Files
doc/nas/README.md
T
Julien LutranandClaude Opus 5 58dcaa5d41 nas: new storage host on A1SAi-2750F — 4 TB off USB onto SATA
Builds the box that ends the usb4t dropouts: the JMicron bridge was the
least reliable device in the setup and it held the intended off-site copy
of ks4. The 4 TB now sits on direct SATA as pool `tank`.

- OS on mdraid RAID1 across two 120 GB SSDs (Intel 330 + Toshiba Q300),
  both ESPs bootable; `incus` ZFS mirror on their tails, ~22% left
  unallocated as over-provisioning
- media at /export/media, exported read-only over NFSv4 to nuc
- transmission-bt moves here (its WireGuard tunnel is in-container, so
  ks4 needed no change) and writes to the dataset locally
- backup pools nucbackup / ks4backup / nasbackup
- monitoring live: msmtp (submission+auth, verified 250), zed with
  NOTIFY_DATA, zpool-health.sh every 15 min, smartd on all three disks

Traps recorded because none of them point at their own cause: booting
with the display active kills the i915 probe and wedges incus; d-i picks
grub-pc vs grub-efi from how the installer booted; `incus storage create`
hangs forever on a mountpoint=none dataset; the BMC is deliberately never
cabled, so there is no out-of-band console.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-30 23:53:30 +02:00

51 lines
2.8 KiB
Markdown

# Storage: nas
Storage + backup host on the LAN, added 2026-08.
- **Always-on host.** nuc is now an on-demand media box (see
[nuc/README.md](../nuc/README.md)), so everything that must stay up —
LAN DNS, the HTTP proxy, torrents — lives here.
- Debian 13, Supermicro **A1SAi-2750F** / Intel Atom C2750 (8 c, 20 W,
ECC DDR3) — build procedure: [nas-install.md](nas-install.md)
- SSH: `ssh -i id_rsa_claude root@192.168.0.4`
- **No iGPU** (Avoton is headless; video is the AST2400 BMC). Anything
needing hardware transcoding stays on nuc.
- Pools:
- `incus` — ZFS mirror across the last partition of both 120 GB SSDs;
holds this host's container roots. OS itself is on mdraid RAID1 +
ext4 across the same disks (rationale in
[nas-install.md](nas-install.md) §2).
- `tank` — the 4 TB WD Red, **on direct SATA**. This is the whole
point of the box: the disk used to hang off a JMicron USB bridge on
nuc that suspended the pool 61 times in 30 days
([nuc/usb4t-dropouts.md](../nuc/usb4t-dropouts.md)). Single vdev,
accepted — nothing on it is irreplaceable.
- `tank/media``/export/media`: the media library. Exported
**read-only over NFSv4 to nuc**, where `jellyfin-server` reads it;
written locally only by `transmission-bt`.
- Backups: nuc ↔ nas **cross-replication** (each host's instances live
on the other), plus the ks4 pull leg —
[nas-install.md](nas-install.md) §9,
[ks2/nas-seed.md](../ks2/nas-seed.md).
## Instances
| Name | IP | Doc | Features |
|---|---|---|---|
| blocky | 192.168.0.254 | — | unprivileged, autostart; DNS ad-blocker for the LAN. Moved from nuc 2026-08-30 so it survives nuc being powered off |
| privoxy | 192.168.0.11 | — | unprivileged, autostart; filtering HTTP proxy, listens on **:3128** (not privoxy's default 8118); static config in `/etc/systemd/network/eth0.network`, `DNS=192.168.0.254`. Moved from nuc 2026-08-30 |
| [transmission-bt](transmission-bt.md) | 192.168.0.7 | ✅ | unprivileged, autostart; always-on WireGuard full tunnel → ks4 (egress = 193.70.35.17, kill switch: no default route); `/export/media` disk device (`shift=true`), downloads to `/media/downloads`; web UI :9091 (LAN only). Moved from nuc 2026-08-30 |
## Backup pools hosted here
| incus pool | dataset | receives |
|---|---|---|
| `nucbackup` | `tank/backup/nuc` | nuc's instances (pushed nightly, 03:30) |
| `ks4backup` | `tank/backup/ks4` | ks4's instances (pulled over WG, 05:00 — after FTTH) |
| `nasbackup` | `tank/backup/nas` | **nas's own** instances (local copy, 04:00) |
nas's own instances are replicated **locally** rather than to nuc: nuc is
an on-demand box and usually powered off, so it is not a usable backup
target. `nasbackup` lives on `tank`, a different pool from the `incus`
SSD mirror the instances run on.