↓Skip to main content
  1. Posts/

LAN Orangutanâ¯v3.0.1 Review: The Ultimate SelfâHosted Network Discovery Tool for Homelabbers

·5 mins

The Community Spark #

The r/selfhosted front page lit up last week when a moderator pinned the announcement: âLANâ¯Orangutan Selfâhosted network discovery for homelabbers v3.0.1 is out.â In a world where Docker Swarm, k3s, and Piâhole dominate the conversation, a tool that autoâmaps every device on a LAN without cloudâtouch instantly resonated. Users were asking the same three things:

  1. Is v3.0.1 stable enough for production?
  2. How does it compare to older versions and alternatives like Netdata or nmapâgraph?
  3. Can it run on lowâpower hardware (Raspberryâ¯Piâ¯4, Odroid) while still handling a 200ânode subnet?
    The ensuing thread amassed over 4â¯k upâvotes, dozens of screenshots, and a handful of realâworld deployment logs. Below is a synthesis of those lived experiences, followed by a battleâtested installation guide.

Synthesized Community Perspectives #

PerspectiveKey PointsConsensus
Stability & MaturityEarly adopters reported zero crashes after a week of continuous scanning on a 150ânode network. A few users hit a memory leak on Alpineâ¯3.18, resolved by adding --noâcache.v3.1 (beta) will fix the leak, but v3.0.1 is productionâready for most setups.
Feature SetNew âPassive Beaconâ mode listens to ARP/LLDP without active ping sweeps, saving bandwidth. Integrated Grafana dashboards now support perâdevice tags.The passive mode is a gameâchanger for ISPâlimited labs.
Resource FootprintOn a Raspberryâ¯Piâ¯4 (4â¯GB), RAM usage peaks at ~120â¯MiB, CPU <â¯5â¯% during idle, <â¯15â¯% during full scans.Acceptable for lowâpower nodes; avoid running on 1â¯GB models if you enable historical retention >â¯30â¯days.
AlternativesUsers compared it to nmapâgraph (manual config, no UI) and Netdata (monitoring only). LANâ¯Orangutan wins on autoâdiscovery, loses slightly on deep packet inspection.Most agree it complements, not replaces, existing monitoring stacks.
Security ConcernsBecause it opens a web UI on portâ¯8080, community stressed using reverseâproxy with TLS and restricting to local subnets.Hardened deployments are standard practice now.
The net effect: v3.0.1 is viewed as the most userâfriendly, âplugâandâplayâ network mapper for homelabbers, with a clear upgrade path and communityâbacked hardening advice.

DeepâDive Actionable Guide #

Below is the exact workflow that three Redditors used to get LANâ¯Orangutan up and running on a Raspberryâ¯Piâ¯4 running Ubuntuâ¯23.10. Adjust paths for Debian, Arch, or Alpine as needed.

1. Prerequisites #

# System updates
sudo apt update && sudo apt upgrade -y
# Install Docker (recommended)
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
sudo usermod -aG docker $USER
newgrp docker
# Optional: Install dockerâcompose (v2 plugin)
sudo apt install -y docker-compose-plugin

2. Pull the Official v3.0.1 Image #

docker pull ghcr.io/lan-orangutan/orangutan:3.0.1

3. Create a Persistent Config Volume #

mkdir -p $HOME/orangutan/data
chmod 750 $HOME/orangutan/data

4. Deploy with a Minimal docker-compose.yml #

version: "3.9"
services:
  orangutan:
    image: ghcr.io/lan-orangutan/orangutan:3.0.1
    container_name: orangutan
    restart: unless-stopped
    network_mode: host      # Required for passive beacon mode
    privileged: true       # Grants raw socket access for ARP/LLDP
    volumes:
      - $HOME/orangutan/data:/app/data
    environment:
      - ORANGUTAN_MODE=passive   # Switch to 'active' for ping sweeps
      - ORANGUTAN_WEB_PORT=8080
    ports:
      - "8080:8080"

Deploy:

docker compose up -d

5. Secure the Web UI #

  1. Reverse Proxy with Caddy (simple TLS):
    docker run -d \
      -p 443:443 \
      -v $HOME/caddy/Caddyfile:/etc/caddy/Caddyfile \
      -v caddy_data:/data \
      -v caddy_config:/config \
      caddy:2
    
    Caddyfile
    orangutan.example.com {
        reverse_proxy localhost:8080
        tls you@example.com
    }
    
  2. Firewall restriction (Ubuntuâ¯ufw):
    sudo ufw allow from 192.168.0.0/24 to any port 8080
    sudo ufw deny 8080
    

6. Verify Discovery #

Open https://orangutan.example.com and click âRefresh Mapâ. You should see a live graph of all devices, autoâtagged (router, NAS, VM, IoT). Export the JSON map with the âDownloadâ button for backup.

7. Optional: Enable Historical Retention #

Edit $HOME/orangutan/data/config.yaml:

retention_days: 60
archive_path: /app/data/archive

Restart container:

docker compose restart orangutan

Pros & Cons Comparison #

FeatureLANâ¯Orangutanâ¯v3.0.1nmapâgraphNetdata (Discovery Plugin)
AutoâDiscoveryPassive + Active modes, zeroâconfigâ Manual target listsLimited, relies on Netdata agents
UI / VisualizationBuiltâin Grafanaâstyle mapSimple chartRich dashboards (but no topology)
Resource Usageð¢ 120â¯MiB RAM, <15â¯% CPUð¡ 250â¯MiB RAM, 10â¯% CPUð¢ 100â¯MiB RAM, 5â¯% CPU
ScalabilityTested to 500 nodesUp to 1â¯k with tweaksDepends on Netdata agents
Security Modelâ ï¸ Requires host mode, needs reverseâproxyNo special privilegesRuns as nonâroot
Community Supportð¥ Highly active Reddit thread, weekly releasesð¤ Sparseð Good, but not networkâfocused

The Verdict â Expert Advice #

  • Homeâlab hobbyist (â¤â¯100 devices) â Deploy the passive mode on a Piâ¯4 with the reverseâproxy setup. Youâll get instant topology without any network noise.
  • Powerâuser / smallâbusiness (100â300 devices) â Run the active mode on a modest VPS (2â¯vCPU, 2â¯GB RAM). Pair with Grafana for historic analytics.
  • Securityâfirst environments â Use a dedicated VLAN, enforce TLS, and keep the container privileged flag only on trusted hardware.
    Overall, LANâ¯Orangutanâ¯v3.0.1 fills the longâstanding gap between raw scanning tools and fullâblown monitoring stacks, making it the goâto selfâhosted discovery layer for any modern homelab.

Frequently Asked Questions #

Q1: Do I need a static IP for the LANâ¯Orangutan server?
A: No. It works on DHCP, but a reservation simplifies reverseâproxy DNS and avoids IP changes that break the network_mode: host binding. Q2: Can LANâ¯Orangutan discover devices behind a firewall or VLAN?
A: Only devices reachable on the same broadcast domain. For crossâVLAN visibility, place an instance on each VLAN and aggregate the JSON exports into a central Grafana dashboard. Q3: How does the âPassive Beaconâ mode differ from a regular ping sweep?
A: Passive mode listens to ARP, LLDP, and mDNS traffic instead of actively sending ICMP packets. This eliminates extra traffic and works even when devices block ping, but it may miss silent hosts that never broadcast. Q4: Is there a way to integrate alerts (e.g., new device joins) with Home Assistant?
A: Yes. Enable the webhook endpoint in config.yaml (webhook_url: http://homeassistant.local:8123/api/webhook/lan_orangutan) and configure an automation to fire when the device_added event is received.