<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tod's Homelab</title><link>https://homelab.tod.net/</link><description>Recent content on Tod's Homelab</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 08 Jul 2026 23:35:00 -0400</lastBuildDate><atom:link href="https://homelab.tod.net/feed.xml" rel="self" type="application/rss+xml"/><item><title>Migrating Active Directory to Samba, One Domain Controller at a Time</title><link>https://homelab.tod.net/posts/off-windows/migrating-active-directory-to-samba/</link><pubDate>Wed, 08 Jul 2026 23:35:00 -0400</pubDate><guid>https://homelab.tod.net/posts/off-windows/migrating-active-directory-to-samba/</guid><description>&lt;p&gt;&lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/"&gt;The first post in the Downsizing series&lt;/a&gt; named Active Directory as one of the two reasons the old Windows dependency had to go: &lt;code&gt;vader&lt;/code&gt; and &lt;code&gt;maul&lt;/code&gt;, two Windows Server 2019 domain controllers, each a license to track and a machine that existed mainly to run one service. &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/the-pki-detour/"&gt;The PKI Detour&lt;/a&gt; covered the identity side of that problem going sideways for two weeks — a dead-end ACME proxy, three failed attempts at FreeIPA — before landing on Samba AD as the replacement. This is the second post in &lt;strong&gt;Off Windows&lt;/strong&gt;, the thread that tracks removing every remaining Windows dependency from the lab; &lt;a href="https://homelab.tod.net/posts/off-windows/preparing-the-windows-fleet-for-samba/"&gt;the first post&lt;/a&gt; covered getting the rest of the fleet ready the evening before. This one covers the part that actually moves the domain: the in-place replica join that swaps both Windows DCs for a Samba box named &lt;code&gt;sidious&lt;/code&gt;, without a single workstation noticing.&lt;/p&gt;</description></item><item><title>Preparing the Windows Fleet for Samba</title><link>https://homelab.tod.net/posts/off-windows/preparing-the-windows-fleet-for-samba/</link><pubDate>Sun, 05 Jul 2026 12:58:47 -0400</pubDate><guid>https://homelab.tod.net/posts/off-windows/preparing-the-windows-fleet-for-samba/</guid><description>&lt;p&gt;&lt;strong&gt;Off Windows&lt;/strong&gt; tracks removing every remaining Windows dependency from the lab, starting with the two domain controllers that gave the series its name. &lt;a href="https://homelab.tod.net/posts/off-windows/migrating-active-directory-to-samba/"&gt;The next post in the series&lt;/a&gt; covers the actual migration — an in-place replica join that swaps both Windows DCs for a Samba box named &lt;code&gt;sidious&lt;/code&gt; without a single workstation noticing. This post covers the evening before that: getting the rest of the Windows fleet — the desktops, laptops, and &lt;code&gt;piett&lt;/code&gt;, &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/"&gt;the Windows Server box running Veeam Backup &amp;amp; Replication&lt;/a&gt; and one of the two Windows-licensing reasons this whole series exists — under Ansible management and onto a trust chain that would survive the domain changing underneath them.&lt;/p&gt;</description></item><item><title>The Mastodon Migration</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/the-mastodon-migration/</link><pubDate>Sat, 04 Jul 2026 13:30:14 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/the-mastodon-migration/</guid><description>&lt;p&gt;The &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/the-pki-detour/"&gt;previous post&lt;/a&gt; ended with two weeks of wrong turns and an honest need for something to just work. The same day FreeIPA got shelved — June 19 — I got it: Mastodon came off a dedicated Ubuntu VM running a source-checked-out install and onto official Docker images running in a Proxmox LXC, and every part of it went the way infrastructure work is supposed to.&lt;/p&gt;
&lt;h2 id="what-was-there-before"&gt;What was there before&lt;/h2&gt;
&lt;p&gt;Mastodon had been running on a dedicated Ubuntu 24.04 VM (&lt;code&gt;mastodon.tod.net&lt;/code&gt;) since long before this rebuild started — a source-checked-out Ruby/Node install managed by rbenv and nvm, the deployment model the Mastodon project&amp;rsquo;s own install guide walks you through. &lt;code&gt;mastodon.tod.net&lt;/code&gt; reaches the public internet the same way every other externally reachable service here does: a &lt;a href="https://github.com/cloudflare/cloudflared"&gt;cloudflared&lt;/a&gt; tunnel, so nothing about the host itself — old VM or new LXC — needs an inbound firewall rule. It worked, but every version bump meant babysitting Ruby and Node versions by hand, and the data volume was 71 of 95 GB used, with roughly 64 GB of that being nothing but a remote-media cache — other servers&amp;rsquo; avatars and post images, fetched and stored locally the first time anyone here saw them, then never cleaned up automatically enough to keep pace.&lt;/p&gt;</description></item><item><title>The PKI Detour: A Week on the Wrong Cert Strategy, Three FreeIPA Failures</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/the-pki-detour/</link><pubDate>Mon, 29 Jun 2026 12:00:00 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/the-pki-detour/</guid><description>&lt;p&gt;&lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/infrastructure-to-build-infrastructure/"&gt;GitLab was up&lt;/a&gt;. The code had a home. The obvious next question was: how does every other internal service get a TLS certificate?&lt;/p&gt;
&lt;p&gt;The answer I wanted: something clean, automated, and not requiring full Cloudflare DNS credentials on every host. The answer I got — eventually — was &amp;ldquo;Cloudflare DNS-01, one token per service, and accept the limitations.&amp;rdquo; Getting there took a week on the wrong approach, then six days and three attempts on a more ambitious one. This post is both of those failures, what they cost, and what survived them.&lt;/p&gt;</description></item><item><title>Infrastructure to Build Infrastructure</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/infrastructure-to-build-infrastructure/</link><pubDate>Sun, 28 Jun 2026 12:00:00 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/infrastructure-to-build-infrastructure/</guid><description>&lt;p&gt;In the &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/why-i-left-xcp-ng-for-proxmox/"&gt;previous post&lt;/a&gt; I explained why
the new cluster runs Proxmox instead of XCP-ng. This one is the migration itself —
specifically, how it started: the Terraform and Ansible that stood up the first
guest, what running them actually looked like, and the moment the code finally had
a home somewhere other than my laptop.&lt;/p&gt;
&lt;h2 id="rebuild-dont-convert"&gt;Rebuild, don&amp;rsquo;t convert&lt;/h2&gt;
&lt;p&gt;The obvious-sounding plan is to export each VM from XCP-ng and import it into
Proxmox. I didn&amp;rsquo;t do that. The two platforms use different disk formats and guest
tooling, and — as the last post covered — Proxmox&amp;rsquo;s LXC model means many of these
guests stop being full VMs at all. A cross-hypervisor disk conversion would have
dragged years of per-VM cruft along with it.&lt;/p&gt;</description></item><item><title>Why I Left XCP-ng for Proxmox</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/why-i-left-xcp-ng-for-proxmox/</link><pubDate>Sun, 28 Jun 2026 09:00:00 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/why-i-left-xcp-ng-for-proxmox/</guid><description>&lt;p&gt;The &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/"&gt;first post&lt;/a&gt; in
this series covered why I&amp;rsquo;m retiring two 1U servers, and the
&lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/did-the-rebuild-actually-save-power/"&gt;second&lt;/a&gt; measured the power
saving. This one backs up to a decision that came before any of the migration
work — and didn&amp;rsquo;t go the way I planned.&lt;/p&gt;
&lt;figure class="theme-figure"&gt;
 &lt;img class="theme-img-light" src="https://homelab.tod.net/posts/downsizing-the-homelab/why-i-left-xcp-ng-for-proxmox/minis.jpg" width="1600" height="1205" alt="Two Minisforum mini PCs side by side, front panels labelled PROXMOX-MINI01.tod.net and PROXMOX-MINI02.tod.net, blue power lights lit." loading="lazy"&gt;
 &lt;img class="theme-img-dark" src="https://homelab.tod.net/posts/downsizing-the-homelab/why-i-left-xcp-ng-for-proxmox/minis-dark.jpg" width="1600" height="1205" alt="Two Minisforum mini PCs side by side, front panels labelled PROXMOX-MINI01.tod.net and PROXMOX-MINI02.tod.net, blue power lights lit." loading="lazy"&gt;
 &lt;figcaption&gt;&lt;code&gt;proxmox-mini01&lt;/code&gt; and &lt;code&gt;proxmox-mini02&lt;/code&gt; — the two Minisforum UM350s the rebuild runs on now, and the boxes that wouldn&amp;rsquo;t take XCP-ng with Secure Boot enabled.&lt;/figcaption&gt;
&lt;/figure&gt;

&lt;h2 id="i-had-already-chosen-xcp-ng-on-purpose"&gt;I had already chosen XCP-ng, on purpose&lt;/h2&gt;
&lt;p&gt;When I built the old pool years ago, I ran it on &lt;a href="https://xcp-ng.org/"&gt;XCP-ng&lt;/a&gt;,
and I chose it largely on the strength of &lt;a href="https://lawrencesystems.com/"&gt;Lawrence
Systems&lt;/a&gt; — Tom Lawrence&amp;rsquo;s channel, which I&amp;rsquo;ve
&lt;a href="https://www.youtube.com/@LAWRENCESYSTEMS"&gt;followed for years&lt;/a&gt;. XCP-ng ran that
pool faithfully the whole time. So when I started the rebuild my default was
obvious: put the current XCP-ng release on the new mini PCs and carry on. I wanted
to do this rebuild &lt;em&gt;right&lt;/em&gt; and not cut corners.&lt;/p&gt;</description></item><item><title>Did the Rebuild Actually Save Power?</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/did-the-rebuild-actually-save-power/</link><pubDate>Sat, 27 Jun 2026 12:00:00 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/did-the-rebuild-actually-save-power/</guid><description>&lt;p&gt;In the &lt;a href="https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/"&gt;first post&lt;/a&gt; I
listed power as one of four reasons for retiring two 1U Supermicro servers in
favour of two small Proxmox mini PCs. It was honestly one of the main ones. The
old pair ran around the clock to do work that fits comfortably on a single modern
node, and Maine has some of the highest residential electricity prices in the
country.&lt;/p&gt;
&lt;p&gt;So: did it work? Did the rebuild actually save power?&lt;/p&gt;</description></item><item><title>Why I'm Replacing a Homelab That Still Works</title><link>https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/</link><pubDate>Sat, 27 Jun 2026 09:00:00 -0400</pubDate><guid>https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/</guid><description>&lt;p&gt;For several years my homelab has run on two 1U Supermicro servers — &lt;code&gt;chimaera&lt;/code&gt;
and &lt;code&gt;basilisk&lt;/code&gt; — paired together as an XCP-ng pool. Each has two Xeons, 128 GB of
ECC RAM, dual 10-gigabit networking, and local disk. Between them they offer 24
cores, 48 threads, and 256 GB of RAM. They work. Nothing is failing. That is the
part that makes a setup hard to walk away from.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://homelab.tod.net/posts/downsizing-the-homelab/why-im-replacing-a-homelab-that-still-works/server-stack.jpg"
			alt="A stack of home server hardware: two 1U rackmount servers on top, two small mini PCs side by side in the middle, and a larger NAS chassis at the bottom."&gt;&lt;figcaption&gt;
			&lt;p&gt;Top to bottom: &lt;code&gt;chimaera&lt;/code&gt; and &lt;code&gt;basilisk&lt;/code&gt; (the 1U servers being retired), then &lt;code&gt;proxmox-mini01&lt;/code&gt; (left) and &lt;code&gt;proxmox-mini02&lt;/code&gt; (right), with the NAS underneath. The two small boxes in the middle are set to replace the two big ones above them.&lt;/p&gt;</description></item></channel></rss>