tl;dr: Proxmox or bare metal? Containers yes/no? What is your use case?

I used a Dell R710 when I first started self-hosting, it ran ESXi with one VM for each service I wanted. Restarting the server required me to first shutdown each VM in order and then the whole host. When setting up a new service to host I had to create a new VM (allocate RAM, disk etc), install the OS (I ran Debian) and then follow instructions for how to setup the service. This mostly was not a problem but one software I never managed to get working was Apache Guacamole.

Nowadays I have a Dell Optiplex I salvaged for parts, got a new case and all my HDDs from my R710. Because it has much less RAM and an old Intel i5 (6th or 7th generation), I decided to get into Docker. With Docker containers you write your compose file and it will just work. No more need to dig through documentation for which version of a dependency to use, how to handle if two services on the same host need different versions (this was part of the reason for one VM/service). With Docker, I can try out a software in seconds and have it configured to my liking in minutes.

Today I have NixOS (bare metal) and it comes with Podman which uses systemd. Hence restarting my OS (albeit not that often, almost never unless I mess up my config) is a no-brainer because Podman via systemd will manage everything. Adding, stopping or removing containers in general is easy. I have a script running as a service which will stop a container, create a BTRFS subvolume snapshot, start the service again and start borg backup to backup from the snapshot.

For me using Proxmox would just an extra layer of complexity I don't need. I only have one server and I am the only user.

Questions:

  • Do you use Proxmox instead of a bare metal installation?
  • Do you use containers or do you install manually?
  • What is you use case that requires your setup the way it is?

top 50 comments

sorted by: hot top controversial new old
[–] 1 point 20 hours ago*

Ram is expensive... so all my 24x7 things are containers (docker compose on Alpine Linux) or FreeBSD jails.

  • source
  • [–] 1 point 1 day ago*

    I use VMs for OS isolated and hardware isolation. I run containers on top of OSs for apps.

    That said I use Harvester so I can run containers on bare metal AND VMs as containers.

    Even on one bare metal I do this, so I can spin up a test VM of harvester to confirm configs. If you one node is super beefy a neat trick is to have VMs running a cluster so you can have a kind of high availability even if your infra is a single point of failure.

  • source
  • [–] 5 points 3 days ago*

    Proxmox is a hypervisor, while docker is containerization.

    Comparing them is like comparing an apple to a glass of milk. They have different use cases.

    I run multiple VMs specifically for Docker services. I run other VMs for other things. And LXCs for applications where containerization makes sense but I don't want to use Docker.

  • source
  • [–] 28 points 4 days ago*

    It's not an either-or scenario. Running services in Docker/Podman is great and makes a lot of sense, as you've found. But there's no reason the OS running those Docker containers can't be a VM on a hypervisor like Proxmox. Then you get the simplicity of Docker, in addition to the isolation and segmentation (network and process) provided by VMs, and snapshot-based incremental backups from PBS. It's the best of both worlds. You wouldn't have a VM per service like you ran before, instead you'd have a VM per group of related services with common networking and security requirements. For example, all of your publicly exposed services can run in Docker in their own isolated VM that's walled off from the rest of your network, while your internal-only services also run in Docker, but on a separate VM on your internal network.

  • source
  • [–] 38 points 4 days ago* (3 children)

    I used to be bare metal Debian, but I moved to ProxMox for a few reasons.

    1. Backup and restore is a breeze, and the UI makes things human friendly.
    2. It makes it easier to separate my wiki notes in an LXC so that I can still see them if I’m doing maintenance on my main server VM that requires restarts.
    3. There is essentially no noticeable performance reduction.

    It works, it’s easy, and the simplicity has saved my butt a few times. I don’t think I’ll be switching, and I’d recommend it to anyone running a homelab. I still use docker to manage most of my services inside a VM.

  • source
  • hideshow 3 child comments
  • load more comments (2 replies)
    [–] 8 points 3 days ago (2 children)

    Security is a big reason to use VMs. Containers share the kernel with the host. That means that any of the kernel vulnerabilities from this year (like DirtyFrag and CopyFail) could have been used to compromise your host. Once the host is compromised, the only way to be safe is to literally buy a new machine. Seriously. Viruses can bury deep and even infect the motherboard firmware to persist indefinitely.

    Kernel vulnerabilities are frequent enough that I find VMs worth it. I still use containers in my VMs though.

  • source
  • hideshow 2 child comments
  • [–] 29 points 4 days ago (2 children)

    I use both. The main benefit of proxmox is having VM snapshots/daily backups, if you mess up, just restore the whole thing. You also have stricter isolation, e.g. put public facing containers in one VM and local only stuff in another.

    Also has high availability if you have multiple nodes but that can be achieved with container orchestration as well.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 19 points 4 days ago

    I like the flexibility that proxmox provides me. I do this as a hobby and I'm self taught. I can try a bunch of things and if I mess up I can start over without much hassle.

  • source
  • [–] 20 points 4 days ago (3 children)

    I'll die on this hill.

    Containers run on "bare metal" in the same way that other processes on your system run.

  • source
  • hideshow 3 child comments
  • [–] 3 points 3 days ago*

    I like running docker containers inside of specific unprivileged LXCs on my proxmox host. Why? Because it works and I'm not an expert.

    I can spin up a new LXC and test things without fucking up my entire server. It allows me the flexibility to try new services or attempt things that I'd otherwise be too timid to try on the chance it fucks up my entire system and I have to spend two and half weekends trying to get back to where I was when things just worked.

  • source
  • [–] 11 points 4 days ago

    Proxmox running LXC's and VM's, all of them also have docker installed

  • source
  • [–] 6 points 4 days ago

    Podman sounds like a podcast about other podcasts

  • source
  • [–] 7 points 4 days ago

    Generally speaking:

    • just want it to work with minimal effort: containers
    • need very custom things, or very high efficiency: bare metal
    • need high security, emulating bare metal, or like to do extra IT work: virtualization

    Generally, these days, containers win 99% of the time as the best home lab backbone.

  • source
  • [–] 7 points 4 days ago

    You should be using them depending on your needs. There's a difference between app containers (single app per container), system containers (multiple apps in the same container) and VMs (OS + whatever, virtualized rather than containerized).

    You probably need app containers most of the time so docker or podman is a good fit. But sometimes you might feel more confortable with another level of abstraction. Tools like Proxmox or Incus make it easy to manage "system"-level abstractions like system containers (with LXC) or VMs (with KVM) and give you a unified management approach.

    You don't have to give up app containers either. You can run docker or podman inside an LXC system container and have the best of both worlds.

    Deciding when to take advantage of the system abstraction is the hard part. A simple rule of thumb is to do it when you'd like to manage the "machine" that holds the stack in a way that's different from the host. Maybe you want to run a different Linux distro; maybe it's the same distro as the host but you want to organize it differently; maybe you need to run a non-Linux OS.

  • source
  • [–] 7 points 4 days ago

    I use proxmox for basically anything in my homelab, but there's no particular reason. I use it because it does what I need. It supports VMs in case I need a bit more control over what runs in the system (like a Windows VM) and it supports LXCs that fundamentally work like docker with less configuration steps. It provides a nice webUI if I need to check up on some things and an API so I can orchestrate all my systems with terraform.

    It does the job and I never saw a reason to switch away from it.

  • source
  • Having to manually start and stop your VMs is very atypical, proxmox can absolutely handle that itself

  • source
  • [–] 7 points 4 days ago* (last edited 4 days ago)

    I moved from VMware Fusion after a hardware failure and migrated to Proxmox. I use VMs to isolate client information and to test and use different OS versions and distros.

    I have a VM that runs Docker and connect to it via SSH for running applications I don't want to install on my main workstation.

    My main workstation is also a VM.

    I came from bare metal Linux for years and found that I spent too much time recompiling kernels to make it work with my hardware.

    Now that everything is a VM, changing underlying hardware, and even hypervisor is trivial.

    If VMware hadn't been bought by Broadcom and allowed me to virtualise x86 on Apple Silicon, I'd still be running VMware Fusion. UTM by the way is completely unreliable .. I really tried.

    As it is, I'm running Proxmox on AMD.

    in summary, Proxmox allows me to build what I need when I need it virtually and it's running on a standard Debian host.

    Edit: #$#__# autocorrect (unreadable -> unreliable)

  • source
  • [–] 6 points 4 days ago

    Check out the krun runtime for podman, if you want stronger container isolation from the host. It creates a small VM for each container. Gpu passthrough on linux is limited though.

  • source
  • [–] 6 points 4 days ago

    I use Proxmox with a VM for each service I provide and I still use docker compose.

    This way I have nice VM backups (with Proxmox BS) + dockerized services deployed via GitLab CI pipelines.

  • source
  • [–] 6 points 4 days ago (1 child)

    I like Proxmox for it's first-class treatment of ZFS. You can easily run Docker/Podman on top of it or in a VM. Proxmox has some other advantages like replication and clustering, but I'd say you don't need that in a home setup (at least I don't).

    If I had to redo my setup today, I'd probably give TrueNAS SCALE a chance though.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 5 points 4 days ago (4 children)

    I'm running Docker inside a Debian VM on Proxmox and I forgot why. Next time I'd just run Docker on Debian.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)

    Proxmox with Kubernetes and containerization can allow you more easily manage your services and to have less downtime. But, as you said, it adds another layer. Is it worth the time to set it up? Over a long period, yes.

    As a DevOps/Developer/Sysadmin, I'd probably use it if I set up a lot of services. If I just have some kind of file share thing, probably not.

  • source
  • [–] 5 points 4 days ago

    I used to run bare metal monolith container host and it worked pretty well but eventually network configurations started tripping over each other and causing real issues (complicated by me running rootless Podman and wanting to run K3s cluster etc). I wanted to run Proxmox native containers but it turns out they run full root therefore breakout in one container means full host access, so now I run VMs as container hosts.

  • source
  • [–] 3 points 4 days ago
    • No
    • Manual only
    • Because I'm old and crusty, and always rawdogged service setups. I'm sure containers are nice and all, I just never got around to learning them properly.
  • source
  • [–] 5 points 4 days ago

    @captcha_incorrect Currently I'm running my personal services similar to you using Podman Quadlets and I really like it.
    I have also a testing installation of Proxmox on another system, but I'm also not so clear, if it would be a good way for my purposes.

  • source
  • [–] 3 points 4 days ago

    Proxmox with LXC’s and a few VM’s.
    Often with Portainer as well.

    It’s just nice to use and easy to automate backups.

    I used to run barebone on Debian, but I accepted that I’m not good enough in the terminal and to used to graphical solutions to go back.

  • source
  • [–] 4 points 4 days ago

    I use Proxmox as a VDI server. I understand that this isn't homelab territory, but selfhosted VDIs have proven exponentially more reliable and easier to manage than cloud based ones (after the initial PitA setup). Flawless copy/paste, screen resize, and most importantly, file transfers. When you connect to 12 different clients, each with a different set of security requirements, system hardening, monitoring, and VPN access, being able to console amd fully interact with a sandboxed desktop becomes priceless.

  • source
  • Install incus on your OS of choice to manage LXCs and VMs, it’s ideal!

    No need to chain yourself to an OS that is rolling on the free branch, get stability and control!

    As for LXCs vs Podman containers, seems it is preference of control. LXCs are little OSes you need to keep up to date, containers need to be rebuilt to keep up to date. (I think only Linuxserver images actually rebuild just for base OS updates, hopefully the reverse proxy and authentication images too)

    Podman brings some nice networking, read-only features, and user abstraction with it, I think that helps it push ahead.

    That said, LXCs are little OSes and that flexibility can be very useful. For instance, incus is able to make an LXC with a unique Mac from an Ethernet adapter - I haven’t cooked how to do that with Podman yet. So I run my DNS from there so it doesn’t mess with my server’s DNS port.

  • source
  • [–] 4 points 4 days ago

    I have a mix...

    I have a home built NAS running on Arch with local installation of Immich (ie not a container)

    I also have a low power, passively cooed box with Proxmox installed to run VMs for Home Assistant, ansible, uptime kuma, smokeping, etc.

    I only intended to run Proxmox to test it out (my Home Assistant was running on a Pi3 and getting too slow for Voice), as I'd been using ESXi for years at work.

    I now want to migrate to Arch with Incus and move those VMs across, but as I currently only have the 1 host and hardware's expensive, it'll stay that way for a while...

    (Bonus: I have a few RasPi Zeros scattered around the house too running various things bare metal)

  • source
  • load more comments
    view more: next ›