Proxmox VE is the foundation of my homelab. Every service β the Samba AD controller, Authentik, Forgejo, TrueNAS, the monitoring stack β runs as either an LXC container or a KVM virtual machine on a single Proxmox node. One physical machine, a clean web UI, a full REST API, and the flexibility to run anything from a 64MB Alpine container to a full Windows Server VM.
This article covers the practical decisions behind a useful Proxmox setup: disk layout, network configuration, LXC versus KVM, and the small adjustments that make day-to-day operation smooth.
Proxmox runs on any x86-64 machine, but a few things make a meaningful difference:
Proxmox installs from a bootable ISO onto a dedicated drive. During installation:
/var/lib/pveAfter first boot, disable the enterprise repository and enable the no-subscription repository if you are not purchasing a Proxmox subscription:
# /etc/apt/sources.list.d/pve-enterprise.list
# Comment out the enterprise line, then add:
deb http://download.proxmox.com/debian/pve bookworm pve-no-subscription
apt update && apt dist-upgrade
I separate storage concerns into three tiers:
| Tier | Device | Purpose | |---|---|---| | OS | NVMe (single or ZFS mirror) | Proxmox itself, VM configs | | Fast storage | NVMe or SSD ZFS pool | VM disks, databases, containers | | Bulk storage | HDD ZFS RAIDZ2 | Backups, media, NFS shares |
The fast pool uses a mirrored pair of NVMe or SATA SSDs β IOPS matter for running databases and containers. The bulk pool uses RAIDZ2 (equivalent to RAID6) across four or more drives, accepting lower IOPS in exchange for capacity and double-drive fault tolerance.
Add both pools to Proxmox under Datacenter β Storage after creation with zpool create.
The default Proxmox install creates a single Linux bridge (vmbr0) on the first physical NIC. For a homelab this is fine to start, but VLAN-aware bridging unlocks proper network segmentation:
# /etc/network/interfaces β VLAN-aware bridge
auto vmbr0
iface vmbr0 inet static
address 192.168.1.10/24
gateway 192.168.1.1
bridge-ports enp3s0
bridge-stp off
bridge-fd 0
bridge-vlan-aware yes
bridge-vids 2-4094
With bridge-vlan-aware yes, each VM and container can be tagged to a specific VLAN from the Proxmox UI. The physical NIC connects to a managed switch trunk port. pfSense handles inter-VLAN routing and firewall rules.
This is the most consequential daily decision in Proxmox. The rule I follow:
Use LXC when:
Use KVM when:
In practice: Samba AD, Authentik, Forgejo, NGINX, monitoring stack β all LXC. Windows Server, any VM requiring GPU passthrough β KVM.
Proxmox has built-in snapshot and backup tooling. Snapshots are cheap on ZFS β creating one takes milliseconds and uses copy-on-write to track changes. Use them before any major change:
# From the CLI
pct snapshot <vmid> pre-upgrade --description "Before apt dist-upgrade"
qm snapshot <vmid> pre-upgrade
For backups, Proxmox Backup Server (PBS) is the purpose-built companion tool. It deduplicates across backups and across VMs, making it far more storage-efficient than raw dump backups. A PBS instance running as an LXC container on the same node can back up all other containers and VMs to the bulk ZFS pool β or to an off-site location via the WireGuard tunnel.
intel_iommu=on or amd_iommu=on)chronyc sources should show a reachable server)Proxmox VE Β· ZFS Β· LXC Β· KVM Β· pfSense Β· Proxmox Backup Server