← Blog

Alexis Β· 2026-09-29

Running Proxmox on bare metal: a practical setup guide

Proxmox VE is the foundation of my homelab. Every service β€” the Samba AD controller, Authentik, Forgejo, TrueNAS, the monitoring stack β€” runs as either an LXC container or a KVM virtual machine on a single Proxmox node. One physical machine, a clean web UI, a full REST API, and the flexibility to run anything from a 64MB Alpine container to a full Windows Server VM.

This article covers the practical decisions behind a useful Proxmox setup: disk layout, network configuration, LXC versus KVM, and the small adjustments that make day-to-day operation smooth.

Hardware considerations

Proxmox runs on any x86-64 machine, but a few things make a meaningful difference:

Installation

Proxmox installs from a bootable ISO onto a dedicated drive. During installation:

After first boot, disable the enterprise repository and enable the no-subscription repository if you are not purchasing a Proxmox subscription:

# /etc/apt/sources.list.d/pve-enterprise.list
# Comment out the enterprise line, then add:
deb http://download.proxmox.com/debian/pve bookworm pve-no-subscription
apt update && apt dist-upgrade

Disk layout

I separate storage concerns into three tiers:

| Tier | Device | Purpose | |---|---|---| | OS | NVMe (single or ZFS mirror) | Proxmox itself, VM configs | | Fast storage | NVMe or SSD ZFS pool | VM disks, databases, containers | | Bulk storage | HDD ZFS RAIDZ2 | Backups, media, NFS shares |

The fast pool uses a mirrored pair of NVMe or SATA SSDs β€” IOPS matter for running databases and containers. The bulk pool uses RAIDZ2 (equivalent to RAID6) across four or more drives, accepting lower IOPS in exchange for capacity and double-drive fault tolerance.

Add both pools to Proxmox under Datacenter β†’ Storage after creation with zpool create.

Network design

The default Proxmox install creates a single Linux bridge (vmbr0) on the first physical NIC. For a homelab this is fine to start, but VLAN-aware bridging unlocks proper network segmentation:

# /etc/network/interfaces β€” VLAN-aware bridge
auto vmbr0
iface vmbr0 inet static
    address 192.168.1.10/24
    gateway 192.168.1.1
    bridge-ports enp3s0
    bridge-stp off
    bridge-fd 0
    bridge-vlan-aware yes
    bridge-vids 2-4094

With bridge-vlan-aware yes, each VM and container can be tagged to a specific VLAN from the Proxmox UI. The physical NIC connects to a managed switch trunk port. pfSense handles inter-VLAN routing and firewall rules.

LXC containers vs KVM virtual machines

This is the most consequential daily decision in Proxmox. The rule I follow:

Use LXC when:

Use KVM when:

In practice: Samba AD, Authentik, Forgejo, NGINX, monitoring stack β€” all LXC. Windows Server, any VM requiring GPU passthrough β€” KVM.

Snapshots and backups

Proxmox has built-in snapshot and backup tooling. Snapshots are cheap on ZFS β€” creating one takes milliseconds and uses copy-on-write to track changes. Use them before any major change:

# From the CLI
pct snapshot <vmid> pre-upgrade --description "Before apt dist-upgrade"
qm snapshot <vmid> pre-upgrade

For backups, Proxmox Backup Server (PBS) is the purpose-built companion tool. It deduplicates across backups and across VMs, making it far more storage-efficient than raw dump backups. A PBS instance running as an LXC container on the same node can back up all other containers and VMs to the bulk ZFS pool β€” or to an off-site location via the WireGuard tunnel.

Post-install checklist

Stack

Proxmox VE Β· ZFS Β· LXC Β· KVM Β· pfSense Β· Proxmox Backup Server