this post was submitted on 16 Aug 2026
22 points (100.0% liked)

askchapo

23328 readers
172 users here now

Ask Hexbear is the place to ask and answer ~~thought-provoking~~ questions.

Rules:

  1. Posts must ask a question.

  2. If the question asked is serious, answer seriously.

  3. Questions where you want to learn more about socialism are allowed, but questions in bad faith are not.

  4. Try !feedback@hexbear.net if you're having questions about regarding moderation, site policy, the site itself, development, volunteering or the mod team.

founded 6 years ago
MODERATORS
 

I am technologically skilled to some extent, but not nearly enough to justify the financial investment I'm about to make In a home server without checking that I'm not way off the mark. Reddit tech answers are usually useless, all jerking each other off about being the most vague and useless. So I'm here, just humbly asking if my plan will work before I waste a ton of money if it doesn't.

So I want to run immich, jellyfin, vaultwarden, and a couple other small programs (including backup automation) on a home server. The photos and videos are very important and I want off of large corporate cloud services for all the reasons you can imagine. There are about 2TB of important photos and data right now to backup.

So my plan: a mini pc with a low-level i3 or i5 chip but about 256gb SSD and 8gb ram. I will buy a UPS, a hub/NAS for 2 4TB HDDs, and a separate hub for backups elsewhere on another 4TB HDD. I already have a pc with an ok graphics card (only like 8 years old, but it was above average then) and good processor. My plan is to run the server with Linux, docker, and portainer on the mini-pc, and do the most intensive work (things like local Machine Learning on the photo library in immich) on the gaming pc. To save on energy, the mini pc is the only thing on most of the time, and I will turn on the old gaming pc to do the hard tasks.

I am hoping a friend will allow me to (somehow? I don't know how yet) keep a hub+HDD backup at their place which is updated weekly automatically whenever their computer turns on.

Is this all achievable? Am I missing something small or huge? Any tech people here know something that I'll likely miss on my first attempt?

you are viewing a single comment's thread
view the rest of the comments
[–] Chana@hexbear.net 2 points 1 month ago

The main thing is to put up some roadblocks to getting your data.

Your main defense is to ensure your data is encrypted and that you're using ssh to send it, specifically using ssh public + private keys and not a password. Then even if someone manages to access your system, they can't get the data without being a pretty high level attacker (like a government). If you set up just this it'll probably be enough.

Regarding full disc encryption, it is possible but a little complex to set up in this instance because it requires you to put in a password before the kernel starts (kernel is loaded from disc) so you would need to be present or buy another thing (a kvm box). Or have server level hardware that provides a kvm already, which requires $$$ or a lot of research to find a consumer machine with it. A kvm box might actually be handy for you (gives you a remote keyboard, screen, mouse at the hardware level) and there are less expensive ones on AliExpress but you don't need it. Example: imagine you do a system update to keep things secure and something goes wrong before the ssh server starts. Without a kvm you'll be unable to access the system remotely to fix it - you'll need to go to your friend's house. Probably not a huge deal but just something to think about.

But you can give yourself a lot of the benefits by just encrypting one partition. You can then either use something like a mini ssh server (dropbear) to enter a password to unlock it remotely or have the tpm auto unlock it. The former is better security-wise but then you have to have internet access at that early stage (more setup). The auto-unlock with the tpm means if someone takes only the drive and not the whole computer, then they can't decrypt it. So it's quite a bit less protective but also very easy to set up and you can try to add the drop bear functionality later once you have tpm auto unlock. Please note that you'll 100% want a password as your main fallback option for unlocking a partition, as then you can still access the data even if something else fails (machine breaks, bios update goes wrong, etc).

I think a good compromise is the use of ssh + encrypted backups, a single encrypted partition that is unlocked by the tpm (and has a backup password), and requiring a password for accessing your bios + boot menu. This eliminates all plausible threats:

  • Your running system is protected by standard Linux password protection which is quite good.
  • Your system is protected against someone accessing your drive by using a bootable USB drive. The password for bios/boot menu for sure and the tpm can also be set up to not unlock when new hardware is attached, if you want that.
  • Your drive is protected if it's taken alone (bound to the tpm, which is on the motherboard).

If you just do my very first suggestion (encrypt the data itself, use ssh + keys) you'll probably be just fine though. It could also be just fine to just do that and keep the other stuff in mind for the future. Just getting remote access to your friend's network will be a decent enough project!