MrRowie — Ihr Freund und Helfer
Das Server‑Konzept, das Ihren Betrieb trägt — vom sparsamen Mini‑PC bis zum Enterprise‑Cluster. Ein Wächter‑Trio pflegt, überwacht und sichert es. Alles im Haus, alles Open Source.
Unverbindlich anfragenWas ist MrRowie?
Ihr eigener Server statt fremder Cloud — betreut, als wäre Ihr IT‑Betreuer immer im Haus.
MrRowie ist kein Gerät von der Stange — MrRowie ist ein Konzept. Ein komplett aus Open Source gebauter Server‑Stack, der auf allem läuft, was x86 oder ARM ist. Am liebsten auf sparsamen Mini‑PCs (Minisforum & Co.): leise, wenige Watt — und trotzdem mächtig genug als vollwertiger NAS‑Ersatz. Und wenn es mehr sein muss, skaliert dasselbe Konzept auf richtig fetter Hardware zum Enterprise‑Cluster. Und egal auf welcher Hardware — das System bleibt immer dasselbe: Proxmox mit ZFS und Autosnapshots, Pangolin für den sicheren Zugriff, dazu Server‑Nanny, Patch‑Management und Wazuh. Einmal gebaut, überall gleich betreut. Und alles davon ist Open Source — keine Lizenzfalle, kein Zwangs‑Abo, kein Kleingedrucktes. Darauf läuft, was Sie täglich brauchen: der Fileserver, die private Cloud für Dateiaustausch und Termine, Ihre Branchenanwendungen — jede Aufgabe sauber getrennt in einer eigenen virtuellen Maschine. Ihre Daten liegen bei Ihnen im Haus, nicht in einer fremden Cloud.
Wer von VMware kommt, findet hier den vollständigen Ersatz für die Enterprise‑Virtualisierung: Hochverfügbarkeit, Snapshots, Replikation und Backups sind eingebaut — ohne Lizenzkosten, ohne Abo‑Überraschungen, und in Punkten wie Snapshot‑Tiefe und Wiederherstellung sogar einen Schritt voraus.
Das Besondere ist nicht die Kiste — es ist die Betreuung, die eingebaut ist. Drei Wächter arbeiten zusammen, damit Sie sich um nichts kümmern müssen:
- Das Sicherheitsnetz: automatische Momentaufnahmen (Snapshots) halten laufend jeden Stand fest — eine versehentlich gelöschte Datei ist in Minuten zurück, nicht erst nach Stunden.
- Die Server‑Nanny: überwacht rund um die Uhr, hält das System aktuell und meldet sich bei mir, bevor etwas ausfällt.
- Miyagi: das schlafende Backup — eine zweite Sicherung außer Haus, für Angreifer unerreichbar.
Eingebaute Betreuung
Das ZFS‑Dateisystem legt automatisch Momentaufnahmen an. Jemand hat den falschen Ordner gelöscht oder eine Datei überschrieben? Der Stand von vor einer Stunde ist noch da — zurückholen dauert Minuten.
Die Snapshots wandern zusätzlich per Replikation auf eine zweite Platte: selbst ein Plattenausfall kostet keine Daten.
Jede Nacht prüft sie Speicherplatz, Updates, Dienste, Temperatur, Backups und mehr — und schreibt jeden Morgen einen Bericht in verständlichem Deutsch. Wird etwas kritisch, schlägt sie sofort Alarm, nicht erst am Monatsende.
Sicherheitsupdates spielt sie automatisch ein. Sie merken davon nur eines: dass alles läuft.
Der Sicherungsserver steht außer Reichweite und ist normalerweise ausgeschaltet. Er wacht von selbst auf, holt sich die Datensicherung, prüft sie — und legt sich wieder schlafen.
Erpressungstrojaner können nicht verschlüsseln, was gar nicht erreichbar ist. Über jede Sicherung kommt ein Bericht per E‑Mail.
Was Sie davon haben:
- Ihre Daten bleiben im Haus — keine Cloud‑Abhängigkeit, keine Abo‑Falle.
- 100 % Open Source — keine Lizenzkosten, kein Vendor‑Lock‑in.
- Ein Ansprechpartner, der die Anlage gebaut hat und sie täglich sieht.
- Jeden Morgen ein Statusbericht — Sie wissen, dass geprüft wurde, nicht nur gehofft.
- Von unterwegs erreichbar — auf Wunsch: einzelne Dienste sicher über einen verschlüsselten Tunnel, ganz ohne offene Ports am Router.
Ab hier wird es technisch: so ist MrRowie gebaut. Alles davon ist Open Source und versioniert in Git.
Die Basis: Proxmox VE + ZFS
Virtualisierung mit VMs und LXC‑Containern — jede Rolle isoliert, Backups auf Hypervisor‑Ebene, Web‑UI für den Überblick. Bei uns kommt Proxmox aber nie ab Werk — jede Installation wird von der ersten Minute an nachgeschärft:
- ZFS‑ARC‑Cache sauber dimensioniert — Speicher und Anwendungen teilen sich den RAM ohne Gerangel
- Automatische ZFS‑Snapshots ab Tag eins, pro Datenbereich individuell einstellbar
- Die komplette Systemkonfiguration (/etc) wird laufend automatisch mitgesichert
- SSH‑Zugang ab Werk gehärtet
- … und vieles mehr, reproduzierbar per Script
Automatische ZFS‑Snapshots samt Aufbewahrungsregeln und Replikation — mit Dashboard, das Lücken sichtbar macht statt sie zu verstecken.
Dazu komplettes Host‑Disaster‑Recovery: gesichert wird auch die gesamte PVE‑Root‑Konfiguration (/etc/pve, Netzwerk, Paketquellen, SSH, Firewall, ZFS‑Properties), Restore in vier geführten Phasen bis zurück zu den Gast‑Configs — ein zerstörter Hypervisor ist kein Neuaufbau mehr.
Fertige, gehärtete LXC‑Rollen für die Klassiker: Samba‑Fileserver und Active‑Directory, Nextcloud & Co. — reproduzierbar aufgesetzt statt handgeklöppelt.
Die Server‑Nanny: Pull, nicht Push
Ein dünner Sensor auf der Node, die Intelligenz am Master — und jeden Morgen ein Klartext‑Report vom lokalen Sprachmodell. Ohne Cloud.
Der Master zieht die Messdaten per restricted SSH‑Key (forced command). Die Kunden‑Node baut nie eine Verbindung nach außen auf — sie braucht weder VPN noch offene Ports.
Auf der Node läuft nur ein Runner, der Collector‑Scripts einsammelt und ein JSON bereitlegt. Bewertung, KI‑Zusammenfassung, HTML‑Mail und Trend‑Historie passieren zentral am Master.
Jeder Collector liefert seine eigene Ampel (green/yellow/red) mit. Ein neuer
Sensor ist ein Script in collectors.d/ — er erscheint
im nächsten Report, ohne dass der Master ihn kennen muss.
An Bord: 10 Collectoren + 2 Scanner, beliebig erweiterbar —
Alarmierung in zwei Ebenen: Wird ein kritischer Sensor rot (Platte voll, Internet eingebrochen), mailt die Node sofort selbst — autark, auch wenn der Master gerade nicht lebt. Jeden Morgen zieht der Master zusätzlich alle Standorte, bildet je Node ein Ampel‑Verdict und lässt ein lokal laufendes Sprachmodell den Tagesbericht je Kunde formulieren — als HTML‑Mail mit Detail‑PDF. Ist eine Node beim Pull nicht erreichbar, ist genau das der Alarm: „keine Daten" ist selbst ein Befund.
Berichtswesen: aus derselben Trend‑Historie entstehen Monatsberichte für die Geschäftsführung, ein Report‑Archiv und eine Flotten‑Webübersicht mit Ampel‑Verlauf pro Gerät.
Nicht nur melden, sondern beheben: automatische Security‑Updates flottenweit und wöchentliche Nextcloud‑Pflege samt Status‑Snapshot gehören dazu.
Das ausführliche Prospekt zum Mitnehmen — 15 Seiten Architektur, Collectoren, Alarmierung und Security‑Layer:
Der Security‑Layer: Wazuh
Neben der Gesundheit wacht ein zweiter, unabhängiger Layer über die Sicherheit: Wazuh sammelt Logs und Sicherheitsereignisse aller Systeme (inklusive Firewalls), erkennt Angriffe und Auffälligkeiten und meldet Wichtiges in Echtzeit. Die gesamte Regel‑Konfiguration ist versioniert — mit einer bewussten Rausch‑Politik: Routine wird leise gezählt, echte Vorfälle kommen sofort durch. So bleibt ein Alarm ein Alarm — und geht nicht in hundert Belanglosigkeiten unter.
Sicher erreichbar — wenn man das will
Standardmäßig ist MrRowie von außen unsichtbar. Sollen einzelne Dienste (z. B. die private Cloud) von unterwegs erreichbar sein, übernimmt das Newt zusammen mit einem Pangolin-Gateway: Der Mini‑Server baut einen ausgehenden, verschlüsselten WireGuard‑Tunnel zum Gateway auf — am Router wird kein einziger Port geöffnet. Veröffentlicht wird nur, was veröffentlicht werden soll, Dienst für Dienst, auf Wunsch mit zusätzlichem Login davor.
Das Gateway selbst steht unter CrowdSec‑Schutz mit Enterprise‑Lizenz: Angriffsmuster werden erkannt und Angreifer automatisch ausgesperrt — gestützt nicht nur auf die Community‑Blockliste, sondern auf die vollen Premium‑ und Dritt‑Blocklisten samt Echtzeit‑Angriffsalarmen. Dazu kommen die üblichen Schutzschichten vom automatischen TLS‑Zertifikat bis zur strikten Trennung der veröffentlichten Dienste voneinander.
Miyagi im Detail
Trojanersicher. Mehrstufig. Zukunftssicher.
Miyagi ist die Offsite‑Sicherung mit minimaler Angriffsfläche: Der Backup‑Server ist die meiste Zeit ausgeschaltet und wird per Wake‑on‑LAN geweckt. Nach dem Start läuft alles automatisch: Er verbindet sich zum Produktivsystem und zieht die ZFS‑Snapshots zu sich (Pull — das Produktivsystem hat keinerlei Zugang zum Backup‑Ziel), einmal pro Woche kommt zusätzlich ein Proxmox‑Backup‑Server‑Lauf dazu. Danach wird verifiziert, per E‑Mail berichtet — und der Server legt sich wieder schlafen.
Das Ergebnis: Selbst wer das Produktivsystem vollständig übernimmt, kann die Backups weder löschen noch verschlüsseln — das Ziel ist schlicht nicht erreichbar.
Interesse?
Ob als betreuter Server für Ihren Betrieb oder als Technik‑Gespräch unter Kollegen — melden Sie sich.
Kontakt aufnehmenMrRowie — your friend and helper
The server concept that carries your business — from a frugal mini PC to an enterprise cluster. A trio of guardians maintains, monitors and protects it. Everything on‑premises, everything open source.
Get in touchWhat is MrRowie?
Your own server instead of someone else's cloud — cared for as if your IT partner were always on site.
MrRowie is not an off‑the‑shelf device — MrRowie is a concept. A server stack built entirely from open source that runs on anything x86 or ARM. Preferably on frugal mini PCs (Minisforum & co.): quiet, a few watts — yet powerful enough as a full‑blown NAS replacement. And when you need more, the same concept scales to seriously beefy hardware as an enterprise cluster. Whatever the hardware — the system always stays the same: Proxmox with ZFS and automatic snapshots, Pangolin for secure access, plus the Server Nanny, patch management and Wazuh. Built once, cared for the same way everywhere. And all of it is open source — no licence trap, no forced subscription, no fine print. It runs what you need every day: the file server, the private cloud for file sharing and calendars, your line‑of‑business applications — each role cleanly separated in its own virtual machine. Your data stays on your premises, not in someone else's cloud.
Coming from VMware? This is the complete replacement for enterprise virtualisation: high availability, snapshots, replication and backups are built in — with no licence fees, no subscription surprises, and in areas like snapshot depth and recovery even a step ahead.
The special part isn't the box — it's the built‑in care. Three guardians work together so you don't have to worry about a thing:
- The safety net: automatic snapshots continuously preserve every state — an accidentally deleted file is back in minutes, not hours.
- The Server Nanny: watches around the clock, keeps the system up to date and alerts me before something breaks.
- Miyagi: the sleeping backup — a second copy off site, out of any attacker's reach.
Care, built in
The ZFS file system takes snapshots automatically. Someone deleted the wrong folder or overwrote a file? The state from an hour ago is still there — restoring takes minutes.
Snapshots are also replicated to a second disk: even a disk failure costs no data.
Every night it checks disk space, updates, services, temperatures, backups and more — and writes a plain‑language report every morning. If something turns critical, it raises the alarm immediately, not at the end of the month.
Security updates are applied automatically. You notice only one thing: everything just works.
The backup server sits out of reach and is normally powered off. It wakes up on its own, fetches the backup, verifies it — and goes back to sleep.
Ransomware cannot encrypt what cannot be reached. Every backup run is reported by e‑mail.
What's in it for you:
- Your data stays in‑house — no cloud dependency, no subscription trap.
- 100% open source — no licence fees, no vendor lock‑in.
- One contact person who built the system and sees it every day.
- A status report every morning — you know it was checked, not just hoped.
- Reachable on the go — if you want: individual services securely through an encrypted tunnel, with no open ports on your router.
From here on it gets technical: this is how MrRowie is built. All of it is open source and versioned in Git.
The foundation: Proxmox VE + ZFS
Virtualisation with VMs and LXC containers — every role isolated, hypervisor‑level backups, a web UI for the overview. But we never ship Proxmox as it comes from the factory — every install is sharpened from minute one:
- ZFS ARC cache properly sized — storage and applications share RAM without fighting
- Automatic ZFS snapshots from day one, individually tunable per data area
- The entire system configuration (/etc) is continuously backed up alongside
- SSH access hardened out of the box
- … and much more, reproducible by script
Scheduled ZFS snapshots with retention rules and replication — plus a dashboard that makes gaps visible instead of hiding them.
On top of that, full host disaster recovery: the entire PVE root configuration is backed up too (/etc/pve, network, package sources, SSH, firewall, ZFS properties), with a guided four‑phase restore all the way back to the guest configs — a destroyed hypervisor is no longer a rebuild.
Ready‑made, hardened LXC roles for the classics: Samba file server and Active Directory, Nextcloud & co. — set up reproducibly instead of hand‑crafted.
The Server Nanny: pull, not push
A thin sensor on the node, the intelligence on the master — and every morning a plain‑language report from a local language model. No cloud involved.
The master pulls the metrics via a restricted SSH key (forced command). The customer node never opens a connection to the outside — it needs neither a VPN nor open ports.
The node only runs a small runner that collects collector scripts and prepares one JSON. Evaluation, AI summary, HTML mail and trend history all happen centrally on the master.
Every collector ships its own traffic light (green/yellow/red). A new
sensor is one script in collectors.d/ — it shows
up in the next report without the master having to know it.
On board: 10 collectors + 2 scanners, extensible at will —
Two levels of alerting: if a critical sensor turns red (disk full, internet degraded), the node mails immediately by itself — self‑sufficient, even if the master is down. Every morning the master additionally pulls all sites, forms a traffic‑light verdict per node and has a locally running language model write the daily report per customer — an HTML mail with a detail PDF. If a node is unreachable during the pull, that is the alert: "no data" is a finding in itself.
Reporting: the same trend history feeds monthly management reports, a report archive and a fleet web overview with per‑device history.
Not just reporting — fixing: fleet‑wide automatic security updates and weekly Nextcloud maintenance with status snapshots are part of the package.
The full brochure to take away — 15 pages of architecture, collectors, alerting and the security layer:
The security layer: Wazuh
Alongside health, a second, independent layer watches over security: Wazuh collects logs and security events from all systems (including firewalls), detects attacks and anomalies and reports what matters in real time. The entire rule configuration is versioned — with a deliberate noise policy: routine is counted quietly, real incidents come through immediately. An alarm stays an alarm — instead of drowning in a hundred trivialities.
Securely reachable — if you want it
By default, MrRowie is invisible from the outside. If individual services (e.g. the private cloud) should be reachable on the go, Newt together with a Pangolin gateway takes over: the mini server establishes an outgoing, encrypted WireGuard tunnel to the gateway — not a single port is opened on your router. Only what should be published gets published, service by service, optionally with an additional login in front.
The gateway itself is protected by CrowdSec with an enterprise licence: attack patterns are detected and attackers are banned automatically — backed not just by the community blocklist but by the full premium and third‑party blocklists with real‑time attack alerts. Add the usual layers from automatic TLS certificates to strict separation of the published services.
Miyagi in detail
Ransomware-proof. Multi-layered. Future-proof.
Miyagi is the off‑site backup with a minimal attack surface: the backup server is powered off most of the time and woken via Wake‑on‑LAN. After boot, everything runs automatically: it connects to the production system and pulls the ZFS snapshots (pull — the production system has no access whatsoever to the backup target), and once a week a Proxmox Backup Server run is added. Then everything is verified, reported by e‑mail — and the server goes back to sleep.
The result: even someone who fully compromises the production system can neither delete nor encrypt the backups — the target simply cannot be reached.
Interested?
Whether as a managed server for your business or a tech talk among colleagues — get in touch.
Get in touch