

Oh yeah and I did enable Proxmox VM firewall for the TrueNAS, the NFS traffic goes via an internal interface. Wasn’t entirely convinced by NFS’s security posture when reading about it… At least restrict it to the physical machine 0_0 So I now need to intentionally pass a new NIC to any VM that will access the data, which is neat.
Something to consider, advice given to me, is that ZFS support on Linux regularly breaks with newest kernels so if you go for ZFS long term, be prepared to run a lts kernel at least as a backup.
I use both. LUKS+btrfs being nice on the Arch desktops, and ZFS on a serverside pool, managed by a TrueNAS Scale VM.