MrRowie — your friend and helper

The server concept that carries your business — from a frugal mini PC to an enterprise cluster. A trio of guardians maintains, monitors and protects it. Everything on‑premises, everything open source.

The concept

What is MrRowie?

Your own server instead of someone else's cloud — cared for as if your IT partner were always on site.

MrRowie is not an off‑the‑shelf device — MrRowie is a concept. A server stack built entirely from open source that runs on anything x86 or ARM. Preferably on frugal mini PCs (Minisforum & co.): quiet, a few watts — yet powerful enough as a full‑blown NAS replacement. And when you need more, the same concept scales to seriously beefy hardware as an enterprise cluster. Whatever the hardware — the system always stays the same: Proxmox with ZFS and automatic snapshots, Pangolin for secure access, plus MrsNanny, patch management and Wazuh. Built once, cared for the same way everywhere. And all of it is open source — no licence trap, no forced subscription, no fine print. It runs what you need every day: the file server, the private cloud for file sharing and calendars, your line‑of‑business applications — each role cleanly separated in its own virtual machine. Your data stays on your premises, not in someone else's cloud.

Coming from VMware? This is the complete replacement for enterprise virtualisation: high availability, snapshots, replication and backups are built in — with no licence fees, no subscription surprises, and in areas like snapshot depth and recovery even a step ahead.

The special part isn't the box — it's the built‑in care. Three guardians work together so you don't have to worry about a thing:

  • The safety net: automatic snapshots continuously preserve every state — an accidentally deleted file is back in minutes, not hours.
  • MrsNanny: watches around the clock, keeps the system up to date and alerts me before something breaks.
  • MrMiyagi: the sleeping backup — a second copy off site, out of any attacker's reach.
Three guardians

Care, built in

The safety net

The ZFS file system takes snapshots automatically. Someone deleted the wrong folder or overwrote a file? The state from an hour ago is still there — restoring takes minutes.

Snapshots are also replicated to a second disk: even a disk failure costs no data.

MrsNanny

Every night it checks disk space, updates, services, temperatures, backups and more — and writes a plain‑language report every morning. If something turns critical, it raises the alarm immediately, not at the end of the month.

Security updates are applied automatically. You notice only one thing: everything just works.

MrsNanny in detail — with video →

MrMiyagi — the sleeping backup

The backup server sits out of reach and is normally powered off. It wakes up on its own, fetches the backup, verifies it — and goes back to sleep.

Ransomware cannot encrypt what cannot be reached. Every backup run is reported by e‑mail.

MrMiyagi in detail →

What's in it for you:

  • Your data stays in‑house — no cloud dependency, no subscription trap.
  • 100% open source — no licence fees, no vendor lock‑in.
  • One contact person who built the system and sees it every day.
  • A status report every morning — you know it was checked, not just hoped.
  • Reachable on the go — if you want: individual services securely through an encrypted tunnel, with no open ports on your router.
  • AI, yes — but ours: reports are written by a local language model on our own hardware; no cloud service reads along.
For engineers — a look under the hood

From here on it gets technical: this is how MrRowie is built. All of it is open source and versioned in Git.

Under the hood

The foundation: Proxmox VE + ZFS

Proxmox VE (on steroids)

Virtualisation with VMs and LXC containers — every role isolated, hypervisor‑level backups, a web UI for the overview. But we never ship Proxmox as it comes from the factory — every install is sharpened from minute one:

  • ZFS ARC cache properly sized — storage and applications share RAM without fighting
  • Automatic ZFS snapshots from day one, individually tunable per data area
  • The entire system configuration (/etc) is continuously backed up alongside
  • SSH access hardened out of the box
  • … and much more, reproducible by script

GitHub →

pve-zfs-tool

Scheduled ZFS snapshots with retention rules and replication — plus a dashboard that makes gaps visible instead of hiding them.

On top of that, full host disaster recovery: the entire PVE root configuration is backed up too (/etc/pve, network, package sources, SSH, firewall, ZFS properties), with a guided four‑phase restore all the way back to the guest configs — a destroyed hypervisor is no longer a rebuild.

GitHub →

zamba-lxc-toolbox

Ready‑made, hardened LXC roles for the classics: Samba file server and Active Directory, Nextcloud & co. — set up reproducibly instead of hand‑crafted.

GitHub →

Private AI

It works without the big providers.

Personal data can be processed in-house — with AI on your own hardware.

Every morning, a language model summarises the state of the systems in plain language — written by Ollama on your own hardware, not by a cloud service. No log, no hostname, no personal data leaves the house for it, and no corporation trains on your business data. And because the AI runs locally, it keeps working even when the internet does not.

Our principle: everything we use, we also host ourselves — or you do. Whichever way you want it. The whole system is built for admins and IT service providers who want their tools in their own hands — open source, documented, on your hardware. And us? We are the Miyagis who teach you how.

We do not demonise the cloud — we use both worlds where it makes sense. But the order of priorities is non-negotiable: data protection comes first. Wherever personal data is involved, processing happens in-house — with tools that belong to you, not to a provider whose business is analysing your data.

Security

The security layer: Wazuh

Alongside health, a second, independent layer watches over security: Wazuh collects logs and security events from all systems (including firewalls), detects attacks and anomalies and reports what matters in real time. The entire rule configuration is versioned — with a deliberate noise policy: routine is counted quietly, real incidents come through immediately. An alarm stays an alarm — instead of drowning in a hundred trivialities.

Remote access

Securely reachable — if you want it

By default, MrRowie is invisible from the outside. If individual services (e.g. the private cloud) should be reachable on the go, Newt together with a Pangolin gateway takes over: the mini server establishes an outgoing, encrypted WireGuard tunnel to the gateway — not a single port is opened on your router. Only what should be published gets published, service by service, optionally with an additional login in front.

The gateway itself is protected by CrowdSec with an enterprise licence: attack patterns are detected and attackers are banned automatically — backed not just by the community blocklist but by the full premium and third‑party blocklists with real‑time attack alerts. Add the usual layers from automatic TLS certificates to strict separation of the published services.

Contact

Interested?

Whether as a managed server for your business or a tech talk among colleagues — get in touch.

Get in touch