Rack, power & network 12 items
Shared infrastructure — the frame, everything that feeds it and everything that connects it. Per-machine parts live under their own server below.
The switches are bought here and designed in the network section, which is deliberate: this is the buy list, that is the reasoning. Their port maps, speeds and rules live under Network design.
| Item | Qty | Price |
|---|---|---|
| VEVOR 20U Open Frame Server Rack23″–40″ adjustable depth, 4-post, casters · B0C64YY7G7 Set post-to-post depth to 24″ before mounting anything. | 1 | 125.99 |
| Vented rack shelves ×3 2 likely included Test earlyDepth to suit a 14.5″ tower · holds the APC, and stays for good — that unit keeps the network gear after the CyberPower arrives, so this is not a temporary fixture. The VEVOR's own package contents list two of these. They appear as “2 pallets”, which is the same listing's translation of trays — and a sibling VEVOR SKU sells the identical frame described as including 2× vented 1U rack shelves. The contents list also matches the ten cage nuts this sheet already counts on, which is a good sign it is the right list. The build now needs three, not two. One under the APC, and two across the network bay — the switches, the eero and the edge box add up to more width than a single 19″ tray gives. So the two in the box cover most of it and one more is a real purchase. Confirm two things before relying on it. Depth: a shallow 1U tray will not safely carry a 14.5″ tower hanging off the front posts. Rating: the APC is ~26 lb, which is more than a light AV tray expects. Included shelves are built to a price. Kept as a buy line rather than deleted, because it becomes a real purchase the moment either check fails. | 2 | — |
| CyberPower CP1500PFCRM2U Planned1500 VA / 1000 W pure sine, AVR, 8 outlets, 2U rackmount, 10.5″ deep · B0B354X985 Pure sine is the right call for the PSU's active PFC. The target unit, not a day-one buy — the APC below carries the load meanwhile, so this price sits outside the build total. Takes the media and cloud servers — about 475 W, under half its rating, roughly ten minutes. The game server goes on the BR1000MS instead. A 2000 VA version is $449.95 if the NAS is a certainty — see UPS headroom. | 1 | 359.95 |
| Second CyberPower CP1500PFCRM2U Later1500 VA / 1000 W pure sine, 2U · $359.95 · conditional, outside every total Buy it to replace the BR1000MS, not to sit beside it. Two matched 2U units want 4U against the current 2U-plus-a-tower-on-a-shelf, so it gives a rack unit back. One battery SKU, one NUT config, and either unit can take any server. Not worth it yet — media server runtime is already ~10 min, which is a shutdown window rather than a reserve. Two triggers change that: the NAS landing (pushes the first unit to ~60% and runtime back to 6–7 min), or the BR1000MS battery failing, when you are spending money regardless. It buys blast radius, not redundancy. Every server here is single-PSU, so a second unit splits load and cannot fail over — real A+B needs dual-PSU servers or a transfer switch per box, which costs more than the UPS. | 1 | — |
| APC Back-UPS Pro BR1000MS Have1000 VA / 600 W pure sine, AVR, tower 14.5″×3.9″×10.2″ · B0779KYKLB · owned, $191.43 Carries the media server and the office eero today. Once the CyberPower lands this takes the game server plus the office eero and three switches — about 190 W, a third of its rating, roughly 20 minutes. Not interim; it has a permanent job. One of only two pure-sine units in the house, so it and the CyberPower are the only ones that may ever carry a server. See the power topology. Tower, not rackmount: it needs a shelf, and lying on its side it eats about 3U against the CyberPower's 2U. | 1 | — |
| TP-Link TL-SG108S-M2 AddMain LAN — 8× 2.5 Gb, unmanaged, fanless metal · B0CMFX748Y Replaces the main switch. Serves the whole rack rather than one machine: internet and management only, never storage. Committed at seven of eight ports on day one. Uplink, four servers, the N2+ and the edge box. The main switch held sixteen and still had reserves — this has one spare, so plan on a second switch rather than a spare port when the next machine lands. The gain is the trunk, not the machines. Every main-LAN NIC here is gigabit, so nothing gets individually faster; what changes is that several machines can pull from a 2.5 Gb service at once without queueing behind a single gigabit uplink. Fanless matters here — it lives on an open shelf in an office, and the sheet already refuses noisy parts on that argument. | 1 | 59.99 |
| TP-Link TL-SG105S-M2 AddEdge switch — 5× 2.5 Gb, fanless metal, smaller than a paperback · B0CMXXPTVH Sits between the office eero and the rack. Replaces the GS108. One port uplinks to the eero, one to the gaming tower, one down to the main LAN switch. This is where 2.5 Gb matters most. It carries the whole WAN path, so it is the switch that decides whether anything in the house can reach past a gigabit of the 2.5 Gb service. Three of five ports used, against the GS108's three of eight. Not a problem, but the office loses its casual spare ports. Same family as the main switch, which is worth more than it sounds. One vendor, one firmware story, and the two behave identically — and a 5-port TL-SG105S-M2 is cheap enough to keep as the cold spare the network design already asks for. | 1 | 34.99 |
| BrosTrend 2.5 Gb, 5-port Have ×2Carries the isolated storage island — see the network design · owned, $37.99 each Unchanged by the 2.5 Gb switch refresh. It was already 2.5 Gb and already right for this job, so it stays put while the two Netgears are replaced around it. Two of these are owned, and the second is the spare the network design keeps asking for. The island switch has no redundancy and the kitchen unit sits in the WAN path — an identical box in a drawer covers either failure with no shopping and no compromise, which is better than the gigabit fallback the retired Netgears would have offered. Never uplinked to the main LAN switch. Needs a printed tray; desktop form factor. | 2 | — |
| Monoprice SlimRun Cat6A, 10-pack Add5 ft, snagless RJ45, 550 MHz, 10G rated, UTP, pure bare copper, 30 AWG, ten colours · B07958D19L Patching for the whole rack. Pure bare copper rather than copper-clad aluminium is the thing worth paying for — CCA is what fails intermittently under PoE and tight bends. 30 AWG SlimRun is roughly half the diameter of standard 24 AWG patch cable: less bulk behind the posts and better airflow, at the cost of being easier to damage. Fine at 5 ft, wrong choice for long runs. Ten colours suits the cable discipline in the build order — power down one side, data down the other, and a colour per role. | 1 | 26.33 |
| ODROID N2+ 4 GB HaveAmlogic S922X, 4× A73 + 2× A53, 4 GB RAM, gigabit Ethernet, 4× USB 3.0 · ~4 W · U16 · owned, $95 Three jobs: NUT master for both UPS units, sensor gateway for the Govee kit, and Home Assistant / Homebridge. Runs an AmeriBrit Panel agent like every other machine. Serves the whole rack rather than one machine, which is why it lives here beside the switches rather than under a server. It is not a fourth server and should never be given a server's job. It is the only machine in the build that is out-of-band relative to the servers while still being inside the house — that is the entire value, and loading it up destroys it. Two USB ports for the UPS data cables plus one for the Bluetooth dongle. Four available, so one stays free on both storage stages. | 1 | — |
| 128 GB A2 microSD — N2+ boot HaveDay-one boot media · B09B1JFY24 · owned, $60.05 That price changes the upgrade argument entirely. The 64 GB eMMC below is $47 — cheaper than the card already in the slot. The eMMC stopped being a $47 luxury on top of a cheap card and became the better part for less money, which moves it from “planned” toward “buy it with the next order”. The weakest component in the build, and worth saying plainly A2 is a performance class, not an endurance one. It specifies minimum random IOPS and sustained sequential write so apps launch faster. It carries no TBW figure and says nothing about lifespan. Endurance is a separate product line entirely — SanDisk Max Endurance, Samsung PRO Endurance — sold for dashcams and surveillance because those write continuously. So will this box. Worth knowing for the record: on Linux SBCs, A2 often doesn't even deliver its performance claim. The speedup depends on command queuing and host-side caching that most SD host drivers don't implement, so A2 cards frequently benchmark at or below A1 on boards like this. You are paying for a spec the platform can't use. The irony belongs on the sheet: the machine whose entire job is to report failure has the least reliable storage in the rack. Every server here boots from SSD or NVMe. The NUT master boots from a card with a crude FTL, minimal wear levelling and no meaningful SMART. Mitigations are load-bearing on this stage, not optional. Home Assistant recorder purge_keep_days at 7, /var/log on tmpfs or log2ram, swap off, no local metrics database, and a dd image of a known-good card kept off the box.Power-loss corruption is the other common killer and is already handled: the N2+ is on the BR1000MS and shuts down under its own NUT master. | 1 | — |
| Hardkernel 64 GB eMMC Module N2 Linux Add$47.00 · going with the next order — it costs less than the microSD already in the slot N2-series module, not N2L. Linux variant, not Android. Both are easy to order wrong. Capacity is the smaller half of the argument — wear headroom scales with capacity, so 64 GB carries roughly twice the spare blocks of the 32 GB for this workload. No reader or writer needed. Fit the module with the microSD still in — the S922X keeps microSD UHS mode active alongside eMMC, which the older S905 could not — boot from the card, dd the image across, set boot order. The card then stays in the slot as a bootable recovery image of a known-good system, which is a better end state than buying a reader would have produced.The wait-for-a-trigger plan is retired. It made sense when this was $47 on top of a card that was assumed cheap — buy on evidence, not on principle. At $47 against the card's $60.05 there is nothing left to wait for, and the triggers it was waiting on (a read-only remount, an unexplained reboot) are all failures of the part being replaced. Buying ahead of them is the point. The eMMC buys margin, not immunity. Keep the mitigations after it lands — HA's recorder is the heaviest writer here either way. Hardkernel's own listing price; verify at checkout and factor Korean shipping, which usually costs more than the module. | 1 | 47.00 |
| Day-one spend · planned units excluded, owned kit at $0 | $247.30 | |
Media server 20 items · 6 owned
A transplant, not a new build. The first six rows are already on hand and set the constraints everything below works around; the rest mounts, cools, powers or connects them.
| Item | Qty | Price |
|---|---|---|
| AMD Ryzen 5 3600 Have6-core, 65 W TDP, no integrated graphics 65 W settles the cooling question. No iGPU means the GPU is also display output. | 1 | — |
| ASUS Prime B450M-A II HavemATX, AM4, 6× SATA, 1× M.2, one PCIe 3.0 x16 + x1 slots The binding constraint. Only one x16 slot, and the M.2 socket disables SATA 5/6 when populated. | 1 | — |
| 16 GB DDR4 HaveBoard takes up to 128 GB across four slots Fine for Jellyfin plus containers. Thin if you add VMs — cheap upgrade later. | 1 | — |
| ZOTAC RTX 3050 Twin Edge OC 8 GB Have~130 W, dual-slot, axial fans NVENC handles Jellyfin transcodes. Axial cooler recirculates heat, so front intake matters. | 1 | — |
| SK Hynix NVMe M.2 2280, 256 GB HaveBoot drive — OS and containers · capacity confirmed Sits in the board's M.2 socket, so it costs no SATA port and no bay. It does disable SATA 5/6, which is the trade the storage math below is built on. Trickplay deliberately lives on its own SATA SSD, not here — so this drive only carries the OS and containers. At 256 GB that is comfortable: roughly 40–50 GB for Debian plus Jellyfin, Immich and their images, leaving ample headroom. | 1 | — |
Hard drives — 5 on hand HaveJellyfin_M2 8 TB · Jellyfin_M5 8 TB · Jellyfin_M1 1 TB · Jellyfin_M3 1 TB · Jellyfin_M4 1 TB19 TB raw across five drives. They fit with room to spare: six of the seven bays used once the trickplay SSD takes one, and six of the eight SATA ports. The two 8 TB drives carry the library. The three 1 TB drives are earmarked for replacement with 8, 10 or 14 TB — see the upgrade path in the math. | 5 | — |
| GPERHUAN 4U Server Chassis7× 3.5″ bays, ATX/mATX/ITX, front panel lock · B0D4764WSF One 120 mm front position, two 80 mm rear. | 1 | 89.99 |
| MSI MAG A750GL PCIE5750 W, 80+ Gold, fully modular, ATX 3.1 · B0CC3QBGDL Good price. Modular matters in a 4U — every uninstalled cable is airflow. | 1 | 89.99 |
| Thermalright Peerless Assassin 120 Mini135 mm tall, dual tower, 6 heat pipes, AM4 · B0CQQYJC5M ~15 mm clearance in a 4U. Mount blowing front-to-back. | 1 | 33.90 |
| ARCTIC P12 Pro120 mm PWM, 600–3000 RPM, static-pressure optimised · B0DJDC74BP Front intake. Put this in hub slot 1 so its RPM is the one reported. | 1 | 6.39 |
| ARCTIC P8 Max80 mm PWM, 500–5000 RPM, 0 dB mode · B09VDNGW8K Rear exhaust. Cap the curve — 5000 RPM on 80 mm is unpleasant. | 2 | 17.98 |
| ARCTIC Case Fan Hub Add10× 4-pin PWM out, SATA power, magnetic · B0887VG14J Dumb splitter, so Debian keeps control via the motherboard header. | 1 | 12.00 |
| ARCTIC MX-7 thermal paste4 g with MX-Cleaner | 1 | 9.59 |
| SinLoon PCIe x1 90° riser, 10 cm Test earlyRoutes x1 cards around the dual-slot GPUCheap risers cause intermittent link failures. Verify both cards before closing the lid. | 2 | 29.98 |
| ELECNEXUS 4-Port SATA CardPCIe 3.0 x1 to 4× 6 Gbps SATA Runs at PCIe 2.0 x1 (~500 MB/s shared) in your board. HDDs on this card, SSD on a board port. | 1 | 21.99 |
| Dual-port 2.5 Gb NIC ChosenIntel I226-V, two ports, low-profile bracket · B0G2MVP69M · fits x1/x4/x8/x16 Same I226-V as the single card it replaces, so the driver story is unchanged — Intel over Realtek, as the sheet has always specified. One card now does both jobs: port 1 to the main LAN at 2.5 Gb, port 2 to the storage island at 10.10.10.10 with no gateway. The motherboard's gigabit port is deliberately unused.This is what keeps the media server buildable. Two single NICs plus the SATA card would be three add-in cards on a board where fitting two was already the open question. The dual card collapses that to two, and it is the reason the slot count stops being a risk. Put it in the x4-capable slot if the GPU leaves one reachable. On a B450 the x1 slots are PCIe 2.0 — about 4 Gb/s — against 5 Gb/s if both ports ran flat out at once. That is not a real workload here (a 2.5 Gb download and a full-rate island transfer rarely coincide), but the x4 slot removes the question entirely. | 1 | 46.99 |
| Thermalright M.2 2280 heatsink Good pickFor the SK Hynix boot drive — confirmed 2280, so the heatsink fits Worth having: the M.2 socket sits under the GPU's downdraft in a 4U, and NVMe throttles hot. | 1 | 5.79 |
| ADCAUDX SATA III cables, 6-packSlim, 1 m, locking latch | 1 | 12.68 |
| TEAMGROUP AX2 256 GB SATA SSD Price2.5″, SATA III, 3D NAND TLC, 520 MB/s read · B08CJX8M4D Trickplay images only — deliberately off the boot drive, so the OS can be rebuilt without regenerating thumbnails. Goes on a board SATA port; the HDDs get the expansion card. Sized well past need — trickplay for a large library lands near 20 GB — but 256 GB is the smallest AX2 and the headroom costs $77 less than the 1 TB it replaces. Still roughly double market for the capacity: a Crucial BX500 or Kingston A400 at this size runs $20–30. Trickplay is small random reads, so any SATA SSD performs the same here. | 1 | 52.99 |
| 2.5″ to 3.5″ drive adapter AddSeven 3.5″ bays and no stated 2.5″ mount The game server needs its own — counted separately in that section. | 1 | 8.00 |
| Media server, parts to buy | $410.26 | |
Mounting hardware 2 items · both missing
Nothing on the wishlist carries the weight of anything. This is the single biggest gap in the build.
| Item | Qty | Price |
|---|---|---|
| Tecmojo 1U Universal Rack Rails, 2-pack Add20.9″–32″ adjustable, 14-gauge steel, 110 lb · B0DXTVRY6G One set each for the 4U, both 2U boxes, and the UPS. Front ears alone will bend on a 40 lb chassis. | 2 | 110.00 |
| M6 cage nuts + screws, 50-pack AddThe rack includes ten. Four rail sets plus chassis ears exhausts that immediately. | 1 | 12.00 |
| Still needed · every Add row in the day-one build, game server excluded | $168.33 | |
Monitoring 5 items · 1 recurring
Three sensors and the box that reads them. Bluetooth thermometer in the rack, USB adapter so the N2+ can reach it, smart plug for real draw numbers — and an off-site VPS running the management panel that collects all of it. These feed the panel through the N2+'s agent; the panel owns alerting, and nothing in this rack routes notifications anywhere else.
| Item | Qty | Price |
|---|---|---|
| Govee H5075 thermometer / hygrometerBluetooth, alerts, data export — rack ambient temperature, read by the N2+ Also the measurement that settles the N2+ fan question, since it now reports its own SoC temperature alongside this. | 1 | 12.99 |
| ASUS USB-BT500Bluetooth 5.0 — lets the N2+ read the H5075 over BlueZ. Takes the third of its four USB ports. Moved off the media server deliberately. A rack thermometer read by a machine inside the rack's own failure domain reports nothing at the moment it matters. | 1 | 19.74 |
| Govee Smart Plug, energy monitoring15 A — measures actual rack draw so you can size the UPS on data, not estimates | 1 | 15.29 |
| OVH VPS — management panel Monthly2 vCore, 4 GB RAM, 40 GB NVMe · $5/month, $60/year Runs AmeriBrit Panel — updates, resource and storage monitoring, UPS state, alerts to iOS and webhooks. Every machine in the rack runs an agent that reports to it, the N2+ included. The only recurring cost on this sheet, and the only line that is not hardware. It sits outside the build total, which is one-time money. Off-site is the whole point. A monitor living in the rack cannot tell you the rack is down — it goes down with it. The one machine whose job is to report failure must not share a power feed, a switch or a room with what it watches. The outbound-agent design is the architecture, not a detail of it. Agents dialling out to a collector on the same switch would not be a weakened version of this — it would be a LAN service with extra hops. No open ports, CGNAT tolerance and no DDNS are all properties of the collector being on the far side of the WAN. They evaporate together the moment it moves in-house. The N2+'s agent is the authoritative source for UPS state, not the media server's. During an outage the servers are the things shutting down, so their agents go quiet exactly when detail is wanted. The N2+ outlives them by a wide margin, so the timeline reads on battery → servers shutting down → clean → last word from the N2+ rather than three agents stop, silence. Config in git. A $5 VPS without snapshots makes the monitoring system its own single point of failure. Config in a repo, restore in twenty minutes. 2 vCore / 4 GB is generous for a panel — real room for an external probe node later, genuinely off-net, which is what that job requires. | 1 | 5 /mo |
| External check on the panel itself AddHealthchecks.io or UptimeRobot · one URL · $0 Nothing currently watches the watcher. If the OVH box dies, or the outbound path breaks, or a firewall rule gets fat-fingered, the result is silence — and silence is indistinguishable from everything being fine. That is the exact failure this whole design exists to eliminate, reintroduced one layer up. Two fixes, and both are needed. The panel must alert on absence, not only on events — an agent that stops checking in is an incident, and if a missing heartbeat doesn't page then the panel only catches failures polite enough to report themselves. And one external check pointed at the panel, because it is the only component you neither own nor maintain, which is the entire point of it. | 1 | 0.00 |
Game server separate budget
Second box, built on an AM3+ Gigabyte platform that is already on hand and running today — it goes in on the first pass alongside the media server. Its spend is tracked on its own line rather than in the totals at the top, since the platform costs nothing and only the case, PSU and drives are still to buy. The chassis takes a standard ATX PSU, so this runs the same PSU model as the media server rather than a second form factor to stock.
An HP EliteDesk Mini was evaluated as a 1U replacement for this box and passed over. It is not gone — it moved to the misc server below, with no job assigned.
| Item | Qty | Price |
|---|---|---|
| Rosewill RSV-Z2600U Chosen Stock4× 3.5″ bays + 1× 5.25″, mATX, 4 PCI slots, 2× USB 3.0, front panel lock · B096WG8H6X 15.0″ deep, aluminium, rear-mount PSU. Ships with 3× 80 mm PWM fans and rack mounting hardware, so the game server needs no fan spend at all. Decided — and that makes the stock problem real. This is also the cloud-server chassis, and there was one left. Buy the second now or the cloud server needs a different case. | 1 | 99.99 |
| Gigabyte GA-78LMT-USB3 R2 HaveAM3+, AMD 760G, mATX 9.6″×7.6″, 4× DDR3 slots, 1× PCIe x16 + 1× x1 + 2× PCI Form factor confirmed — clears both 2U cases with room to spare. Sockets AM3+, so the CPU is an FX or Phenom II. | 1 | — |
| AMD FX-6300 HaveSix-core Piledriver, 3.5 GHz base / 4.1 GHz turbo, 95 W TDP, AM3+ Cores are plentiful; single-thread throughput is not, and most game servers are bound by exactly that. Fine for a handful of players, thin for a busy Minecraft world. Meter it before committing a permanent U — Piledriver idles far higher than the Ryzen. No integrated graphics on the chip, but the board's 760G provides onboard video, so no GPU is needed and chassis card clearance doesn't apply. | 1 | — |
| 20 GB DDR3-1333 HaveUnbuffered, non-ECC · A0 4 GB · A1 4 GB · A2 4 GB · A3 8 GB All four slots are full. More memory means replacing sticks, not adding them. The board's DMI table claims a 16 GB ceiling and a 4 GB module limit, but it is running 20 GB with an 8 GB stick — the table is just conservative. | 4 | — |
| ARCTIC S8038-10K Only if needed80×80×38 mm, 500–10000 RPM, 102 CFM, 51 mmH₂O static, dual ball bearing · B09VGW7L6Y · $10.99 Do not buy these preemptively. The Rosewill ships with three 80 mm PWM fans, and this box is a 95 W CPU with two SSDs and no GPU — the stock fans have an easy job. They become the right answer in one specific case: if the low-profile cooler cannot hold the FX-6300 in 2U. Forcing air across a starved cooler is what high static pressure is for, and it is how server chassis solve exactly this problem. Buy on a temperature reading, not on spec sheets. Measure before ordering. 38 mm is 13 mm thicker than standard, spent along the airflow axis rather than the height — an 80 mm fan clears 2U either way, but the Rosewill's fan bracket is built around 25 mm and may not have the depth. Cap the PWM curve. 10000 RPM is a datacenter setting and assumes nobody is sitting near it. | 3 | 10.99 |
| Low-profile CPU cooler Tight fitMust dissipate 95 W inside roughly 70 mm · UTLGAMENG publishes 65 mm; Rosewill publishes nothing The narrowest constraint in this build. The stock FX-6300 cooler is around 65 mm, so it may just clear — measure it before assuming. The media server's Peerless Assassin is 135 mm and is not an option. If the stock cooler doesn't fit, note that 95 W AM3+ in a sub-70 mm envelope is a thin market — check AM3+ mounting explicitly, since most current low-profile coolers ship AM4 brackets only. | 1 | — |
| MSI MAG A750GL PCIE5 Second unit750 W, 80+ Gold, fully modular, ATX 3.1 · B0CC3QBGDL Same model as the media server, not the same physical unit — one PSU can't feed two chassis. Now that the parts are known this box draws roughly 160 W loaded (95 W CPU, board, four DIMMs, one SSD), so 750 W runs it at about 21% — below the efficiency sweet spot and around $30 more than a 450 W would cost. The argument for it is one spare model that drops into either server. | 1 | 89.99 |
| TEAMGROUP AX2 256 GB SATA SSD2.5″, SATA III, 3D NAND TLC · B08CJX8M4D Boot drive — OS only. Same split as the media server: the box can be rebuilt without touching game data. Same model as the media server's trickplay drive, so one spare covers both machines. | 1 | 52.99 |
| TEAMGROUP AX2 1 TB SATA SSD Price2.5″, SATA III, 3D NAND TLC · B08CKFDPJ3 Server files — worlds, JARs, mods, backups. Kept off the boot drive so an OS rebuild never risks game data. Generous for the job: several instances plus backups rarely pass 100 GB. Fine if you would rather not think about capacity again. This objection is a property of the FX-6300's chipset, not of the drive. The same SSD reaches its full rating on any modern AHCI controller — the misc server, for instance. It does not travel between machines. Confirmed SB7x0 at SATA II — about 275 MB/s, against this drive's 540 MB/s rating. Half of what you would pay for is unreachable on this board, whatever the price. The price half of this flag is now stale and possibly reversed. $129.99 was flagged as roughly double a $50–70 market — that market is gone, and Crucial has left the consumer business entirely. Re-check against current comparable drives before substituting. Buy on warranty and endurance, not on the speed number. The controller is also in IDE mode, not AHCI. That costs NCQ and reliable TRIM, which matters far more to an SSD than the SATA generation does. Switch it in BIOS before this drive goes in. | 1 | 129.99 |
| 2.5″ to 3.5″ drive adapter AddOne per SSD — the Rosewill has no 2.5″ mount Two drives now, so two adapters, and they take 2 of the Rosewill's 4 bays. No bulk storage lives here, so the remaining two are spare. The UTLGAMENG alternate has one 2.5″ mount built in, which would drop this to a single adapter. The media server buys its own separately. | 2 | 16.00 |
| Priced so far, Rosewill chassis · one case only, not both · cooler still open | $388.96 | |
Misc server role undecided
A real machine, on hand, with no job. The HP EliteDesk 705 G4 DM was evaluated as a replacement for the game server and passed over — the FX-6300 build stays as specced. What is left is a capable little box with nothing assigned to it, so it sits here rather than being written out of the sheet. Nothing is bought for it until it has a purpose, but the platform work is already done and is kept below so the decision is cheap when it comes.
What it is
Serial MXL9505DF8 — HP's convention puts characters 4–6 as year and week, so week 50 of 2019, Mexico assembly.
705 means AMD. Socketed AM4, Raven Ridge APU, Radeon Vega graphics — not the Intel 800-series it was first taken for. HP's QuickSpecs offer only four-core parts in the DM column; the Ryzen 7 PRO 2700X/2700 and Ryzen 5 PRO 2600 are SFF and MT only, so four cores is the ceiling.
| Likely CPU | Cores | Boost | TDP | Likelihood |
|---|---|---|---|---|
| Ryzen 5 PRO 2400GE | 4C/8T | 3.8 GHz | 35 W | Most common |
| Ryzen 5 PRO 2400G | 4C/8T | 3.9 GHz | 65 W | Possible |
| Ryzen 3 PRO 2200GE | 4C/4T | 3.6 GHz | 35 W | Possible |
| Ryzen 3 PRO 2200G | 4C/4T | 3.7 GHz | 65 W | Possible |
The CPU is socketed so a swap is physically possible, but temper that: HP BIOS whitelists are restrictive and the 705 G5 moved to Picasso on a different BIOS. Assume no upgrade path unless someone has confirmed one on this exact board.
| RAM | 2× 8 GB DDR4-2666, dual-channel · confirmed |
| RAM ceiling | 32 GB · 2 slots, both full |
| M.2 slots | 2 listed — one may be 2230 WLAN |
| 2.5″ 7 mm bays | 1 · caddy may be absent |
| 3.5″ bays · PCIe slots | None · none |
| SATA | SATA III 6 Gb/s, AHCI |
| Out-of-band management | None — AMD, so no vPro/AMT |
| Draw · weight | ~10–30 W · ~3 lb |
Dual-channel is the good answer — full ~42 GB/s rather than the ~21 a single module would have given on a Raven Ridge APU. What it costs is the upgrade path: two slots, both occupied, so more memory means replacing both sticks rather than adding one. Same trap the FX-6300 is in with all four DDR3 slots full.
What it is actually suited for
The constraints decide this more than the CPU does. No PCIe, no 3.5″ bays, one 2.5″ bay, 32 GB ceiling, ~10–30 W. That rules out anything storage-shaped and anything wanting a card.
What it leaves is compute in a small envelope — a Docker host, a second Pterodactyl node if the game server ever needs one, a staging box for the panel before changes reach the VPS, or a DNS/Pi-hole and light services box.
Two jobs it should not take. Anything the N2+ already owns — NUT, sensors, Home Assistant — because splitting those across two boxes doubles the config and halves the clarity. And anything holding data that matters, since there is one bay and no redundancy in it.
It is also the obvious eventual replacement for the FX-6300, on roughly +33–40% single-thread and a fraction of the draw. That is a decision for when the FX gives trouble, not now.
Answer these before spending anything on it
One teardown plus one boot settles all of it, and none of it is worth doing until it has a job.
| Exact CPU | lscpu | grep 'Model name' |
| Is slot 2 M.2 2280 or 2230 WLAN? | lspci + visual |
| Is the OEM NVMe still in it? | nvme smart-log /dev/nvme0 |
| 35 W or 65 W thermal build? | Heatsink colour + brick wattage |
| Does it have the 2.5″ caddy? | Visual, during teardown |
The caddy is the one that bites. HP Desktop Minis configured M.2-only frequently shipped without the 2.5″ bracket and its SATA/power cable. It is a separate HP part at roughly $15–25 used, and without it a 2.5″ drive has nowhere to mount. Check it before ordering any drive for this box.
Not to be mistaken for a fault: on some Desktop Mini models HP firmware throws a boot warning when a 2.5″ drive is fitted without the caddy's cooling fan. Dismissable, machine runs fine.
A healthy OEM NVMe may mean no boot drive purchase at all. Worth the thirty seconds before assuming a spend.
Storage — researched, not bought
Drives were specced for this box while it was a game-server candidate. That role is gone, so the spend is not justified yet — but the work stands, and the reasoning is kept here so it is not redone later.
Boot, when needed: Silicon Power P34A60 256 GB · B07ZGK3K4V. M.2 2280 single-sided, PCIe 3.0 x4, SM2263XT controller, Micron 96-layer 3D TLC, ~2,100/1,200 MB/s, 150 TBW, 5-year warranty.
Native Gen3 is the point, not a compromise. It matches the Raven Ridge slot exactly — a Gen4 drive would cost more and downshift anyway. Single-sided and low-power suits a 1 litre chassis with no case airflow, and it is TLC rather than QLC. The 256 GB is the slowest of its family on fewer NAND dies and a smaller SLC cache, which is irrelevant for boot and visible only on large sustained writes.
Buy from Amazon or Silicon Power direct, not a marketplace seller. SP's bill of materials varies by production run — Micron and Intel TLC have both been observed — and counterfeit SP drives exist.
Bulk storage is deliberately unspecced. With no role there is no capacity requirement, and this box has exactly one 2.5″ bay with no redundancy behind it. Size that drive against the job, once there is a job.
One correction worth keeping: the sheet's standing "SB7x0 at SATA II, half of what you pay for is unreachable" objection to the AX2 is a property of the FX-6300's chipset, not of the drive. This box runs a modern AMD Promontory controller at SATA III 6 Gb/s in AHCI with no IDE mode, so a SATA SSD reaches its full rating here. That objection does not travel between the two machines.
Racking it, if it ever earns a U
Not placed in the elevation. A box with no job does not get a rack position reserved for it — that is how spare U quietly disappears. It would take 1U in the printed mount, and the sheet's spare 1U at U15 is the obvious candidate.
The print is Printables 658936, already on the print list as conditional. It was designed around the 800-series bezel and this is a 705 — same 1 litre chassis, and the commercial ModMount family covers 705 G3–G5, so it should fit, but the front port layout differs. Check the facade cutouts against the machine before committing filament.
Placement rules if it lands: not directly above the media server's rear 80 mm exhausts, and leave the U above it clear unless whatever sits there has an open bottom. On the 65 W build the perforated top is a primary intake — stacking on it chokes the machine, and a printed sleeve that covers it is a larger threat to cooling than any workload.
Power would come off the BR1000MS alongside the game server and the N2+. At ~10–30 W it is noise against that unit's ~194 W.
Worth doing whenever it is next open
Independent of role, and cheap while the lid is off:
| Blow out the fin stack | 5–15 °C |
| Repaste with MX-7 | 5–10 °C |
| Pads on VRM + chipset | Indirect |
| Pad any M.2 to the chassis | 10–20 °C on the SSD |
The fin stack is the biggest single win on a used mini — dust packs where you cannot see it — and factory paste is 2019 vintage. MX-7 is already costed on the media server line and covers this too.
Free levers, and they are AMD ones. Fan profile to maximum cooling; HP's defaults assume a desk. Cap cTDP in BIOS if exposed, or use ryzenadj for STAPM/PPT limits on Linux — not intel_rapl or MSR 0x150, which are the wrong platform entirely. Raven Ridge has no undervolt offset interface, so power limits are the only lever.
Raven Ridge Tctl throttles at 95 °C, and sustained 75–85 °C under load is normal. Temperature alone is not a failure — only clock collapse is.
Cloud server other list
The least-decided machine in the build. No board, CPU or drives are specced for it yet, so it carries a chassis and a NIC and nothing else — it holds a 2U bay in the elevation and a port on both switches, and that is the extent of the commitment.
| Item | Qty | Price |
|---|---|---|
| Rosewill RSV-Z2600U Same case as game4× 3.5″ bays + 1× 5.25″, mATX, 3× 80 mm PWM, 15″ deep · B096WG8H6X Cloud server. Four bays beats three, and it's a real brand with review volume. Reserved rather than planned — no board, CPU or drives are specced for this box yet, so the chassis is the only line it has. The game server has claimed this model, and stock was down to one. This box has no other parts decided, so it is the one that can wait — but if you want them matched, the second case is the piece to buy ahead of the rest. | 1 | — |
2.5 Gb low-profile NIC AddCloud server's port on the storage island · 10.10.10.20The only hardware the network design still needs. Roughly $19 — not costed here since no model is chosen. Low-profile bracket required; match the Intel i226 family for the same Linux driver story as the media server's card. | 1 | — |
NAS 8 items
Bulk library storage, and the last box to land. Everything but drive capacity is decided. The rules that govern that choice — CMR only, two parity, parity sized to the largest data drive — are settled below; the number on the label is not. It is dual-homed like the servers — one port to the main switch for management, one to the storage island at 10.10.10.30.
| Item | Qty | Price |
|---|---|---|
| NAS board — mATX, not N100 DecideOMV + mergerfs + SnapRAID stays. The board does not — see the lane budget in the math. The N100 plan was written for eight bays and does not reach twelve. It has nine PCIe lanes in total, and the NAS boards built on it spend every one: the SATA controller, both M.2 slots, and each onboard NIC. They ship no PCIe slot at all, so there is physically nowhere to put an HBA. Take the chassis up on mATX instead. A cheap LGA1700 mATX board gives an x16 slot for the HBA, four onboard SATA, an M.2 for the NVMe boot drive and an x1 slot spare — which is exactly the shape this build needs. That also retires the “both NICs must be onboard” rule. It existed only because a Mini-ITX board has one slot and the HBA took it. With a second slot free, the 2.5 Gb island card has somewhere to live and board selection gets much easier. The cost is power: roughly 10 W idle for an N100 against 35–60 W for an LGA1700, or about $30–40 a year running 24/7. | 1 | — |
| LGA1700 mATX board, H610M or B760M AddNeeds: 4× SATA, one PCIe x16, one M.2 NVMe, one PCIe x1 · roughly $70–100 That is the whole shape of the requirement, and H610M boards hit it almost by default — the x16 takes the HBA, the four SATA make up the twelve, the M.2 boots, and the x1 carries the 2.5 Gb island card. Confirm the M.2 slot does not disable SATA ports. Plenty of boards share bandwidth between the two, and on this build that is not a footnote — losing two SATA to the boot drive turns 4 + 8 into 10 + NVMe and the twelfth bay has nowhere to connect. This board needs a CPU and RAM that the N100 did not. The N100 was a soldered SoC, so the switch adds two line items rather than swapping one — both are below. Check which memory generation the board takes before buying either. LGA1700 spans DDR4 and DDR5 and the boards are not interchangeable, so the board decision picks the RAM. | 1 | — |
| LGA1700 CPU — Celeron G6900 or i3-12100 Add~$45–90 · new for the Celeron, used for the i3 A file server is not a CPU workload. mergerfs passes reads straight through, and SnapRAID's parity maths is bound by disk throughput long before it is bound by cores — a dual-core Celeron is genuinely enough here. Where it does matter is a rebuild. Restoring a failed drive from parity reads every other disk and computes across all of them, so the i3's four cores turn a long weekend job into a shorter one. That is the argument for spending the extra $40, and it is a real one on a twelve-bay box. Both have integrated graphics, so no card is needed to see BIOS — worth having on a machine with no out-of-band management. Do not buy the F variants. An i3-12100F has no iGPU, and this build has no spare slot for a display card once the HBA and the NIC are in. | 1 | — |
| 8–16 GB DDR4 or DDR5 Add~$30–60 · generation decided by the board, non-ECC is fine here 16 GB, and the reason is the filesystem rather than the workload. SnapRAID itself is modest, but Linux will use everything left over as page cache, which is what stops a media library hammering the disks for metadata it just read. SnapRAID's real memory cost scales with file count, not capacity — roughly a gigabyte of RAM per 16 TB of protected data for the hash tables during a sync. Twelve bays of large drives lands comfortably inside 16 GB; 8 GB would work today and get tight as the array fills. ECC is not worth chasing on this platform. Consumer LGA1700 does not support it, and SnapRAID checksums every block on disk anyway — which catches the corruption that matters here. Wanting ECC properly means a different socket and a much larger bill. | 1 | — |
| LSI 9211-8i HBA, IT mode Add8 ports over 2× SFF-8087, PCIe 2.0 x8 · ~$30–50 used Eight of the twelve drives; the board's four SATA carry the rest. PCIe 2.0 x8 is ~4 GB/s, against maybe 250 MB/s from a spinning drive — not close to a bottleneck. IT mode is the whole point — buy it pre-flashed. In IR mode the card presents RAID volumes and hides SMART, which breaks the two things this build depends on: SnapRAID needs raw disks, and the panel needs per-drive SMART to alert on a failing one. The same silicon is sold as a Dell H310 and an IBM M1015, usually cheaper, and cross-flashing them to IT mode is a known but fiddly job. Worth it only if you want the exercise; otherwise pay the few dollars for one already flashed. It expects server airflow it will not get here. The heatsink is passive and sized for a wind tunnel — in a 2U with 80 mm fans it needs to sit where air actually moves, and it is worth watching its temperature on the panel once the agent is running. Alternates if the price is right: the 9207-8i is the PCIe 3.0 version of the same idea, and a 9201-16i or 9305-16i takes all twelve drives on one card — tidier, but hotter and dearer. | 1 | — |
| Data drives — CMR only Decide3.5″ SATA, capacity open · start with three or four, not twelve Never SMR. This is the one drive rule that cannot be worked around. Shingled drives rewrite overlapping tracks on every write, so a SnapRAID sync that should take hours takes days, and a rebuild can effectively never finish. The trap is that SMR is rarely on the box — WD Red below 8 TB and Seagate Barracuda Compute are the usual offenders. WD Red Plus or Pro, Seagate IronWolf and Toshiba N300 are CMR; check the specific model number, not the family name. 8–14 TB is the sensible band, and bigger is not simply better: rebuild time scales with drive size, and a rebuild is the window where a second failure costs you data. A 20 TB drive is a longer time spent exposed. Buy them in batches over time, not all at once. Drives from one production run share a failure distribution, and correlated failure during a rebuild is precisely the scenario parity exists to survive. Staggering purchases is free insurance against it. Prices moved sharply — see the pricing note in the math before treating any figure here as current. | 3–4 | — |
| Parity drives — 2×, sized to the largest data drive DecideSame CMR rule, same shopping list · two bays of the twelve The parity floor is a hard constraint, not a guideline: parity must be at least as large as the biggest data drive. That means the largest drive you ever add sets the parity size permanently — put one 14 TB drive in an 8 TB array and you have just bought a 14 TB parity drive too. Decide the ceiling now and buy to it. Two parity, not one, and the reason is rebuild time. Restoring an 8 TB+ drive reads every other disk for the better part of a day or more. Single parity means any second failure inside that window loses data — and a second failure is likeliest exactly then, because a rebuild is the heaviest load the array ever sees. SnapRAID supports up to six; two is the right number for twelve bays. Worth being clear about what SnapRAID does not do: it is not RAID. Parity is computed when you run a sync, so anything written since the last one is unprotected. That is an acceptable trade for a media library of write-once files, and a bad one for anything actively changing — which is why the cloud server exists separately. | 2 | — |
| RackChoice 2U, 12-bay Chosen12× 3.5″/2.5″ hot-swap SATA/SAS 6 Gbps, mATX or Mini-ITX, 21.5″ deep, 4× 80 mm + 120 mm top, 4 low-profile slots · B0BTY185DY Ships 20″ sliding rails, three SFF-8087→4×SATA breakout cables and a 2×2.5″ bracket — cables you would otherwise buy. It takes a standard ATX PSU, which is the argument that decides this. That makes it a third MSI A750GL, the same unit as the media and game servers, so one spare model still covers every machine in the rack. 21.5″ fits inside the 24″ post spacing the build order fixes on day one, with room for service loops behind it. Twelve bays against the eight this build planned for. Cheap headroom, but see the HBA note in the math — twelve bays is more than one 8-port card. | 1 | — |
Print these 5 models · +1 conditional
PETG or ASA, never PLA. A 4U server, a GPU and a UPS in one frame will creep PLA at 50–60 °C, and a sagging bracket puts cables under tension. 0.20 mm layers, 4 walls, 20–30% infill, 40% around screw holes.
| Model | Qty | Notes |
|---|---|---|
| Side cable bracketsk8md · Printables 772936 | 6–8 | Mounts with the same rack screws as the device beside it, so it costs no U. Rear posts: power down one side, data down the other. |
| Blank panels, 1U / 2U / 4Ubtadeus · Printables 381380 | 3–4 | EIA-310 compliant. Two side pieces and one center, center flipped in the slicer. |
| Storage switch tray Find a modelNo model picked yet | 1 | The 2.5 Gb switch is desktop form factor, same problem as the main switch. Size the tray once the switch is in hand — a generic 1U shelf works if nothing fits. |
| Sub-1U cable guideoXiVanisher · Printables 532072 | 1 | Under half a U, holes sized for larger RJ45 boots. Mount directly below the switch. |
| ODROID N2+ 19″ rack mount Test earlyJonas Burkhard · Printables 948730 | 1 | Thinnest-sourced model on this list by a wide margin — one STL, 23 downloads, zero makes, zero comments, no published U height and no hardware list. Nothing else here is that unverified, which is why it carries the flag. Check the STL bounding box before slicing: a full-width 19″ panel is 483 mm and will not fit a 256 mm bed. Confirm clearance for the passive heatsink (~30–35 mm total, should clear 1U) and verify hole spacing against the VEVOR posts. Load is trivial at ~200 g, so this print is about creep near the UPS heat, not weight. |
| EliteDesk Mini 1U mount Misc serverSpekkie3D · Printables 658936 | 1 | Only printed if the misc server is given a job and a rack position. Two halves joined with 6× M3×10 and hex nuts; the mini slides in from the back and seats against the facade bezel, with 2× M3×10 through the rear tabs stopping it creeping. A blank left bracket is included for single-PC use, which is our config. Print face-down, no supports. Each half is roughly 240×180 mm — check against the bed. Well proven, unlike the N2+ mount: ~19k downloads, 113 makes and comments, 12 remixes, updated October 2025. Designed around the 800-series bezel, and ours is a 705. The 705 G4 DM shares the 1 litre chassis with the 800 G4 DM, and the commercial ModMount family explicitly covers 705 G3–G5, so it should fit — but the 705's front port layout differs. Check the facade cutouts against the actual machine before committing filament. We deviate from the author's material recommendation. They suggest PLA because shrinkage makes the front lip a tight fit. The PETG/ASA rule wins anyway — this bracket is cantilevered off the front posts in an open frame near a 4U's exhaust, and PLA softens around 60 °C. Fit is the easier problem: print a ~20 mm test slice of the facade, then sand the inside chamfer with 120 grit, or scale X/Y by +0.3–0.5% and re-check the ear hole spacing. Two things the model does not solve. There is no power-brick arm — use the side cable brackets on a rear post or velcro it under the network shelf, and decide before the cables are dressed. And top-panel clearance, which is critical on the 65 W build. |
The math
Storage ports and bays
The board has six SATA, but the M.2 socket disables SATA 5/6 when populated — and it is populated, since the SK Hynix NVMe is the boot drive. That trade is already made, not hypothetical. The GPU takes the only x16 slot, so an LSI HBA is off the table and the x1 SATA card is the workaround.
| Board SATA, M.2 fitted | 4 |
| ELECNEXUS x1 card | +4 |
| Ports available | 8 |
| Chassis 3.5″ bays | 7 |
| Trickplay SSD, on its adapter | −1 |
| Bays left for HDDs | 6 |
| Drives on hand | 5 |
| Spare | 1 bay · 2 ports |
The five drives on hand fit with room left. They use six of seven bays and six of eight ports, so there is one bay for a sixth drive. After that, bays bind before ports do — the eighth port would have nowhere to put a drive.
Boot costs nothing in this budget: the NVMe sits on the board, using no port and no bay. Growing past six HDDs means the NAS, not this chassis.
19 TB raw, and no parity. Two 8 TB drives plus three 1 TB. Nothing here is redundant — a drive failure loses whatever was on it, which is the argument for the NAS running SnapRAID rather than the media server growing indefinitely.
The three 1 TB drives are worth reconsidering. Each costs a bay and a port to contribute 1 TB, and consolidating them into one larger drive would free two of each — the scarce resources in this chassis are physical, not capacity.
Twelve bays is more than one HBA
The chassis choice quietly changes the card you need. The plan says “LSI HBA in IT mode”, which in practice means a 9211-8i — and that is eight ports, not twelve. Three SFF-8087 breakout cables ship with the RackChoice; a 9211-8i only has two ports to plug them into.
| Option | Cost | Verdict |
|---|---|---|
| 9211-8i + 4 drives on board SATA | Cheapest | Fine here — see below |
| 9201-16i / 9305-16i | ~0–80 more used | Cleanest, one card, all twelve |
| 8-port card + SAS expander | Extra part, extra heat | Not worth it at this size |
Mixing controllers is genuinely fine on this stack, which is not true of every NAS design. SnapRAID and mergerfs work per-filesystem, not per-array — there is no RAID controller that needs to see every disk, so a pool split across an HBA and the board’s own SATA ports behaves identically. That is a real advantage of the OMV + mergerfs + SnapRAID choice already on this sheet, and it is what makes twelve bays cheap rather than expensive.
Where the N100 plan runs out
The board was chosen when this was an 8-bay build. Twelve bays plus an NVMe boot drive is past what it can do, and the reason is lanes rather than performance.
The N100 has nine PCIe 3.0 lanes in total, and the NAS boards built on it spend all nine — a JMB585 or ASM1166 SATA controller, one lane per M.2 slot, one per onboard i226, two more if the board carries 10 GbE. The result is the thing that actually blocks this: those boards ship no PCIe slot, so an HBA has nowhere to go. It is not that the HBA would be slow. There is no connector.
| Configuration | 12 drives? | NVMe boot? | Verdict |
|---|---|---|---|
| N100 + HBA | No slot | — | Impossible |
| N100, 6 SATA + M.2→6 SATA adapter | Yes | No — both M.2 used | Boot drive lost |
| mATX + 9211-8i + 4 board SATA | 8 + 4 = 12 | Yes, M.2 | Use this |
| mATX + 9201-16i / 9305-16i | All 12, one card | Yes, M.2 | Tidier, hotter, dearer |
The chassis already solved this and it is worth noticing. The RackChoice takes mATX, so a cheap LGA1700 board gives an x16 slot for the HBA, four onboard SATA to make up the twelve, an M.2 for the boot drive, and an x1 slot left over for the 2.5 Gb island card. That last slot retires the “both NICs must be onboard” requirement, which only ever existed because Mini-ITX had one slot and the HBA claimed it.
What it costs is idle power, and that is the honest trade: roughly 10 W for an N100 against 35–60 W for an LGA1700, which is $30–40 a year at 24/7. Real money over five years, and still the right call — an NVMe boot drive and a proper HBA are worth more here than the difference.
Do not populate twelve on day one. Twelve 3.5″ drives is roughly 18 lb of disk alone, pushing this chassis past the ~38 lb the weight table budgets for an 8-bay NAS, and every spinning drive is ~8 W idle before it is ~25 W spinning up. The bays are headroom to grow into, not a shopping list — and the parity floor still applies, so the largest data drive sets the parity drive size whatever the bay count.
What the owned kit is worth
Value in the rack, not money to find — none of this enters the build total, which exists to say what is still unspent. Listed so the two are never confused, and so the rack's real cost is recoverable if it ever matters for insurance or a sale.
| Owned | Qty | Each | Value |
|---|---|---|---|
| APC Back-UPS Pro BR1000MS | 1 | $191.43 | $191.43 |
| ODROID N2+ 4 GB | 1 | $95.00 | $95.00 |
| BrosTrend 2.5 Gb, 5-port | 2 | $37.99 | $75.98 |
| 128 GB A2 microSD | 1 | $60.05 | $60.05 |
| Priced so far | $422.46 |
Nine owned items are still unvalued, and they are the expensive ones — the Ryzen 5 3600, the ASUS Prime board, 16 GB of DDR4, the ZOTAC RTX 3050, the SK Hynix NVMe, five hard drives, and the whole FX-6300 platform of board, CPU and 20 GB of DDR3. The GPU alone likely exceeds everything in the table above.
So treat $422 as a floor on owned value, exactly as the build total is a floor on spend. Both climb as prices are filled in; neither is wrong, both are incomplete, and the sheet says which is which rather than quietly averaging them into one confident number.
Every price on this sheet is stale — read this before ordering
The NAND and DRAM markets moved sharply while this sheet was being written, and they moved up. NAND contract prices have multiplied roughly 4.2–4.5× over three quarters. 2 TB NVMe drives that ran $120–150 a year ago now run $300–480. Micron exited the Crucial consumer business entirely, with product ceasing to ship in February 2026. DDR4 followed, and DDR4 SODIMM is worse than most — an end-of-life line with capacity redirected elsewhere.
This inverts one of the sheet's own conclusions. The Price flags on both AX2 drives were set against a market where the 1 TB sat around $36–50, which is what made $129.99 look like double the going rate. That comparison no longer holds. Re-check against current comparable drives rather than against the old note — the flag may now be pointing the wrong way.
| Both AX2 Price flags | Stale · re-check, do not assume |
| The ~$40 DDR4 SODIMM kit estimate | Unreliable · reasoning holds, number may not |
| 256 GB boot / 1 TB data sizing | Reinforced |
| Media server 1 TB → 8/10/14 TB path | Re-price before deciding |
The sizing decisions come out stronger, not weaker. In a market like this the rule is to buy the capacity you will actually use — unused terabytes are expensive insurance. The 256 GB boot drive and the 1 TB data drive are both right for that reason, and the 1 TB is right despite being ~10× the stated need only because it is the machine's only bulk volume.
Nothing on this sheet is a current quote. Verify every figure at checkout. The subtotals are kept because the relative comparisons — what a second chassis or a second PSU costs — survive a moving market. The absolute numbers do not.
Replacing the 1 TB drives
Three bays currently hold 3 TB between them. Swapping them for 8, 10 or 14 TB drives, keeping both 8 TB drives and leaving the sixth bay for parity:
| Replace with | Data, 5 drives | Parity drive needed | Bays used of 7 |
|---|---|---|---|
| 3× 8 TB | 40 TB | 8 TB | 7 · full |
| 3× 10 TB | 46 TB | 10 TB | 7 · full |
| 3× 14 TB | 58 TB | 14 TB | 7 · full |
| 2× 14 TB, one bay left empty | 44 TB | 14 TB | 6 · one spare |
The decision worth making now is the largest drive, not the total. If parity is ever added, the parity drive must be at least as large as the biggest data drive. Buying one 14 TB today sets a 14 TB floor on a purchase you have not made yet — mixing sizes does not average out, it takes the maximum.
So: pick a target size and buy only that size. Three 8 TB drives and an 8 TB parity is a coherent build. Two 8 TB plus one 14 TB is the same capacity as three 10s while forcing the most expensive parity drive of the three options.
Bigger drives make the missing parity worse, not better. Losing a 1 TB drive today costs 1 TB. Losing a 14 TB drive costs 14 TB, and the rebuild — once there is something to rebuild from — runs for the better part of a day. The larger these get, the harder it is to justify the current no-redundancy arrangement.
Watch which port each drive lands on. Four board SATA run at full 6 Gb/s; the four on the ELECNEXUS card share roughly 500 MB/s across all of them, since the x1 slot negotiates PCIe 2.0 on this board. Fine for streaming, painful for a parity sync across four large drives at once. Put the largest drives on the board ports.
One caution on 14 TB specifically: at that size drives are usually 7200 rpm enterprise units — louder, hotter and thirstier than the 5400 rpm class. In an open frame in an office, that is a real cost the capacity table does not show.
Power draw
| Ryzen 5 3600 (PPT) | 88 W |
| RTX 3050 | 130 W |
| Board + RAM | 40 W |
| Drives, idle | 50 W |
| Fans | 15 W |
| Typical | ~325 W |
| Cold boot, all drives spinning up | ~450 W |
750 W puts you near 43% load, right by the Gold efficiency peak. A 550 W would have saved $50 but leaves no room for a future GPU.
UPS headroom
| Media server, typical | ~325 W |
| Game server, loaded | ~160 W |
| Cloud server, estimated | ~150 W |
| Three switches | ~15 W |
| ODROID N2+ | ~4 W |
| Three servers, typical | ~650 W |
| All cold-booting together | ~850 W |
The CyberPower is 1000 W and could carry all three at about 65%, with even a simultaneous cold boot inside the envelope. Note the 1500 VA figure is not the constraint — active-PFC supplies run a power factor near 1.0, so the 1000 W rating is what binds.
It should not have to. Moving the game server to the BR1000MS drops this to ~475 W and takes runtime from roughly five minutes to ten — see the office split below. The figures above are the all-on-one case, kept as the ceiling to design against.
Runtime, not capacity, is the limit either way. Ten minutes is a graceful-shutdown window, not a ride-through — worth wiring up NUT or apcupsd before you rely on it.
Adding the NAS later pushes typical toward 770 W, around 77%, which is where headroom starts to matter. The 2000 VA version of the same unit is $449.95, so about $90 buys that margin if the NAS is a certainty.
The misc server, if it is ever racked, is noise here. At ~10–30 W on the BR1000MS it moves that unit from ~194 W to at most ~224 W, still around a third of its rating. Worth knowing mainly because it means the decision to rack it never has to wait on power.
The interim APC is only 600 W. It carries the media server alone comfortably and two servers at idle with little to spare, but a simultaneous cold boot overruns it — exactly what happens when utility power returns after an outage. Until the CyberPower lands, stagger the boots in BIOS or run the game server straight off the wall. It is the one box whose sudden loss costs nothing.
What you have vs what you're buying
| APC BR1000MS — have | CyberPower CP1500PFCRM2U — planned | |
|---|---|---|
| Capacity | 1000 VA / 600 W | 1500 VA / 1000 W |
| Form factor | Tower, 14.5″ deep | 2U rackmount, 10.5″ deep |
| Rack cost | ~3U, and a shelf you don't own | 2U, rails included |
| Media server alone · ~325 W | 54% | 33% |
| Three servers · ~650 W | over capacity | 65% |
| All cold-booting · ~850 W | over capacity | 85% |
| Adding the NAS later · ~770 W | over capacity | 77% |
| Runtime at ~325 W | ~10 min | ~20 min |
| Runtime at ~650 W | n/a | ~5 min |
| Cost | owned | $359.95 |
These are not alternatives — both stay in service, so read the red as "cannot carry the servers", not "inadequate". The APC is a different class of thing, and its job after the upgrade is the low-draw network gear, where 600 W is enormous.
Settled: the APC lives beside the rack, not in it. It is a 14.5″ tower and would have cost roughly 3U on a shelf. The 2U it would have taken is instead reserved for the second CyberPower, shown dotted at the bottom of both views — so the eventual swap is a slide-in, not a re-hang.
Runtimes are approximate — battery age and load shape both move them, and neither figure is long enough to be a ride-through. Both are shutdown windows.
Weight — and what the rack is actually rated for
| Day one | Fully populated | |
|---|---|---|
| VEVOR 20U frame | ~45 lb | ~45 lb |
| CyberPower UPS | ~46 lb | ~92 lb · two units |
| Media server, 4U + 6 HDDs | ~34 lb | ~34 lb |
| Game server, 2U | ~20 lb | ~20 lb |
| Cloud server, 2U | — | ~22 lb |
| NAS, 2U + 8 HDDs | — | ~38 lb |
| — same chassis, all 12 bays filled | — | ~44 lb |
| main switch + network shelf | ~8 lb | ~8 lb |
| ODROID N2+ + printed mount | <1 lb | <1 lb |
| Rails, cage nuts, cabling | ~16 lb | ~29 lb |
| Gross | ~170 lb | ~288 lb |
| Load on the rails — frame excluded | ~125 lb | ~243 lb |
The last row is the one to measure against. A rack's load rating excludes its own frame — it is what the rails carry. Day one you are fine on any reading of the VEVOR spec. Fully populated you are comfortably over a 200 lb rating and comfortably under 500, and VEVOR's own pages claim both. Settle it before the NAS and the second UPS go in.
The UPSes dominate. Two CyberPowers are ~92 lb, near a third of the total and all of it sealed lead-acid. That is the reason they hold the bottom 4U rather than anywhere else.
The APC is not counted — it is ~26 lb sitting on the floor beside the rack, so it costs nothing structurally. Fourteen 3.5″ drives across the media server and NAS are ~15 lb between them, more than the main switch, the network shelf and every printed part combined.
The N2+ is a rounding error at ~200 g plus its bracket, which is why that print is about creep near the UPS heat rather than about load. The misc server would add ~3 lb if it is ever racked, which is inside the rounding on every figure above. The rating question is driven by the two UPS units and the NAS, and nothing small changes it.
Assume the rating is static, not rolling. An open frame at ~288 lb on casters is a different proposition from one standing still — load it in position.
Power topology — four units, whole path protected
| Unit | Capacity | Waveform | Carries |
|---|---|---|---|
| APC Back-UPS 1500 · bedroom SKU unconfirmed — see the checks | 1500 VA / ~900 W | Stepped assumed | Wifi modem + main eero |
| APC BE850M2 · kitchen | 850 VA / 450 W | Stepped | Kitchen eero + BrosTrend switch + Eufy HomeBase 3 |
| APC BR1000MS · office | 1000 VA / 600 W | Pure sine | Game server + ODROID N2+ + office eero + 3 switches |
| CyberPower CP1500PFCRM2U · rack | 1500 VA / 1000 W | Pure sine | Media + cloud servers |
Every hop from the modem to the rack is on battery. That is unusual and it removes the failure this build would otherwise have: the rack outliving its own network and becoming unreachable mid-outage. Nothing more is needed upstream.
The waveform column is the one to respect. The two Back-UPS units output a stepped approximation of a sine wave. Modems and eeros are small switching supplies and do not care. An active-PFC server supply very much does — it can run hot, buzz, or drop out entirely on stepped output. Never move a server onto the bedroom or kitchen units, however tempting their spare capacity looks.
That leaves exactly two units that may carry anything with an active-PFC supply: the BR1000MS and the CyberPower. Both are pure sine, which is why the sheet has always specified it.
The kitchen is complete rather than partial: the BrosTrend switch sits on the BE850M2 alongside the eero and the HomeBase 3, so the Eufy stays reachable during an outage and not merely powered. Worth noting because a camera hub that runs but cannot upload is the least useful failure available.
The kitchen unit is on an aftermarket battery — 9.5 Ah against the 9 Ah it shipped with. About +5.5% capacity, slightly less than that in runtime under load. Real, but marginal: battery age moves this figure far more than the extra half amp-hour does, since a tired 9.5 Ah loses to a fresh 9 Ah. Install date is the number worth having.
Expect the panel to under-report this one unit. The UPS derives its runtime estimate from an internal model that assumes the stock battery, and NUT passes that figure straight through — so a larger cell reads conservative rather than better. Worth knowing before the power tab makes the kitchen look weaker than it is.
The N2+ is on the BR1000MS rather than the CyberPower, and that is deliberate. It is the box that must outlast every server it shuts down, and it holds both UPS data cables. Putting it on the unit that carries the media server would mean the NUT master and its heaviest client draining the same battery.
The outage telemetry window, part-answered off the front panel. The panel keeps hearing from the house for as long as the WAN path holds, not as long as the office unit holds — so it is the bedroom and kitchen units' runtimes, not the office unit's ~20 minutes, that bound how long an outage stays visible from outside.
The bedroom unit reads ON LINE at 122 V, battery full, load bar at the bottom of its range. A modem plus one eero is roughly 25 W against a 1500 VA unit — low single-digit percent, which puts runtime in hours rather than minutes. The kitchen unit is the tighter of the two: a smaller 850 VA battery carrying an eero, the BrosTrend switch and the Eufy HomeBase 3.
So the telemetry window comfortably outlasts the rack, which is the answer you want — the panel will still be hearing from the house long after the servers have shut themselves down. Worth a real figure from both front panels rather than a bar graph, but this is no longer an open risk.
Splitting the office load
Never plug one UPS into another. The downstream unit's charger looks like a nonlinear load with real inrush to the upstream one, most manufacturers forbid it, and the runtimes do not usefully add. Both office units hang off the wall independently.
Leaving the BR1000MS on 30 W of network gear wastes it. It is pure sine, so it is one of only two units in the house allowed to carry a server — and hours of network runtime buy little once the servers are already down. Put the game server on it.
| BR1000MS · game server + eero + 3 switches | ~190 W · 32% · ~20 min |
| CyberPower · media + cloud servers | ~475 W · 48% · ~10 min |
The media server's runtime roughly doubles, from about five minutes to ten, which is the real prize. Both units land near half load, which is where their batteries last longest and run coolest.
The game server is the right one to move: it holds nothing that a sudden loss would damage, so pairing it with the older battery costs the least. Media and cloud — the two that hold data — stay on the newer, larger unit.
Both USB runs land on the N2+, so there is still only one shutdown path. Two units, two data cables, but one upsd and one master upsmon — every server is an identical slave pointed at U16. The simplicity that splitting the load used to cost has been recovered: you get the extra five minutes and one config.
The N2+ adds ~4 W to the BR1000MS, taking it from ~190 W to ~194 W. Not enough to restate the table.
Coming back up
Shutting down cleanly is the easy half. Coming back on is two separate settings, and neither is on by default.
1 · BIOS: restore on AC power loss. Set it to Power On, not Last State.
| Media · ASUS Prime | Advanced → APM → Restore AC Power Loss → Power On |
| Game · GA-78LMT-USB3 | Power Management Setup → AC BACK → Always On |
| Game · same board | ErP / EuP → Disabled — it cuts the standby rail auto-power-on runs from |
Last State reads as the safer option and is the wrong one here. NUT shut the box down cleanly, so the last state is off — and it stays off.
2 · The UPS has to actually cut its outlets. This is the step that gets missed. NUT's shutdown must finish by telling the UPS to drop the load, so it re-energises when mains returns — shutdown.return, issued by upsdrvctl shutdown at the end of upsmon's sequence.
Without it, the failure is specific: power comes back before the battery is flat. The outlets never de-energised, the servers never see an AC transition, and they sit there off until someone walks over and presses a button. A battery running all the way down does the right thing by accident — you do not want correct behaviour to depend on the outage being long enough.
Confirm each unit supports it before relying on it, because CyberPower's NUT load-shed support is less consistent than APC's: upscmd -l cyberpower should list shutdown.return.
3 · Test it the long way. Pull the plug and leave it — all the way down, outlets dead, then restore mains. Cutting the test short at "they shut down" only proves the half that was already easy.
Nothing on the monitoring panel can verify this. It sees a broken shutdown path; it cannot see a server that would never come back, because that only shows up during the one event you are building for.
WAN headroom
2.5 Gb down, 300 Mbps up. Only one of those numbers matters here: self-hosting spends upload. Every remote Jellyfin stream, every Immich share, every restic push leaves the house, so the 300 is the figure to plan against and the 2.5 Gb is close to irrelevant.
| 4K HDR direct play | 40–80 Mbps |
| 1080p remux direct play | 20–40 Mbps |
| Transcoded 1080p | 8–12 Mbps |
| Concurrent 4K at 300 Mbps | 4–7 |
| Concurrent 1080p remux | 7–15 |
Which end binds depends on the stream, and that is new. For transcoded playback the RTX 3050 still runs out first — NVENC manages roughly 8–12 simultaneous 1080p encodes, and 300 Mbps would carry closer to thirty. But for 4K direct play the uplink now binds instead: no transcode means the GPU is not involved at all, and four to seven streams is the ceiling. Direct play is also the case a good client picks by default.
The path in is now 2.5 Gb the whole way, which changes what that download is worth. Both Netgears were replaced, so eero to edge switch to main switch runs at 2.5 Gb with nothing in the middle throttling it. An earlier revision of this sheet said the opposite; it was written when both switches were gigabit.
Individual machines are still capped near 940 Mbps, because every main-LAN NIC in the rack is gigabit — the 2.5 Gb cards are committed to the isolated storage island. No single server got faster. What changed is contention: two or three machines pulling at once now share a 2.5 Gb trunk instead of queueing behind one gigabit uplink, which is the case that actually shows up during a large download or a restic seed.
Everything else is noise: game servers are 10–50 kbps per player, Immich sync is inbound and bursty, restic is incremental after the first seed and runs overnight.
The mesh backhaul is no longer the thing to watch. Two wireless hops could hold the rack to 200–400 Mbps, which used to be a real haircut against a gigabit uplink — against 300 Mbps up it is roughly a wash. Confirming the backhaul is wired still matters for downloads and for the LAN, just not for what leaves the house.
Sizing the panel VPS
2 vCore, 4 GB, 40 GB NVMe at $5/month. The instinct is that 40 GB is tight for a metrics database. It is not the constraint.
| Samples, per host per day · 15 s | 5,760 rows |
| Five agents, 30 days full resolution | ~860k rows · <350 MB |
| Hourly rollups, one year | ~44k rows · noise |
| Debian + Postgres + binaries | ~10 GB |
Five agents now — three servers, the NAS when it lands, and the N2+. Even with the retention job never written, that is roughly 2.6 GB a year, or a decade of headroom on 40 GB.
Set retention before the first agent connects anyway — but for the right reason. It is an index-size and query-speed decision, not a capacity one, and being clear about which problem you are solving stops it being deferred as "we'll deal with it when the disk fills". The disk will not fill.
4 GB is comfortable for Postgres, Caddy and the panel itself. The panel is a Rust binary in the tens of megabytes resident, so the database gets essentially all of it. Two cores are idle most of the time: a handful of agents posting every 15 s and an alert sweep every 60 s is not a workload.
Two things would break this sizing, and neither is planned: shipping logs to the panel rather than just metrics, or keeping full-resolution history for a year instead of rolling it up. Both are disk problems, and both are decisions rather than surprises.
Airflow
One 120 mm in (~70 CFM), two 80 mm out (~80 CFM) plus PSU exhaust. Slightly negative pressure.
Not a thermal problem — intake pulls through the drive cage, cooling the HDDs on the way past. It is a dust problem: unfiltered air enters through every seam. Blow the chassis out every few months.
If the P12 Pro has to run loud to hold GPU temps, drop to one rear P8 Max. Less exhaust, closer to neutral, quieter.
PCIe slots
One x16 (GPU) plus x1 slots. Two cards want them: the SATA card and the dual-port NIC. That is the same count as before only because the NIC became a dual — the media server now needs 2.5 Gb on both the main LAN and the island, and two single cards would have made it three.
Prefer the x4-capable slot for the dual NIC. B450's x1 slots are PCIe 2.0, roughly 4 Gb/s, against 5 Gb/s if both its ports saturated simultaneously. In practice they will not, but if a slot with more lanes is reachable past the GPU, use it there.
Verify the exact slot count on your board before ordering either. If there is only one usable slot after the dual-slot GPU, something still has to give — most likely the SATA card, with bulk storage moving to the NAS instead.
10 GbE is not possible here. It needs x4 or x8. 2.5 G over x1 is the ceiling.
Fan control on Debian
The hub is a dumb splitter, so lm-sensors and fancontrol drive it through the motherboard header. The real obstacle is the Super I/O driver.
Nuvoton chips need acpi_enforce_resources=lax at boot. ITE chips need the out-of-tree it87 module via DKMS — the frankcrawford fork is the maintained one.
Run sensors-detect after the build. If pwmconfig finds no PWM outputs, that's the ACPI lock, not the hardware. Fallback: set a conservative fixed curve in BIOS and move on.
Wiring the fans
| PA120 Mini | CPU_FAN |
| P12 Pro front | Hub, slot 1 |
| 2× P8 Max rear | Hub |
| Hub input | CHA_FAN1 |
| CHA_FAN2 | free |
Cooler stays off the hub so it tracks CPU temp independently. The hub reports RPM from slot 1 only — put the intake there, since it's the fan whose failure matters most.
Network design decided · $0 in switches
Internet service is 1 Gb up and down, so nothing that touches the WAN gains anything from 2.5 Gb. The only traffic that can saturate a 2.5 Gb link is server to server — Jellyfin reading the library, Immich originals, restic snapshots. So 2.5 Gb goes where it can actually be used, on an isolated storage network, and everything else stays on gigabit. Both switches are already owned.
Rule 1 — never uplink the storage switch
No cable between it and the main switch, ever. If the two networks touch, every server has two paths to every other one and traffic takes whichever it likes.
The result is asymmetric routing, ARP confusion, and storage traffic quietly leaking onto the gigabit side — which looks like a performance mystery, not a wiring mistake.
Rule 2 — storage NICs get no default route
Netmask only on the island interfaces. No gateway, no DNS. That is what stops the OS deciding to send general traffic down the storage link.
Reference island hosts by IP or /etc/hosts, never by DNS name. This is the single most common way an isolated network stops being isolated.
Edge — TP-Link TL-SG105S-M2, 5 ports
| 1 | Uplink to eero · 2.5 Gb |
| 2 | Gaming tower · 2.5 Gb |
| 3 | Down to the main LAN switch · 2.5 Gb |
| 4–5 | Spare — two free |
The TP-Link 5-port, replacing the GS108. It still keeps the tower's desk run off the rack switch and leaves the main switch entirely for rack machines.
This is the switch where 2.5 Gb pays most directly. It sits in the WAN path, so the gaming tower can pull more than a gigabit of the 2.5 Gb service instead of being capped by the old GS108.
Three of five ports used. Enough, but note the GS108 left five free and this leaves two.
Main LAN — TP-Link TL-SG108S-M2, 8 ports
| 1 | Uplink to the edge switch · 2.5 Gb |
| 2 | Media server · 2.5 Gb, dual-NIC port 1 — motherboard port unused |
| 3 | Game server, onboard |
| 4 | Cloud server, onboard |
| 5 | NAS, onboard secondary |
| 6 | ODROID N2+ · one-foot patch from U16 |
| 7 | Edge box · reverse proxy |
| 8 | One spare. That is the whole margin. |
Sixteen ports became eight, and the reserves went with them. The main switch held two ports back for future 2U servers and still had eight spare. This is fully committed at seven with one left — the next machine that needs a main-LAN port needs a switch, not a cable. Worth knowing before it is a surprise.
What 2.5 Gb buys here is the trunk, not the machines. Every main-LAN NIC in this build is gigabit — the servers' 2.5 Gb cards are committed to the isolated storage island, which never uplinks. So no single machine gets faster. What changes is that the uplink to the edge is now 2.5 Gb, so two or three rack machines pulling from the internet at once stop contending for one gigabit trunk. With a 2.5 Gb service that is the bottleneck worth removing.
The N2+ is wired only — no onboard wireless — and sits at U16 directly below this switch. Blue cable, main LAN, same as every other onboard NIC, and it needs a fixed DHCP lease by MAC because the NUT slaves resolve it by name.
Storage island — BrosTrend 2.5 Gb, 5 ports
| 1 | Media server · dual-NIC port 2 · I226-V · 10.10.10.10 |
| 2 | Cloud server · NIC still to buy · 10.10.10.20 |
| 3 | NAS · onboard i226 · 10.10.10.30 |
| 4–5 | Reserved — future 2U · .40, .50 |
Static 10.10.10.0/24. The game server is deliberately absent — its board is gigabit-only and it has no storage traffic worth the slot.
Every server is dual-homed
Onboard gigabit to the main switch for internet, SSH, web UIs and management. A second 2.5 Gb card to the island, where applicable, for NFS, Immich originals and restic.
Main LAN addressing is DHCP from the eero — reserve a fixed lease by MAC for every server so hostnames stay stable.
The N2+ is the exception, and deliberately so: one port, main LAN only. It has no storage traffic to carry, the island is gigabit-irrelevant to it, and a 5-port switch has nothing spare. It still needs the fixed lease — more than the servers do, since three NUT slaves resolve it by name.
The rack sits four hops out
Modem to Bedroom to Kitchen to the BrosTrend switch, which fans out to the Eufy HomeBase 3 and to the Office eero. The Office unit then feeds the whole rack.
That makes the BrosTrend a single point of failure for everything in the rack. It is a $38 unmanaged switch carrying the entire WAN path — if it dies, the rack loses internet even though every eero is still up. Worth keeping a spare in a drawer; it is the cheapest insurance in the build.
It is at least on battery, sharing the BE850M2 with the kitchen eero and the Eufy, so a power cut does not take it out. Note this is the second reason that unit matters more than its size suggests.
Worth confirming the backhaul is wired. These are dual-band, so there is no dedicated backhaul radio — on a wireless mesh each hop shares airtime with clients, and this far out the rack could see well under half the 1 Gb service. Wired, it is a non-issue.
Note there are two 2.5 Gb switches in play. The Kitchen BrosTrend is ordinary LAN and carries the rack's uplink. The rack one is the isolated island and must never be confused for it.
The telemetry path is protected end to end
This wasn't planned and it happens to be right, so it is worth stating as a property of the design rather than leaving it to luck: the N2+'s entire path out of the rack — main switch, edge switch, office eero — is already on the BR1000MS alongside the N2+ itself. The one machine that must keep reporting during an outage shares a battery with every hop it needs to do so.
Combined with the modem and both intermediate eeros upstream, the path from the N2+ to the VPS is on battery with no exceptions.
One ambiguity it does not solve. Because the link is wired-only, a dead main switch or a bad patch cable takes the N2+ off the network along with all four servers. The panel still catches it — five agents going quiet at once is unmistakable — but it cannot distinguish the rack is down from the switch is down, and those are very different 2am problems. A ~$10 USB wireless dongle associating to the office eero as a backup path would resolve exactly that. Against it: a second interface on a box whose job is to be simple, plus route metrics to get right so it never becomes the primary path. Left undecided on purpose.
One Homebridge constraint while it is in mind: HomeKit discovery is mDNS, so the N2+ must stay in the same broadcast domain as the phones and the eero-attached accessories. Flat DHCP from the eero across unmanaged switches satisfies that today. If the main LAN is ever segmented, Homebridge is the thing that breaks first and least obviously.
Inbound — what the router forwards
The edge box exists to make this table stop growing.
| Port | Today | After the edge box |
|---|---|---|
| 443 | → media server | → edge box |
| Jellyfin | Separate forward | Deleted — routed internally |
| Any future web service | A new forward each | None — DNS record only |
| 25565–25595 | Minecraft | Unchanged |
The rule this buys: after the edge box, no web service ever requires touching the eero again. A new service is a DNS record plus one entry in the proxy. That is the entire point of the line item, and it is worth stating as a rule rather than a benefit — the moment someone adds a forward "just this once", the consolidation is gone.
The edge box gets a reserved DHCP lease by MAC in the eero app, the same treatment the servers already get. It is the target of a port forward, so a changed address does not degrade it — it takes every web service down at once.
Game ports are untouched and stay that way. A reverse proxy reads the hostname out of a request to route it, and game protocols do not carry one — see the edge box section.
Cable colours
Blue for main LAN, server onboard NICs to the main switch. Green for the storage island. White or red for the eero uplink.
Uniform correct lengths matter more than cable spec. Avoid Cat 7 and Cat 8 — marketing labels at these speeds — plus flat cable, braided jackets, and anything not stating bare copper.
What this gives up
The gaming tower and every Wi-Fi client reach the NAS at 1 Gb, since they arrive through the edge and main switches rather than the island. Fine for occasional access, noticeable if you regularly pull large media off the NAS.
The fix is a 2.5 Gb card in the tower and a run to a reserved island port, or an 8-port island switch (~$60) to cover that and the future servers. Nothing here blocks either.
Edge box — reverse proxy separate budget
Network infrastructure, not a server — same tier as the main switch and the eero, which is why it sits here rather than in the server list. It terminates all inbound web traffic, collapsing every current and future HTTP/HTTPS port forward into one. After this, adding a web service is a DNS record and one proxy entry; it never means touching the router again. Its spend sits outside the build total, like the game and misc servers.
This is a second board, not a second container
The sheet already has an ODROID-N2+ 4 GB running NUT master, out-of-band monitoring and Home Assistant / Homebridge. That is a different machine and stays separate. If the fallback is built, this rack contains two N2+ boards with different jobs and different RAM.
| Existing N2+ 4 GB | New N2+ 2 GB | |
|---|---|---|
| Job | NUT master, monitoring, HA | Reverse proxy only |
| Ports open | None — outbound agent only | 443 inbound |
| Rule | Never given a server's job | Single-purpose DMZ box |
They must never be consolidated. The existing N2+ can shut down every server in the rack through NUT. Putting the internet-facing edge on it would place the public attack surface on the machine that controls rack power — and the sheet's existing rule, that it is the only box out-of-band relative to the servers and loading it up destroys that, is exactly why this is a second board.
| Item | Qty | Price |
|---|---|---|
| Raspberry Pi 4, 2 GB or better Have Test earlyThe primary. Costs nothing if it boots — and dead Pi 4 boards are rare, so work the four causes below before treating the fallback as real. ~940 Mbps native NIC, which matters more here than the CPU does. | 1 | — |
| USB SSD for boot Add~$25 · only if it is not already on SSD Same rule the sheet already applies to the existing N2+, for the same reason. A proxy writes access logs continuously, which is precisely the workload that kills flash cards. Either boot from USB SSD, or run log2ram and ship logs off the box.The Pi 4 boots from USB natively, so this costs no adapter. | 1 | — |
| ODROID-N2+ 2 GB Only if needed~$60–90 board, plus ~$30–50 for 12 V PSU, storage and shipping · ~$95–140 landed Only if the Pi 4 is genuinely dead. Hardkernel ships from Korea and the shipping is a real line, not a rounding error — price it landed before treating this as a $60 board. 2 GB, not 4. The proxy uses ~200–300 MB; with Docker and the OS it lands near 600 MB. The extra RAM buys nothing on this workload, and the 4 GB board already in the rack is committed elsewhere. | 1 | — |
Throughput decides the board
A reverse proxy crosses the NIC twice per request, so effective throughput is roughly half of line rate. That single fact decides the board.
| Board | Real line rate | Effective proxying |
|---|---|---|
| Pi 4 | ~940 Mbps native | ~470 Mbps |
| N2+ 2 GB | ~940 Mbps native | ~470 Mbps |
Both candidates clear the 300 Mbps upload with room to spare, which is the bar that matters: the proxy must never become the bottleneck instead of the connection. Anything on a USB-attached NIC rather than a native one fails that test, which is why the board choice is only between these two.
Before buying the fallback, work these four
Nearly every Pi 4 boot failure is one of these, and none of them is a dead board.
| Underpowered supply | Needs 5 V 3 A. Phone chargers cause boot loops. |
| E-marked USB-C cable | Rev 1.1 boards reject them — try a basic cable |
| Corrupt SD card | Reflash with Raspberry Pi Imager |
| Corrupt bootloader EEPROM | Flash the recovery image to a blank card and boot it |
One diagnostic settles alive-or-dead: pull the SD card and power on. A green ACT LED flashing in a pattern means the board is fine and the problem is storage or image, not hardware.
The most likely outcome by a wide margin is that it boots and the fallback line is never actioned.
Placement and power
| Position | Network shelf, beside the eero and island switch |
| Rack U | 0U — no print required |
| Patch | Short run to the main switch |
| Draw | ~5 W |
| UPS | BR1000MS, with the eero and switches |
~5 W is negligible against the BR1000MS's existing load, and it belongs on the same battery as the network gear it depends on — a proxy running while its switch is dark is useless.
If it is later racked rather than shelved and the fallback N2+ was built, Printables 948730 fits it — a second copy of a print already proven by then, rather than a new unknown. Not required; the shelf has room.
Software — and the one thing that will bite
| OS | 64-bit — Raspberry Pi OS Bookworm (aarch64, not armv7l) or Debian arm64 |
| Proxy | Nginx Proxy Manager, in Docker |
| Ports | 80, 443, and 81 for the admin UI — LAN only, never forwarded |
| Boot media | USB SSD, not microSD |
Single-purpose box. No Pi-hole, no Uptime Kuma, no second workload. On the 2 GB fallback there is no headroom for one — and on either board, the DMZ argument only holds if nothing else lives there.
Cloudflare DNS-01 is a guaranteed encounter, not a possibility. This build uses Cloudflare DNS, and if a record is proxied (orange cloud), Let's Encrypt HTTP-01 cannot reach the box and cert issuance fails with an unhelpful error. It looks like a broken proxy and it is not.
| Option | Verdict |
|---|---|
| DNS-01 via Cloudflare API token | Use this. Built into NPM, works with the proxy on, supports wildcards |
| Grey-cloud the records | Works, but exposes the home IP |
Which is why it is a build-order step below rather than a troubleshooting note.
Which traffic goes where — decided once
Cloudflare Tunnel stays available and the edge box does not replace it. The split is by bandwidth, not by preference.
| Service | Route | Why |
|---|---|---|
| Light web hosted in this rack | Cloudflare Tunnel | No port needed, no bandwidth concern |
| Jellyfin | Edge box, direct | Cloudflare's free-tier terms restrict sustained video streaming through tunnels |
| Nextcloud / cloud server | Edge box, direct | Large file transfers, same reasoning |
| Pterodactyl panel | Either | Light — tunnel is fine |
This is the actual justification for the line item. A tunnel handles the small stuff for free; the edge box exists for the bandwidth-heavy services that should not transit someone else's network.
Two things deliberately absent from this table. The AmeriBrit Panel is not here because it is off-site on the VPS — it never crosses this connection in either direction, since the agents dial out to it. And no Kemit service belongs here at all: that infrastructure stays separate from this build, which is a house rule rather than a technical one, and the easiest one to erode by adding a single convenient row.
What this explicitly does not solve
HTTP and HTTPS only. A reverse proxy routes by reading the hostname out of the request. Game protocols do not carry one — the connection is established before there is anything to read. No amount of configuration changes that.
| Consolidates? | |
|---|---|
| Web services | Yes — all of them, one forward |
| Minecraft · 25565–25595 | No. Needs an MC-aware proxy (Infrared or Velocity) — a separate future line item |
| FiveM | No. 30120 TCP+UDP per instance, one forward each, no way around it |
Stated plainly so it is not re-litigated later when the game ports are still there.
Assembled view drag to orbit
The same twenty U as a solid, with the cable runs the network design implies. Drag it to swing around the rack — the wiring lives at the back, so the rear view is the one that matters when you are deciding what goes where. The flat elevation in the sidebar stays the reference for what sits at which U.
Drag to rotate · arrow keys when focused · hover a device to trace its runs
Three bundles, one side each
Power runs down one rear post, data down the other, exactly as the build order calls for. Drawing them as one bundle per service is the point — a cable you can trace by colour and side is one you can unplug at 2am without tracing it at all.
Hovering a device dims everything else, which is the quickest way to see what a given box actually depends on.
The APC sits on the floor beside the rack rather than in it, so the game server, main switch and network shelf runs leave the frame at the bottom rear and terminate there. The 2U reserved for the second CyberPower stays empty until that swap happens.
Service loops are not drawn
Every run here is the straight-line path. Real ones need the 6–8″ of slack the build order specifies, so a chassis can slide out on its rails without unplugging.
That slack is why the 5 ft patch cables are more forgiving than the 1–2 ft the network design asked for, and also why they will coil behind the posts.
The network shelf
Three U, two trays, five devices — and width is now the binding constraint, not height. The main switch moved down here once it stopped being an 11″ Netgear, which handed a rack unit back and deleted a print. What it did not do is make everything fit on one tray.
| On the shelves | Approx. width |
|---|---|
| TP-Link TL-SG108S-M2 · main LAN | ~8″ |
| TP-Link TL-SG105S-M2 · edge | ~4″ |
| BrosTrend 5-port · island | ~4″ |
| eero 7 · office | ~5″ |
| Edge box · Pi 4 | ~3.5″ |
| Total | ~24.5″ against ~17.5″ usable |
That is why this is two trays rather than one. A 19″ shelf gives roughly 17.5″ of usable width between the ears, and the kit adds up to more than that — so the freed unit pays for a second tray instead of becoming spare. Two trays is ~35″ of run, which is comfortable rather than tight.
The 3U is clearance, not shelf thickness: the trays themselves are 1U each, and the extra unit exists because the eero stands taller than 1.75″. Worth stating plainly, because “we need a 3U shelf” would send you shopping for the wrong part.
Dropping the PDU paid for the second U. The bottom 2U is reserved for the second CyberPower rather than sitting empty. Everything still adds to twenty.
The N2+ took half of what used to be the spare 2U. The elevation summed to exactly twenty with no free U, so its mount had to come from somewhere: U16 for the N2+, U15 still genuinely spare. USB from U16 down to the CyberPower at U3–4 is roughly 4 ft internal, well inside the 5 m limit, and the BR1000MS sits on the floor at the same end.
The storage switch tray stays a separate print, and that was checked rather than assumed. Combining it with the N2+ mount into one 1U tray was considered and rejected: taking the island switch off the network shelf doesn't shrink that shelf below 2U, because the eero is taller than 1.75″ on its own. The combined tray would cost a real U instead of saving one.
Verify before ordering
- Slot count on the B450M-A II, with the dual-slot GPU physically installed. Two cards are on the list: the SATA card and the dual-port NIC. Note which slot is x4-capable — the dual NIC belongs there if the GPU leaves it reachable, since B450 x1 slots are PCIe 2.0 and both NIC ports at full rate would slightly exceed one.
- Rear fan cutout size on the 4U chassis. If they're 120 mm rather than 80 mm, buy P12 Pros instead of P8 Maxes.
- Cooler clearance from motherboard tray to the nearest obstruction. 135 mm should clear, but the chassis publishes no maximum.
- GPU length against the front drive cage. The chassis doesn't publish a maximum card length either.
- SATA power connector count on the PSU. Eight drives means eight connectors, correctly spaced for the cage.
- Rack load rating on the VEVOR listing. VEVOR's own pages contradict each other — some say 200 lb, others 500 lb. Fully populated the rails carry roughly 243 lb, which is over one figure and well under the other. Day one is only ~125 lb, so this can wait — but settle it before the NAS and the second UPS go in. See the weight breakdown in the math.
- SSD price. $129.99 for 1 TB SATA is about double the going rate — and on the game server's SATA II controller, half the speed you're paying for is unreachable.
- Measure the FX-6300's stock cooler. It has to fit under roughly 70 mm. This is the one game-server dimension with no slack, and AM3+ low-profile replacements are scarce.
- Switch the game server's SATA controller to AHCI in BIOS. It currently runs in IDE mode, which costs NCQ and TRIM. Do it before the SSD is installed, and confirm the initramfs carries the
ahcimodule andfstabuses UUIDs — otherwise the box won't boot afterwards. - Read the model number off the back of the bedroom UPS. Its front reads “Back-UPS 1500”, not “Back-UPS Pro” — which is why the sheet no longer names a SKU. The BX1500M it was previously listed as may simply be wrong.
This is not pedantry about a label. The Pro BR series is pure sine, exactly like the office BR1000MS; everything else in the Back-UPS family is stepped. If that unit turned out to be a BR it would be the third pure-sine unit in the house and could legally carry a server — and if it is anything else, the standing rule holds and it must never see one. The wattage figure depends on the same answer. Two seconds with a torch settles it. - STL bounding box on Printables 948730 before slicing. A full-width 19″ panel is 483 mm and does not fit a 256 mm bed. One file with no makes means nobody has confirmed this.
- N2+ heatsink clearance in that mount, and EIA-310 hole spacing against the VEVOR posts.
- USB cable reach from U16 to the CyberPower at U3–4 and to the BR1000MS on the floor. Both are inside the 5 m USB limit, but confirm the actual lengths before the NUT wiring is dressed.
- Confirm the connector types for both UPS units. The CyberPower and the BR1000MS both use USB-B, so that is two USB-A→B cables and neither unit includes one.
- Set the microSD mitigations before the N2+ is racked — recorder purge, tmpfs logs, swap off, and the read-only-remount alert. Stage one runs on the card, so these are the difference between a card that lasts and one that doesn't.
- Add the read-only-remount alert to the N2+'s agent. Flash storage here exposes almost no SMART, so the practical signal is the classic death signature — ext4 remounting read-only. Alert on that, on free space, and on a heartbeat file failing to write. A card that has gone read-only will keep serving the NUT daemon from page cache for a surprisingly long time while silently recording nothing.
- When the eMMC lands: fit it with the card still in, confirm the target device by size in
lsblk— addto the wrongmmcblkwipes the running system — then write, expand and set boot order. Locate the board's microSD-boot override switch first; it is the escape hatch if the image is bad, and Petitboot in the 8 MB SPI flash is the second one. - USB port budget on the N2+. Four ports; two UPS cables and one Bluetooth dongle account for three. One stays free on both storage stages, since boot is never on USB.
- Read rack ambient at U16 and N2+ SoC temperature after a week in place, with the media server under load. This is the measurement that decides the fan question. Room temperature is not a substitute — the 4U exhausts below it in an open frame.
- Confirm the NAS chassis rails against the 24″ post spacing. The RackChoice ships 20″ sliding rails quoted for a 545 mm chassis in a 600 mm cabinet, which should sit comfortably inside 24″ — but confirm the rail's actual mounting range before ordering, because rack depth is the one thing the build order says you cannot change later. The Rosewill alternate is 25.6″ and would need the posts moved.
- Measure the shelf kit against 17.5″ before assuming two trays is enough. Three switches, the eero and the edge box come to roughly 24.5″ of width, which is why the network bay is two trays rather than one. The estimates here are from product photos, not calipers — if the real total passes ~35″ the bay needs a third tray, and the U for it has to come from somewhere.
- Check every NAS drive model for SMR before ordering. Shingled recording makes SnapRAID syncs take days and can stop a rebuild finishing at all, and it is almost never printed on the box or the listing — look the exact model number up against the manufacturer’s own CMR/SMR table. Family names do not settle it: WD Red below 8 TB is SMR while WD Red Plus is not.
- Fix the array’s maximum drive size before buying the first parity drive. Parity must be at least as large as the biggest data drive, so a single oversized drive added later forces a parity replacement as well. Decide the ceiling once and buy parity to it.
- Confirm the NAS board’s M.2 slot does not disable SATA ports. Many boards share bandwidth between the two. Here that would break the drive count outright — four onboard SATA plus eight on the HBA is exactly twelve, so losing two to the boot drive leaves the twelfth bay unconnectable. Check the board manual’s shared-bandwidth table, not the spec summary.
- Buy the HBA pre-flashed to IT mode, or budget the time to cross-flash it. In IR mode it presents RAID volumes and hides SMART, which breaks SnapRAID and blinds the panel’s drive alerts at the same time. Dell H310 and IBM M1015 cards are the same silicon at a lower price if you want the exercise.
- Pick the NAS board form factor before anything else for that box. The N100 plan cannot reach twelve bays — nine PCIe lanes, all spent, and no slot for an HBA. Decide mATX first, because it changes the board, the HBA, the NIC requirement and the power budget together.
- Check the NAS backplane connector type before buying the HBA. Twelve bays needs more than a 9211-8i’s eight ports — decide between a 16-port card and filling the last four from board SATA, and confirm the backplane is SFF-8087 rather than individual SATA.
Check the direction of the bundled cables, not just the connector. The RackChoice lists its three as reverse breakout — SFF-8087 to four SATA, which runs board SATA into a backplane. A reverse cable cannot drive drives from an HBA, and forward and reverse look identical in the bag. If the HBA needs forward breakout, that is a separate purchase. - Unbox the VEVOR before buying any shelf. Its contents list two trays — enough for both the APC and the network shelf, which would delete a purchase and a print. Measure the depth against the 14.5″ APC and check the load rating against its ~26 lb, because included shelves are built to a price and a shallow AV tray cantilevered off the front posts is the wrong place to learn that. Also confirm they are 4-post rather than 2-post cantilever.
- Does the Pi 4 boot? Edge box. This decides primary versus fallback, and it is the only question here that costs money to get wrong. Work the four causes in the edge box section before spending anything — underpowered supply, e-marked USB-C cable, corrupt card, corrupt bootloader EEPROM. Pull the card and power on: a patterned green ACT LED means the board is alive and the fault is storage, not hardware.
- Confirm the OS is 64-bit. Edge box.
uname -mmust returnaarch64, notarmv7l. Nginx Proxy Manager's maintained images are arm64, and a 32-bit install is far cheaper to reflash while the box is still blank than to discover afterwards. - Confirm the boot media. Edge box.
lsblkwith root onmmcblk0means microSD. Add a USB SSD or configurelog2rambefore it goes live — a proxy writes access logs continuously, which is exactly the workload that kills cards. - Cloudflare API token scoped and tested for the DNS-01 challenge, before adding the first proxy host. Edge box. With a proxied record, HTTP-01 cannot reach the box and issuance fails with an unhelpful error. On this DNS setup that is a certainty, not a risk.
- Profile the 705 before ordering anything for it. Misc server. Only worth doing once it has a job. RAM is already answered — 2× 8 GB, dual-channel, which was the blocking one. Two left, and one session settles both:
lscpu | grep 'Model name'sudo lspci | grep -i 'non-volatile\|network'
The CPU decides the multi-instance answer (4C/4T against 4C/8T), and one of the two listed M.2 slots may be a 2230 WLAN slot rather than a second NVMe — confirm before buying two drives. - Check the 705 has its 2.5″ drive caddy during teardown. Misc server. HP Desktop Minis configured M.2-only frequently shipped without the bracket and its SATA/power cable. It is a separate HP part, ~$15–25 used, and without it the AX2 has nowhere to mount — a drive ordered against a bay that cannot hold it. Check this in the same teardown as everything else.
- Check whether the OEM NVMe is still installed, before buying a boot drive. Misc server.
sudo nvme smart-log /dev/nvme0— a lowpercentage_usedmay remove the need to buy the P34A60 at all.
Build order
- Set rack depth to 24″ post-to-post and level it before anything goes in. Changing this later means re-hanging everything.
- Mount the rear cable brackets while the frame is empty. Reaching behind a loaded open frame with a driver is miserable and you'll skip half of them.
- Ground the rack with the included wire. Open frame plus metal chassis, two minutes, worth it.
- UPS in the bottom 2U. Heaviest mass lowest. Load it in place — the rack holds its rating stationary, not while rolling.
- Rails before servers, working bottom to top.
- Test the riser cards on the bench before the chassis goes in the rack. A flaky NIC you blame on drivers for an hour is usually the riser.
- Set the fan curve in BIOS before racking. First GPU load spike on an uncapped 80 mm at 5000 RPM is memorable for the wrong reason.
- Leave 6–8″ service loops per device so a chassis can slide out on its rails without unplugging. Route slack through the brackets, not around them.
- Put the two UPSes on separate wall circuits if the office has them. Two 1000 W units on one 15 A circuit is 1800 W of headroom against two that are hungriest at the same moment — running full load while recharging after an outage. Trivial to arrange now, annoying once the cords are dressed and the service loops are set.
- Rack the N2+ at U16, below the main switch. Set its microSD mitigations at the bench first — recorder purge, tmpfs logs, swap off, read-only-remount alert — because stage one runs on the card and those are what make it last. One blue patch up to main switch port 6, and a fixed DHCP lease by MAC so the NUT slaves have a stable name.
- Run both UPS data cables to the N2+. BR1000MS by USB, CyberPower by USB, both into the same box at U16. Both units use USB-B, so that is two USB-A→B cables and neither UPS includes one. A UPS nothing is listening to is just a surge strip with a battery in it.
- One NUT master, on the N2+. Two
usbhid-upsdriver instances, oneupsd, masterupsmon. All three servers run slaveupsmonpointed at it.
This replaces the earlier two-master arrangement, and it buys three things: one config to get right instead of two, with every server doing the identical thing; a master that outlives the things it shuts down, at 4 W on the BR1000MS rather than a master that is itself mid-shutdown; and it closes the gap this sheet already flagged — the cloud server's link no longer crosses the other UPS's switches to reach its master, so the "dead BR1000MS leaves the cloud server running blind" case disappears instead of being papered over with a timer. - Keep the loss-of-contact shutdown on all three slaves anyway. It is cheap, and the N2+ is now a single point of failure for the shutdown path. One master is simpler, not safer.
- The N2+ must not issue the outlet-kill for either UPS. Standard NUT ordering has the master cut power once the slaves are down — but the N2+ is not powered by the CyberPower at all, and it needs to stay up on the BR1000MS. Handle
POWERDOWNFLAGdeliberately: each server shuts itself down, and nothing tries to cut power to a UPS it isn't plugged into. - Set restore on AC power loss to Power On in every BIOS — Always On on the Gigabyte board, and ErP disabled there too. Not Last State: NUT shuts the machine down cleanly, so the last state is off and it stays off. Do this at the bench, before the chassis is racked and the setting means a monitor on the floor.
- Make NUT's shutdown end with
shutdown.return, so the UPS drops its outlets and re-energises when mains comes back. Without it, power returning before the battery is flat leaves the servers off — they never see the AC transition their BIOS is waiting for. Confirm each unit supports it first:upscmd -lshould list it. - Pull the plug on each UPS separately and watch what happens. An untested shutdown path is worse than none, because you will plan around it. Confirm all three boxes go down cleanly, then leave it unplugged until the outlets are dead and confirm they come back on their own. Stopping at "they shut down" only tests the half that was already easy — a server that shuts down but never returns has just moved the outage.
- Edge box — and do not cut over blind. Jellyfin is reachable today and stays reachable throughout. Troubleshoot the Pi 4 first, ordering the fallback only if it is genuinely dead; flash 64-bit to USB SSD; reserve its DHCP lease by MAC; deploy Nginx Proxy Manager in Docker with the admin UI on 81, LAN only and never forwarded; then get the Cloudflare API token and DNS-01 working and issue a test cert.
- Add Jellyfin as a proxy host and leave the eero forward alone. Test from the LAN by hitting the edge box directly with the hostname. Only once that works do you repoint the 443 forward and delete the Jellyfin one, then add Nextcloud and the Pterodactyl panel. Rollback is one line in the eero app — which is the entire reason for doing it in this order.
What the flags mean
Colour carries the urgency: green is settled, red needs an action before you order, brass is a judgement call with no deadline.
| Have | Already owned. No spend, but it still constrains the build around it. |
| Add | Not on the wishlist yet and the build doesn't work without it. These make up the "still needed" figure. |
| Price | Listed well above the going rate at the time it was flagged. Every one of these is now stale — NAND and DDR4 have risen sharply since, so re-check against current comparable parts rather than trusting the flag. See the pricing note in the math. |
| Stock | Low or single-unit availability. Decide sooner than the rest of the list. |
| Tight fit | Physically marginal. Measure the real part before ordering around it. |
| Test early | Known to fail intermittently. Bench it before the chassis is closed and racked. |
| Find a model | A printed part is needed but no design has been chosen yet. |
| Same case as game | Two machines are specced on one chassis. Buy two, or move one to the alternate. |
| Chosen | Decided. The option that gets bought where several were considered. |
| Not chosen | Considered and passed over. Kept on the sheet so the reasoning survives, and as a fallback. Not in any subtotal. |
| Only if needed | Do not buy preemptively. Bought only if a measurement says so — the row explains which one. |
| Second unit | Same model as one already listed elsewhere, bought again rather than shared. |
| Good pick | Checked and worth keeping. No action needed. |
| Planned | Priced and decided, but deliberately not a day-one buy. Sits outside the build total and gets its own tile at the top. |
| Monthly | A recurring cost, not a purchase. Sits outside the build total, which is one-time money, and carries its own tile at the top. |
| Decide | A choice that blocks other choices. Not a purchase yet — the row explains what it unlocks. |
| Likely included | The listing says it ships in the box, but it has not been unboxed and confirmed. Do not buy against it until it is in hand — and do not delete the line either. |
| Misc server | Belongs to the undecided EliteDesk box. Not bought or printed until that machine has a job. |
| Later | Wanted eventually, not decided. Sits outside every total — some hold a rack position, some carry a price, none are committed. |