All Activity
- Today
-
feature-request Full disk encryption at setup
fren shaped replied to Kopy's topic in Roadmap & Feature Requests
After doing some reading, it seems TrueNAS does not support LUKS at all. So with encrypted datasets the data is protected when a single drive gets stolen out of a server, or returned/sold/decomissioned, but when the whole server gets stolen, it boots right up and unlocks any encrypted drives with the on board encryption keys. You can argue how big that issue practically is when the server is locked up in a datacenter, but in the world at large, that's definitely not acceptable. I hope HexOS can improve on this situation, as many home servers will be small boxes that are portable enough. It walking off is one of the more likely threats, after hardware failure and misconfiguration perhaps. -
ralf joined the community
-
Fruit joined the community
-
olekrisjamt joined the community
-
feature-request Full disk encryption at setup
fren shaped replied to Kopy's topic in Roadmap & Feature Requests
I want to add that I realize that there's a difference between encrypting your dataset, and full disk/system encryption. Encrypting your datasets prevents people from stealing your data and is arguably the most vital. Full disk encryption/system encryption prevents access to any and all (meta)data that might be on the system drive, and helps with boot disk warranty returns and decomissioning. The threat model is slightly different, but also partially overlaps, and I'd consider both valuable additions. If dataset encryption could be inherited from the system encryption in the same way a dataset can inherit encryption from a parent in TrueNAS, things would be pretty straightforward and easy to wrap your head around. Manually setting up full disk LUKS encryption is incredibly flexible, but once you start working with multiple drives and cascading unlocks overlooking or misconfiguring something becomes more likely. Having a simple GUI option for that would be great for peace of mind. -
Why we NEED local config acces, eventually.
fren shaped replied to Duhmez's topic in Roadmap & Feature Requests
The wording used could be interpreted as still needing the Command Deck for setup, but not for management afterwards. Do we know whether this how it should be interpreted, or that the initial setup could also be done locally once 1.0 has been released? I have to say I appreciate the willingness of the HexOS team to listen to features suggested by the community and to actually implement them. -
cnex101 started following Tailscale?
-
Nice score! May I suggest to monitor the power consumption for a bit after getting everything up and running? If power is cheap around your parts you probably don't need to worry, but if it is not, things could quickly add up, as tends to be the case with anything running 24/7 and doubly so with more venerable hardware. It's probably fine, but just so you don't get blindsided by a big bill. That being said, tinkering with server hardware can be lots of fun. Desktop hardware is cool and all, but the specialized enterprise features they put on servers can be interesting to play around with. If you're not familiar, be sure to check out the iDRAC!
-
feature-request Full disk encryption at setup
fren shaped replied to Kopy's topic in Roadmap & Feature Requests
I third this feature request. The job of a NAS is both making data available to you, and unavailable to anyone else who isn't authorized. If someone can just walk off with your server or a drive and gain access to all your personal data, the system is fundamentally unsafe, and not doing its job. Hardware theft should be a financial matter, not a data breach and a major long term worry. Of course, encrypted disks also make warranty returns or decomissioning hardware less of a hassle. I can see arguments for and against enabling full disk encryption by default, even though I feel users should be recommended to do so, while obviously also making clear that losing your password means losing all your data. -
DMGREEN715 joined the community
-
fren shaped joined the community
-
seeg joined the community
- Yesterday
-
joshish joined the community
-
Vytenis joined the community
-
DaCoz joined the community
-
sbufe joined the community
-
Welcome, let’s introduce ourselves here!
pinormous replied to DartSteven's topic in Coffee Talk (Off-Topic)
The previous owner (who had the house custom built) just had a deep freeze in there; not sure why he wanted the vent, but I appreciate his attention to quality, detail, and versatility in his design choices. Was hoping to find someone I could buddy backup my PC image with; I'm sure we can help each other out. -
Thank you, fixed it. Should be fixed in hexos update??
-
I personally didn’t have an issue with this on one of my servers. But if I remember that issue was a docker install issue with the initial setup. Quick resolution would be a full reinstall at the start post drive wipes
-
@Mobius, @Mindless999, my statement was not correct. You can use multiple pools. But it could be that installing 1 click apps are broken with 2 pools. If I remember correctly you have to correct this via the TrueNas interface. We had several forum post about this topic.
-
Welcome, let’s introduce ourselves here!
Dylan replied to DartSteven's topic in Coffee Talk (Off-Topic)
Really jealous of this. I also have a spot under stairs that would be PERFECT for my gear but there is zero way to vent heat (much less cool it) at least without spending silly $$ You've got ample capacity for storage....hoping we can be friends when buddy backup is supported 😁 - Last week
-
are you sure? i got some new drives in today and made a 2nd pool (using hexos interface) without any issues First pool was made using truenas ui (mismatched drive sizes) so maybe making pools in truenas makes a difference? edit: maybe installing 1 click apps are broken with 2 pools? edit2: i got plex to install just not immich, weird
-
Welcome, let’s introduce ourselves here!
pinormous replied to DartSteven's topic in Coffee Talk (Off-Topic)
I expect it will, yes. I have an unused, enclosed nook under the basement stairs; it already has an exhaust vent I plan to put a fan in and it'll be a short run to add an 10/8 gauge drop from the 200 amp box in the garage. -
One of us should make sure to post/share that when he uploads that video. I'd be super interested.
-
HA!! That is great! I just wish he showed proper acknowledgment with something like "This is for my American friend Dylan, who with his stimulating engagement on the HexOS forums, deserves a proper deep dive into the new hardware about to land on your door step. Thanks, Dylan - this one is for you!" I mean...just sayin 🤓
-
I agree with @Sonic - this makes sense and I've already planned for this same expansion on my current 4x8TB NAS.
-
Welcome, let’s introduce ourselves here!
Dylan replied to DartSteven's topic in Coffee Talk (Off-Topic)
Nice rig. Where are you going to put that half rack? That's gotta be drawing more that 15-20 amps, no? -
Welcome, let’s introduce ourselves here!
pinormous replied to DartSteven's topic in Coffee Talk (Off-Topic)
My gaming setup: Corsair Crystal 570x case Ryzen 7 9800x3d 32 GB DDR5 at 7200 mhz Gigabyte RTX 3080 ti Corsair K100 keyboard and Ironclaw mouse Logitech G920 wheel and pedals with Eaton shifter by CustomSimShop Dark Matter 34" 1440p ultrawide Senny HD 6xx powered by Fosi K5 Pro Server stack: Tripp-Lite 25u rack (got the height wrong earlier) Itech BHK117-8e 8 port KVM Dell SC8000 2x Netapp DS4243 w/IOM6s Still hunting for the right UPS, PDUs, and switch to get it all spun up. Truck: 2024 Freightliner Cascadia DD13 engine with DT12 automatic transmission 72" sleeper, double bunk Adaptive cruise, lane departure, TK Tripak Evo APU, 1500w inverter Gigabyte GF KF5 laptop for media consumption and gaming connected to a 40" Vizio TV -
This is well thought approach. One thing to keep in mind. HexOs only supports one pool at the moment. In the future it will support multiple pools. It’s still on the roadmap.
-
It makes sense, will think about it. Also I want to have a raid of max 4 disks, and if I need to expand, just do a second (HDD) RAID with new disks which I can then expand the system by swapping the disks in the future. So if I would have 4x 8TB, will swap the 8 TB disks with 20 TB in the future (example), that way I don't need to swap *all* disks at once, but can just do a few at the same time, while keeping my hardware (and software) the same.
-
@Dylan, Robbie is also reading your questions on the HexOs forum 🙂🙃 This is published tonight: https://www.youtube.com/watch?v=EMCHZVsAKdo
-
It was for more of a because i can since 3 still cost less than one of your previous boot ssd. Ofc you can just do 2 and you'll more than likely be fine. It's more of a future proofing, eventually if you'll want to expand you can expand with 24tb drives which will no doubt go down in price. And your final total capacity will just be that bit higher. Plus 5x24tb with 1 parity drive will use less power than 6x 20tb with one parity drive and give you a similar amount of storage. I first made my storage server around 5 years ago and filled up with 14tb drives now the only good way for me to expand is to get a second system since sata slots in my opinion are pretty valuable I just woke up so sorry if this didn't make too much sense
-
It looks like they don't sell directly, and I probably will go with the EXOS disks in the end since they are a lot cheaper. In Europe it looks like they are only selling through 3rd party resellers. (at least in my country) Although the disks are a lot lower, based on how they handle import taxes, and also the transport costs, it will be cheaper to get "new ones". Great tip for anyone who doesn't need to worry about this though! So simply put: if you run Linux, try to only use Intel cards? Thanks for all the tips there, Since I won't go for any Plex etc, and I have currently a preference of AMD over Intel (and AM5 is currently easily upgradable for the future) I will stick with AM5 for now. I saw you put the 24 TB disks there, and 3x a 128GB SSD. Why would you go for a 3x 128GB ssd for the OS, wouldn't 2 be enough even for a RAID 1 setup? Also the 24TB are (currently) a bit more expensive per GB, any big reason you went for those, other than: they are bigger? Thanks everyone for there 2Cents 🙂 I haven't decided yet when I will get it, but it's now getting more and more into shape. I might build it in a few months, and will definitely update once I received it how everything's going also with changes, and will share once finished.
-
BTW, Robbie from Nascompares announced that he will visit AOOSTAR in October 2025.
-
Let the reviews enter the room 😀. I think the WTR Max, the Zima Cube and the N5 (pro) are only the beginning of series of new NAS / SFF server innovations. I expect to see a lot of new concepts in 2025 / 2026.
-
So, here’s the link to my Raspberry Pi 5 walnut case. I’ll write more about the Pi in my own topic. https://barebaric.com/en/shop/barebaric-raspberry-pi-5-case-made-from-real-oak-or-walnut-wood-1#attr=14,2,3