The Archer C7 at .2 is gone; the FTTH box at .1 is the gateway. Every static holdout (nas host, nuc host, privoxy, transmission-bt) pointed at the dead .2 and had no internet — the reported symptom was privoxy. Also record two things the migration broke that were not obvious: - DHCP reservations did not carry over. blocky held .254 by reservation on the C7; a lease renew on the FTTH box moved it and took LAN DNS down. It is static now. jellyfin-* are still DHCP on stale leases. - The FTTH box advertises native IPv6. transmission-bt's tunnel is AllowedIPs = 0.0.0.0/0, so v6 egressed around the kill switch on the home address. IPv6 is now disabled in that container. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
51 lines
3.1 KiB
Markdown
51 lines
3.1 KiB
Markdown
# Storage: nas
|
|
|
|
Storage + backup host on the LAN, added 2026-08.
|
|
|
|
- **Always-on host.** nuc is now an on-demand media box (see
|
|
[nuc/README.md](../nuc/README.md)), so everything that must stay up —
|
|
LAN DNS, the HTTP proxy, torrents — lives here.
|
|
- Debian 13, Supermicro **A1SAi-2750F** / Intel Atom C2750 (8 c, 20 W,
|
|
ECC DDR3) — build procedure: [nas-install.md](nas-install.md)
|
|
- SSH: `ssh -i id_rsa_claude root@192.168.0.4`
|
|
- **No iGPU** (Avoton is headless; video is the AST2400 BMC). Anything
|
|
needing hardware transcoding stays on nuc.
|
|
- Pools:
|
|
- `incus` — ZFS mirror across the last partition of both 120 GB SSDs;
|
|
holds this host's container roots. OS itself is on mdraid RAID1 +
|
|
ext4 across the same disks (rationale in
|
|
[nas-install.md](nas-install.md) §2).
|
|
- `tank` — the 4 TB WD Red, **on direct SATA**. This is the whole
|
|
point of the box: the disk used to hang off a JMicron USB bridge on
|
|
nuc that suspended the pool 61 times in 30 days
|
|
([nuc/usb4t-dropouts.md](../nuc/usb4t-dropouts.md)). Single vdev,
|
|
accepted — nothing on it is irreplaceable.
|
|
- `tank/media` → `/export/media`: the media library. Exported
|
|
**read-only over NFSv4 to nuc**, where `jellyfin-server` reads it;
|
|
written locally only by `transmission-bt`.
|
|
- Backups: nuc ↔ nas **cross-replication** (each host's instances live
|
|
on the other), plus the ks4 pull leg —
|
|
[nas-install.md](nas-install.md) §9,
|
|
[ks2/nas-seed.md](../ks2/nas-seed.md).
|
|
|
|
## Instances
|
|
|
|
| Name | IP | Doc | Features |
|
|
|---|---|---|---|
|
|
| blocky | 192.168.0.254 | — | unprivileged, autostart; DNS ad-blocker for the LAN. Moved from nuc 2026-08-30 so it survives nuc being powered off |
|
|
| privoxy | 192.168.0.11 | — | unprivileged, autostart; filtering HTTP proxy, listens on **:3128** (not privoxy's default 8118); static config in `/etc/systemd/network/eth0.network` (`Gateway=192.168.0.1`), `DNS=192.168.0.254`. Moved from nuc 2026-08-30 |
|
|
| [transmission-bt](transmission-bt.md) | 192.168.0.7 | ✅ | unprivileged, autostart; always-on WireGuard full tunnel → ks4 (egress = 193.70.35.17, kill switch: no default route in `main`, wg-quick's `fwmark`/`suppress_prefixlength` rules send traffic to table 51820 — **`netplan apply` wipes those rules, so always `systemctl restart wg-quick@wg0` after it**); **IPv6 disabled** (`/etc/sysctl.d/99-no-ipv6.conf`) since the tunnel is `AllowedIPs = 0.0.0.0/0` only and the FTTH box's native IPv6 RA bypassed the kill switch entirely; `/export/media` disk device (`shift=true`), downloads to `/media/downloads`; web UI :9091 (LAN only). Moved from nuc 2026-08-30 |
|
|
|
|
## Backup pools hosted here
|
|
|
|
| incus pool | dataset | receives |
|
|
|---|---|---|
|
|
| `nucbackup` | `tank/backup/nuc` | nuc's instances (pushed nightly, 03:30) |
|
|
| `ks4backup` | `tank/backup/ks4` | ks4's instances (pulled over WG, 05:00 — after FTTH) |
|
|
| `nasbackup` | `tank/backup/nas` | **nas's own** instances (local copy, 04:00) |
|
|
|
|
nas's own instances are replicated **locally** rather than to nuc: nuc is
|
|
an on-demand box and usually powered off, so it is not a usable backup
|
|
target. `nasbackup` lives on `tank`, a different pool from the `incus`
|
|
SSD mirror the instances run on.
|