LGM-OS documentation
8 min · 6 sections
All the NAS documentation, ordered by the moment you are going to need it. If you have just installed it, start with the administration guide; the rest are one-subject guides you only need when you face that particular topic.
Getting started
| Guide | What it is for |
|---|---|
| Installing the NAS from scratch | The very first thing, with screenshots of every screen: downloading the image, writing the USB stick on Windows, Mac or Linux, booting the machine from it and the installation —which asks nothing—. And what to do if the machine will not boot from the stick or something gets stuck. |
| Administration guide | Start with "The first ten minutes": the path from switching the machine on to having disks, folders, accounts and a backup that actually works. Then the day-to-day manual, subject by subject. If you only read one, read this one. |
| Install the panel as an app | The panel on your phone, tablet or computer with its own icon and no browser bar: your NAS certificate —the step almost everybody skips— and the two steps, device by device (iPhone, Android, Windows, Mac and Linux). And what each odd symptom means: the shortcut with no logo, the one that opens blank. |
| LGM Connect, the app | Your NAS in a window on your computer: the whole panel —the same apps, your permissions— plus what a web page cannot do. Your folders as just another drive (offline too), the NAS alerts in your notification centre and the cameras in their own window. Installing it, four ways to find your NAS and what to do when something will not connect. |
| Installing LGM Connect on iPhone | The app on your iPhone without the App Store: the .ipa signed by you with your own Apple ID and Sideloadly. The app-specific password, the "Trust" step everyone gets stuck on, why the signature lasts 7 days and how to renew it in a minute. And what this route does not give you: alerts. |
| If LGM-OS disappears | The question to ask before trusting your family photos to paid software written by one person: if the project stops, the source goes public and the licence check goes away. Plus what happens today if the server is down, what format your data is in, and what your NAS tells lgm-os.com. With the commands to check it yourself. |
| Connecting your devices | Making the NAS show up as just another folder on Windows, Mac, Linux, iPhone and Android: what to type on each one, which protocol to use for what, and why SMB is never published on the internet. |
| Users and permissions | Who sees what: the four layers (the account, the apps, the folders and the protocols), the three levels of each app, the Control Panel screen by screen, groups, and exactly what happens when you remove someone. |
| Project README | What LGM-OS is, how it installs from the ISO or on top of an existing Debian, how it updates (with no need to touch the code) and what its limitations are today. |
Guides by subject
| Guide | What it is for |
|---|---|
| Backups | Getting your data off the NAS before anything happens: which folders to copy, where to (a disk, another server over SSH or the cloud) and how often, how to authorise the SSH key of the remote destination step by step and —the one thing that is not optional— how to check by actually restoring that the backup works. |
| Ransomware protection | Making sure the backups are still there when somebody encrypts the NAS: what really protects you and what does not, the lock on snapshots (the only thing that stops them being deleted, even by root) and what to do in the first ten minutes if it has already happened. |
| Cameras | Video surveillance on the NAS itself: finding the cameras on your network over ONVIF, adding them by hand when they do not support it, how much disk each one eats and why you must not open its port on the router. |
| Access from the internet | Reaching the NAS from outside your home by publishing it with your own domain: DDNS with DuckDNS, a Let's Encrypt certificate, a reverse proxy per subdomain and the security checklist to meet before touching the router. |
| Network services | Turning the NAS into the centre of your network: a WireGuard VPN (the safest way in from outside, with nothing exposed), a DNS server with local names and a DHCP server. It includes how to get the network back if DHCP leaves you with no connection: read it before turning it on and keep it on your phone. |
| Disks, spares and replicas | Getting the most out of the disks once the volume exists: read cache, a hot spare that steps in on its own when another disk fails, a replica of the whole volume to another NAS, network disks (iSCSI) for Windows, Proxmox or VMware and the USB disks you plug in for a while. |
| Files | The whole file manager: preview of documents, photos and notes with nothing downloaded, instant search (inside files too), download links with expiry and password, requesting files from people without an account, the recycle bin shared with the PC and the versions kept by snapshots. |
| Gallery | Photos and videos in a timeline and albums without moving anything from its place: favourites, Live Photos, HEIC and RAW, duplicates, and every account sees only its own. |
| Documents | View any office document converted to PDF with nothing installed, and edit it in the browser with the editor that installs itself the first time — and never sees your disks. |
| Package Center and containers | Installing applications in one click and everything underneath: 31 in-house apps and more than 3,000 from the community, each app's ports and folders, advanced editing with automatic rollback, uninstalling knowing what happens to the data, logs, console and cleanup. |
| Virtual machines | Another computer inside the NAS, from the browser: installing it from its ISO, its screen, giving it its own IP with a bridge, snapshots with memory, growing the disk, handing it a USB device from the NAS and Windows 11's three conditions. |
| Home services | What almost everybody pays for elsewhere and fits in the machine that is already switched on: downloads (links, magnet and .torrent), the TV over DLNA, calendar and contacts against the NAS, a network printer and cloud sync. |
| Notepad | Writing on the NAS, not just storing things on it: edit any text file, the notebook of linked notes (with [[links]], a graph, tags and tasks) and the code editor with syntax highlighting for dozens of languages. |
| Watching over and defending the data | The six pieces that look after what is stored: previous versions inside Windows itself, who touched what, antivirus, a ransomware trap, country blocking and a weekly report. |
| Power | Switching the NAS off at night and having it come back by itself in the morning, Wake-on-LAN, putting the disks to sleep and the UPS — its own, the one it shares with the rest of the house, or another machine's. |
When something goes wrong
| Guide | What it is for |
|---|---|
| When something is not working | Ordered by what you see, not by what is broken: the panel will not open, I cannot see the NAS on the network, it is slow, a disk reports errors, I updated and something broke, the disk filled up, "The «…» setting was damaged" (and how to recover it when nobody can sign in). And what data makes a question answerable. |
| Disaster recovery | When it has already happened: failed disk, reinstalling while keeping the data, restoring from a snapshot or from the off-site backup. |
Reference
| Document | What it is for |
|---|---|
| Port reference | What listens on each port, who opens it and —the part that matters— which ones you may open on the router and which you never do. |
| Glossary | Every odd word in the panel and in these guides, in one sentence: RAID, snapshot, scrub, SMART, ACL, DDNS, Object Lock, token, WOL… |
| CHANGELOG | What changed in each version, with warnings for the ones that need attention when updating. |
| allowlist.py | The closed list of commands and paths the privileged process accepts. It is the source of truth about what the panel can and cannot do to the system. |
How to choose your remote access route
This is the decision that raises the most questions, and both guides read better once you know this:
- Only you and your own devices → the VPN in the network services guide. It publishes nothing on the internet: you open one UDP port on the router and from your phone or laptop you reach the whole local network, not just the panel. It is the safest option and the recommended one.
- Sharing with other people (family, guests, an app that has to be reachable without installing anything) → Access from the internet. It publishes the NAS with a valid certificate and Apache as the only exposed service, and it requires meeting that guide's security checklist first.
You can have both at once and they do not get in each other's way.
Conventions
- Commands starting with
sudoare run on the NAS console (physically, over SSH or from the web terminal in the panel). - Paths inside the panel are written
App → Section → Tab, for exampleControl Panel → VPN. - Blocks marked with ⚠️ describe operations that can leave you without access to the NAS or without a network. Read them in full before running them.