Because she used Jesus as a ‘get out of jail free’ card.

Tailscale is an overlay network. It will use whatever networking is available. If only one of those NICs is a gateway, then that’s what will be used to reach remote Tailnet resources.

Leaving this post here since it's an interesting project to keep an eye on, but the conversation isn't constructive. So, locking the comments.

If the connections are already tagged as you come into the Proxmox server, then you need only to create interfaces for them in Proxmox (vmbr1, vmbr2, etc). EDIT: if you’re doing PCI passthrough of the physical NICs, ignore this step.

Then, in OPNsense, you just adding the individual interfaces. No need to assign a VLAN inside OPnsense because the traffic is already tagged on the network (per your earlier statement).

Whether or not the managed switch that has tagged each port is also providing VLAN isolation, you’ll simply use the OPNsense firewall to provide isolation, which it does by default. You’ll use it to allow the connections access to the fiber WAN gateway.

Proxmox is Debian at its core, which is supported by Docker. There’s no good reason to not run Docker on the bare metal in a homelab. I’d be curious to know what statement Proxmox has made about supporting Docker. I’ve found nothing.

When you mention Postgres, are you saying PG specifically is better, or are you implying that the default SQLite db is what really slows things down? I ask because I’m on mariadb with no complaints, but might switch if NC is faster on Postgres.

No additional stress to the roof. One does have to remove then reinstall if getting the roof done. The cost is approx. $100/panel. With 42 panels, that’s an extra $4200 for a roof job. But, that’s the only real consideration.

Locking the thread. Information relevant to self-hosters has already been shared. Too many reports of off-topic comments to leave this open.

Seriously? Do we have to create a "no posts about what's happening on Reddit" rule?

The moderator team will take this as a learning opportunity. We don't have any rules for this community specific to rudeness or insults. This post was fine as an opinion piece until Edit 2. For this reason, I'm locking the post. Additionally, we'll be updated the community rules on the Sidebar shortly.

