Infrastructure

17 Custom Zabbix checks every Linux Admin should have

Zabbix’s default templates cover the basics pretty well, but accepting only the defaults, puts you in the spectator seat: green or red, up or down, basic alerting. The moment you want to know in-depth why a server feels off, not just that something’s wrong, you’re on your own. As in yo can tweak and get more from Zabbix, but some efforts is required.

Hold your seat, I’ll explain myself.

This post covers the metrics I found myself missing, the problems that i faced once I started paying closer attention, and how I closed those gaps with a set of custom user parameters checks.

Necessity is the mother of invention

After posting my earlier project, where I pulled a small, open-source infrastructure out of a hat for a small business that had nothing and now has real infrastructure, some people reached out and started asking questions. One of those turned into a hands-down agreement on a job.

A tight budget and no Windows Domain

One of the people who reached out was a business owner I know personally. They run a small local company with about 10 Windows PCs, a few printers, one NAS, and a lot of sensitive data handled daily. Budget is tight, and the owner has no interest in cloud-based identity services like Azure AD or M365.

Building the Homelab Server: Hardware Choices and Why

Status: Running

As I said, the homelab project isn’t static. However, this is the current hardware snapshot, if you will.

Main server (custom build):

  • Case: Jonsbo N4, with a custom 3D-printed front intake for two extra fans, improving airflow and cooling for the HDD bay
  • CPU: Ryzen 5 5650G PRO APU (6C/12T). Specifically chose the PRO variant for ECC support
  • Cooler: Noctua NH-L9x65
  • Motherboard: ASRock B550 Pro4, known and proven to work with unbuffered ECC RAM
  • RAM: 2x 32 GB DDR4
  • Boot/OS drive: Crucial MX500 250 GB, running Proxmox VE
  • PVE storage: 1.8 TB Kioxia Exceria Plus G2 SSD
  • TrueNAS OS drive: WD SN730 1 TB, passed through to the TrueNAS VM
  • TrueNAS storage: 4x 4 TB Toshiba N300 HDDs, passed through to the TrueNAS VM
  • PSU: Seasonic Gold 550W, roughly 50W idle draw
  • NICs: Intel I225-V (vmbr0) and Intel I226-V (dedicated backup NIC, vmbr1). Both added after disabling the onboard Realtek chip, which proved unreliable on Proxmox and isn’t worth the risk in a real testing environment
  • HBA: LSI SAS2008, passed through to the TrueNAS VM
  • Zigbee: Sonoff USB MG24 controller, passed through to Home Assistant

Now I want to explain the rationale behind each hardware choice, so I decided to make this its own post. The main homelab writeup would get too large otherwise, and it’s easy to lose focus along the way.

My Homelab

Status: Running

Overview

I’m a firm believer in experience gained by breaking things, working through failures, and solving problems under real constraints, with real ownership of the decisions.

The homelab idea was introduced to me by r/homelab and a few other forums, including Tom Lawrence’s, a very technical community.

For context: my current setup is a rework of a previous build. Below I’ll detail the actual hardware choices, the struggles along the way, and the real-world constraints behind them.

I Got Paid in Groceries. Here's What I Built.

A small retailer asked me for help. They had nothing. No backups. No monitoring. No remote access. Budget: roughly zero, or a discount on groceries. They promised.

I said yes. Mostly because I like a good challenge. Partly because the groceries were decent.

What followed was one of the most honest projects I have worked on in years. No safety net. No team to escalate to. No budget for the right tool. Just me, a 12-year-old HP desktop gathering dust, and the question: what can actually be built with what is here?

SMB Infrastructure

Status: Completed

Overview

Two separate small-business engagements, both with essentially zero budget and no existing infrastructure. The first, paid partly in groceries, came first and proved the approach. It spurred the second: a mixed Windows/Linux environment for a second business, built on the same philosophy but with a wider scope.

The problem

Neither business had any of the basics most infrastructure takes for granted: backups that actually restore, visibility into what’s running, secure remote access, or any monitoring at all. Budget in both cases ruled out new hardware or commercial licensing.

Windows Firewall disabled on multiple hosts. Our monitoring never noticed the change

Windows Firewall disabled on multiple hosts. Our monitoring never noticed the change

A few months back while working with Zabbix for our mixed environment, I realized that the default Windows template doesn’t monitor whether Windows Firewall is actually enabled across its three zones (Domain, Private, and Public). There also wasn’t a straightforward way to see who was or still is logged into each Windows machine. For something as critical as firewall status, this felt like an important gap, so I came up with a two-fold solution: