fleet: re-frame SureFire hosts from tenant-only to PFI-managed
Initial framing was wrong. PFI runs these under a managed-hosting agreement: SSH, OS ops, backups are all PFI's responsibility. Hardware and data belong to the client. Changes: - ssh-target files added for sfsrv-ana (root@10.250.250.115 — same pattern as other PVE nodes) and sf-ana-container (lkraven@10.250.150.100 guess, adjust if different user). - sf-r630 still lacks an ssh-target — the OS-side LAN IP isn't in FortiGate DHCP (static config somewhere). Will fill in once identified; README flags that gap. - READMEs rewritten: dropped "tenant-scoped" / "not SSH-managed" language, added "client context" section that explains the managed-hosting relationship. Backup coverage now listed as planned rather than blocked on tenant coordination. - CLAUDE.md fleet table: SF rows re-labeled "SureFire client (PFI-managed)". Placement-rules section updated to note that SF hosts are first-class PFI-ops targets, just client-owned. - Memory (project_surefire_tenant.md) rewritten to reflect managed-services reality + hosts-file entries needed for name resolution since these aren't in PFI DNS.
This commit is contained in:
@@ -1,35 +1,46 @@
|
||||
# sf-ana-container
|
||||
|
||||
**SureFire tenant workload** at the Anaheim colo — a container
|
||||
host/VM running on the SureFire Proxmox (`sfsrv-ana`, 10.250.250.115).
|
||||
SureFire-client container workload running on `sfsrv-ana` (SureFire's
|
||||
Proxmox at 10.250.250.115). **PFI-managed** under the hosting
|
||||
agreement.
|
||||
|
||||
## Tenancy
|
||||
## Client context
|
||||
|
||||
- **Owner:** SureFire (tenant)
|
||||
- **PFI role:** hosting provider
|
||||
- **Management scope:** coordinate with SureFire before any action
|
||||
- **Client:** SureFire
|
||||
- **PFI role:** full-service managed host
|
||||
|
||||
## Network
|
||||
|
||||
- **LAN IP:** 10.250.150.100
|
||||
- **SSH:** not wired — tenant equipment.
|
||||
- **FQDN:** not in DNS yet — add to workstation `/etc/hosts`:
|
||||
```
|
||||
10.250.150.100 sf-ana-container
|
||||
```
|
||||
- **SSH:** `lkraven@10.250.150.100` (guess — adjust if a different
|
||||
user owns the container's ssh config)
|
||||
|
||||
## Infrastructure
|
||||
|
||||
- **Hypervisor:** `sfsrv-ana` (SureFire Proxmox, 10.250.250.115)
|
||||
- **Site:** Anaheim (PFI colo)
|
||||
- **Subnet:** `10.250.150.0/24` — dedicated SureFire container subnet
|
||||
- **Subnet:** `10.250.150.0/24` — dedicated SF container subnet
|
||||
|
||||
## Role
|
||||
|
||||
Container/workload host for SureFire. Specific services aren't
|
||||
documented here (not PFI equipment).
|
||||
Container/VM workload for SureFire. Specific services TBD — refresh
|
||||
the server-info snapshot once SSH is verified:
|
||||
|
||||
```bash
|
||||
scripts/refresh-server-info.sh sf-ana-container
|
||||
```
|
||||
|
||||
## Backup coverage
|
||||
|
||||
- **Not currently backed up by the PFI fleet.** Needs coverage plan —
|
||||
see `servers/sfsrv-ana/README.md` for the three approaches under
|
||||
discussion.
|
||||
- **VM-image via sfsrv-ana vzdump:** status unknown — depends on what
|
||||
backup jobs are configured on that Proxmox. Audit via
|
||||
`scripts/refresh-proxmox-info.sh sfsrv-ana`.
|
||||
- **File-level restic:** not yet configured — worth adding once we
|
||||
know what state the container runs (DBs, configs, app data).
|
||||
|
||||
## Discovered via
|
||||
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
lkraven@10.250.150.100
|
||||
Reference in New Issue
Block a user