layers that are totally unsigned.

        • gnuplusmatt@reddthat.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          12 days ago

          oci repositories support signing artifacts, container trust policies are a thing. bootc repos are both signed and are distro repos, ostree Fedora and ublue are using it

          Just because quay.io or hub.docker can be accessed without signatures or trust doesn’t mean there aren’t repos out there using it.

  • lemonaz@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Proxmox exclusively with unprivileged LXCs, which themselves host other docker containers/stacks managed with Dockhand (a more modern alternative to both Portainer and Dockge). I have a very tiny low power machine so I have to be kind with my resources, therefore no VMs. But LXCs are simpler anyway. I can easily pass devices like /dev/tun for tailscale and i forget the name of the iGPU for accelerated workloads (for Immich, Nextcloud).

    Reasoning: with containers it’s easy to make mistakes without dire consequences (just docker compose down -v and start over). The LXCs are easy to back up and restore. They hold internal running state of whatever docker containers I run in them.

    Pro tip: don’t map host paths using the UI (mp0 etc), use lxc.mount instead. This will let you continue to have snapshots of your LXCs whereas the other approach makes your LXC incompatible with snapshots.

    Good luck!

  • SirLeToet@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Docker has its uses, but it has gone to far.

    I already have a webserver with Apache, mariadb and everything. Why does your PHP based website only come as a docker solution? Fuck you.

    When you go all in with docker, it quickly becomes a mess with rando NICs and containers named “random 32 character string” and dependencies up the wazoo. Ending up running ancient packages because the developer refuses to apt upgrade their shit.

    Proxmox or any other hypervisor platform gives you control. Whereas you have to take it for docker and youre still at the mercy or the developers to keep your shit secure.

    • GreenKnight23@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      all the problems you expressed with docker aren’t real problems.

      I think you may not like it because you don’t know how to use it.

      don’t like how often a maintainer updates their images? build your own.

      don’t like having multiple bridge interfaces on your host? configure and manage networks within docker and assign them to your containers.

      don’t like having dozens of containers with random names? use docker compose. bonus, you can set up networking with it even easier.

      • SirLeToet@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 days ago

        What? Outdated junk running in containers because the maintainer didnt update their shit is not a real problem?

        Seems that it is perhaps you who doesnt know how to use it.

    • Lee@retrolemmy.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      Years ago I’d have one PHP app that required version X of PHP and another that required version Y and my distro often only had one of them (or you couldn’t install both simultaneously), so I’d have to either compile myself (or later use a 3rd party repo). All solvable of course, but then throw in MySQL version requirements and PHP extensions and it’s just extra crap that containers just take care of for you. I’ve had this kind of inter app requirements conflicts with stuff other than PHP, but I’ve had by far more of it with PHP. For a while I used FreeBSD jails to help, but jails was kind of a pain. I enthusiastically embraced docker for PHP stuff early on.

      A benefit for application developers, particularly PHP is there’s a lot of differences between distros and how people install and configure PHP. Even like which PHP extensions are available and their settings. Other languages things tend to be more consistent at the system level and customizations are app are usually application level (contrast with PHP extensions and system level configurations). It really helps reduce support issues due to distro/user differences if a developer just provides a working dockerfile as a reference implementation and in my experience this is far more likely with PHP than other languages. I realize this is mostly applicable outside of PHP, but I actually personally see more benefit with PHP based on my past experiences.

      • SirLeToet@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 days ago

        Why not have the option for both?

        I dont see how this is a defense for jamming everything in to a container.

    • 3abas@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 days ago

      Ending up running ancient packages because the developer refuses to apt upgrade their shit.

      Tell me you never really had to deal with dependency hell without telling me. That’s literally the main problem docker solves.

      • SirLeToet@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 days ago

        I have had to deal with dependency hells plenty, i am a Debian user after all.

        But with that argument you’re now just running outdated shit in a container. Not a great pro-docker argument tbh.

  • terabyterex@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    because sometimes i need a vm (home assisstant has more features thsn home assisstant container), sometimes a container (i mostly use lxc).

    its not really an extra lauer because proxmox is an os.you use nixos i use proxmox. everything is out of the box. proxmox has comminntiu scripts to run everythkng and set them up. so want to install radarr? bash -c “$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/ct/radarr.sh)”

    sure podman has similar setup but i also need vms and they are all mamaged in one place

    • Oha@lemmy.pobierz.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      so want to install radarr? Paste this totally not sketchy bash script into your terminal and execute it as root!!

      • signalsayge@infosec.pub
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 days ago

        ProxmoxVE helper scripts have been around for quite a while and are pretty easy to read, as well as being pretty well supported in the community. You can just go to the GitHub page and read them. I’ve used some of their scripts before by downloading them, customizing the scripts to my needs, and hosting it on a local web server inside my network. Now I can run one command and I’ll have a new debian container on my host with ssh keys and everything.

        • sonstwas@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          While I agree with you that they’re well seasoned and established I disagree a lot with them being easy to read. They have a lot of sub-scripts that they include willy-nilly over multiple levels.

          Another thing I dislike about them is basically the same as with docker, that they all include everything in it. Like every container wants his own mariadb/postgres/whatever. It should be at least an option to use existing containers, I don’t need to run 5 psql servers… (I know that it had advantages too having everything separate but ehh). And then switching the software back to using the existing psql is more work then just not using the scripts at all…

  • airgapped@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    I used to run bare metal monolith container host and it worked pretty well but eventually network configurations started tripping over each other and causing real issues (complicated by me running rootless Podman and wanting to run K3s cluster etc). I wanted to run Proxmox native containers but it turns out they run full root therefore breakout in one container means full host access, so now I run VMs as container hosts.

  • SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    I have a mix…

    I have a home built NAS running on Arch with local installation of Immich (ie not a container)

    I also have a low power, passively cooed box with Proxmox installed to run VMs for Home Assistant, ansible, uptime kuma, smokeping, etc.

    I only intended to run Proxmox to test it out (my Home Assistant was running on a Pi3 and getting too slow for Voice), as I’d been using ESXi for years at work.

    I now want to migrate to Arch with Incus and move those VMs across, but as I currently only have the 1 host and hardware’s expensive, it’ll stay that way for a while…

    (Bonus: I have a few RasPi Zeros scattered around the house too running various things bare metal)

  • Lemmchen@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    I like Proxmox for it’s first-class treatment of ZFS. You can easily run Docker/Podman on top of it or in a VM. Proxmox has some other advantages like replication and clustering, but I’d say you don’t need that in a home setup (at least I don’t).

    If I had to redo my setup today, I’d probably give TrueNAS SCALE a chance though.

  • hamsda@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    I use Proxmox with a VM for each service I provide and I still use docker compose.

    This way I have nice VM backups (with Proxmox BS) + dockerized services deployed via GitLab CI pipelines.

  • Svinhufvud@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    Check out the krun runtime for podman, if you want stronger container isolation from the host. It creates a small VM for each container. Gpu passthrough on linux is limited though.

  • Jo Miran@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    I use Proxmox as a VDI server. I understand that this isn’t homelab territory, but selfhosted VDIs have proven exponentially more reliable and easier to manage than cloud based ones (after the initial PitA setup). Flawless copy/paste, screen resize, and most importantly, file transfers. When you connect to 12 different clients, each with a different set of security requirements, system hardening, monitoring, and VPN access, being able to console amd fully interact with a sandboxed desktop becomes priceless.