2 min read

Chapter 3: downscaling to 10 Gbits

Mostly due to budget constraints (and really there was no need), I decided on a 10 Gbits build instead. This simplifies (cost wise) the wiring, my switch selection and really let’s be honest: 25 Gbits is overkill right now (although that was emotionally hard to accept).

Here’s my updated shopping list + what I actually paid for parts

Category Component Specifications CHF Notes
Case IPC 4U-40248 117.-
Processor AMD Ryzen 7 7700 8C/16T, 65W TDP 181.95
Motherboard ASRock
B650D4U3-2L2Q/BCM
cheaper, 2x10Gbits RJ45 467.55
Cooling Noctua NH-U9S - 65.-
Memory 64GB DDR5-4800 ECC
UDIMM
Bought second hand due to price surge 300.-
Power Supply Seasonic Focus
GX-750
750W, 2x PCIe
8-pin needed
67.60 Gold
or Platinum
Storage
Controller
LSI 9305-16i 10W 120.- ⚠️ Hard to find
in CH
Boot Drive 2x 1TB WD Black SN700 Only needed 1, have a second one already 78.-
GPU Zotac NVIDIA RTX 4060 Solo 8 GB Second hand 200.-
Total 1597.10 excl. disks + RAM I already had

I got everything right before I left for a 2 months trip, so I was in a bit of a hurry assembling everything (except for the storage controller) before departure (I literally had 2 hours before to assemble + install it all). I managed to get it 95% complete, and then a neighbour helped me get across the finish line after we left so I could remotely access it. I migrated one container after the next to the new machine, which went fine except for some selinux labels which needed adjusting: Basically stop container on old server, sync persistent storage to new server, deploy to new server, test. As I run my docker containers in an ipvlan network, IPs of the containers stayed the same and could still reach each other even though on different machines. Here is the script I used for migrating: https://gist.github.com/JorisM/3c1ed3af57f7b6a07e454e29b0d111e1
As you can see I hard-coded quite a few paths for simplicity’s sake, as I probably won’t re-use it.
I then went ahead and installed vyos as previously described, and I use the publish script to have a local config which I push to the server. I’m still extending this to be a bit more polished, and will post here in the future.

Next up is: Actually replacing my old router with the new vyos build. The plan is to have a short downtime, switching to the media converter + plugging the RJ45 into the LAN port of the ASRock which I have assigned internally as the “WAN” port (nic1). NIC0 will then serve as the “LAN out”. For now I will start with NAT, firewall rules and a DHCP server, and leave everything else on the old box until that much is proven.

Update: this didn’t happen. I got vyos configured and tested, but never flipped it over to be the actual router — it was simply too much at once. New hardware, new storage layout, new router OS, and a two month trip in the middle of it.

I still like vyos for its declarative nature and will revisit it at some point. For now the UCG Fiber does its trick nicely.