Assume the following current state:
* 8GB RPi with proxmox
* a physical router is used to control network access (allowing access only to a whitelisted hosts, VPN killswitch, adblocking, DoT to upstream resolver, etc)
* RPi hosts lightweight LXCs from Community scripts (webdav-like for contacts/calendars, git, etc) without WAN access, LAN-only.
* RPi hosts wireguard server to provide access only to LAN clients (a requirement that came from limitations of connecting clients)
(*) a semi-technical user to maintain it, who has limited experience with home-grade networking equipment like mikrotik (older versions) and openwrt, but no opnsense/pfsense, ubiquity etc. Not afraid of CLI in general, but prefer GUI.
Intention: make the RPi self-sufficient for WAN access and traffic control so it can be run by connecting to a mobile or hotel hotspot wired or wireless.
What would be the best and most lightweight way to implement it so more juice is left for LXCs and VMs running on RPi?
Ideally, I would prefer to have flexibility to run couple of "virtual routers" per group of usage patterns, so some LXC can access internet via Tor, others - via VPN, etc. RPi host itself must also access network via one of them.
I know there is a number of networking-related community scripts for VM like MikroTik RouterOS, Unifi OS server or OpenWRT, and even guides for LXC OpenWRT https://forum.proxmox.com/threads/h...rsion-of-openwrt-and-run-it-on-proxmox.64786/. But I understand there may be more ways to implement it, also more lightweight.
Let's put aside question how to get RPi connected via WiFi or how to get clients connected via LAN to RPi's without controlled wifi router.
Portable router is an option, but less preferred.
* 8GB RPi with proxmox
* a physical router is used to control network access (allowing access only to a whitelisted hosts, VPN killswitch, adblocking, DoT to upstream resolver, etc)
* RPi hosts lightweight LXCs from Community scripts (webdav-like for contacts/calendars, git, etc) without WAN access, LAN-only.
* RPi hosts wireguard server to provide access only to LAN clients (a requirement that came from limitations of connecting clients)
(*) a semi-technical user to maintain it, who has limited experience with home-grade networking equipment like mikrotik (older versions) and openwrt, but no opnsense/pfsense, ubiquity etc. Not afraid of CLI in general, but prefer GUI.
Intention: make the RPi self-sufficient for WAN access and traffic control so it can be run by connecting to a mobile or hotel hotspot wired or wireless.
What would be the best and most lightweight way to implement it so more juice is left for LXCs and VMs running on RPi?
Ideally, I would prefer to have flexibility to run couple of "virtual routers" per group of usage patterns, so some LXC can access internet via Tor, others - via VPN, etc. RPi host itself must also access network via one of them.
I know there is a number of networking-related community scripts for VM like MikroTik RouterOS, Unifi OS server or OpenWRT, and even guides for LXC OpenWRT https://forum.proxmox.com/threads/h...rsion-of-openwrt-and-run-it-on-proxmox.64786/. But I understand there may be more ways to implement it, also more lightweight.
Let's put aside question how to get RPi connected via WiFi or how to get clients connected via LAN to RPi's without controlled wifi router.
Portable router is an option, but less preferred.
Last edited: