fleet: re-frame SureFire hosts from tenant-only to PFI-managed
Initial framing was wrong. PFI runs these under a managed-hosting agreement: SSH, OS ops, backups are all PFI's responsibility. Hardware and data belong to the client. Changes: - ssh-target files added for sfsrv-ana (root@10.250.250.115 — same pattern as other PVE nodes) and sf-ana-container (lkraven@10.250.150.100 guess, adjust if different user). - sf-r630 still lacks an ssh-target — the OS-side LAN IP isn't in FortiGate DHCP (static config somewhere). Will fill in once identified; README flags that gap. - READMEs rewritten: dropped "tenant-scoped" / "not SSH-managed" language, added "client context" section that explains the managed-hosting relationship. Backup coverage now listed as planned rather than blocked on tenant coordination. - CLAUDE.md fleet table: SF rows re-labeled "SureFire client (PFI-managed)". Placement-rules section updated to note that SF hosts are first-class PFI-ops targets, just client-owned. - Memory (project_surefire_tenant.md) rewritten to reflect managed-services reality + hosts-file entries needed for name resolution since these aren't in PFI DNS.
This commit is contained in:
+26
-17
@@ -1,36 +1,45 @@
|
||||
# sf-r630
|
||||
|
||||
**SureFire tenant physical server** at the Anaheim colo — Dell
|
||||
PowerEdge R630. Owner operates the OS; PFI provides rack + network.
|
||||
SureFire-client physical server at the Anaheim colo — Dell PowerEdge
|
||||
R630. **PFI-managed** under the hosting agreement (hardware + OS ops).
|
||||
|
||||
## Tenancy
|
||||
## Client context
|
||||
|
||||
- **Owner:** SureFire (tenant)
|
||||
- **PFI role:** hosting provider
|
||||
- **Client:** SureFire
|
||||
- **PFI role:** full-service managed host
|
||||
|
||||
## Network
|
||||
|
||||
- **iDRAC BMC IP:** 10.250.250.110 (on the management subnet)
|
||||
- **OS-side LAN IP:** unknown — not surfaced via our DHCP discovery.
|
||||
May be static, on a non-DHCP interface, or assigned to a different
|
||||
subnet served by SureFire's own gear.
|
||||
- **iDRAC Web UI:** https://10.250.250.110/
|
||||
- Web UI: https://10.250.250.110/
|
||||
- **OS-side LAN IP:** **unknown** — not in FortiGate DHCP (static
|
||||
config?). Fill this in once identified.
|
||||
- **SSH:** no `ssh-target` set yet because the OS IP isn't known. Add
|
||||
one (e.g. `root@<ip>` or `lkraven@<ip>`) once identified.
|
||||
|
||||
## Infrastructure
|
||||
|
||||
- **Type:** Physical Dell PowerEdge R630
|
||||
- **Site:** Anaheim (PFI colo)
|
||||
- **Management:** iDRAC only from the PFI side (power, console, hardware
|
||||
health). OS-level access is tenant-scoped.
|
||||
|
||||
## Backup coverage
|
||||
|
||||
- Not applicable from the PFI side — tenant equipment. If hosting
|
||||
terms require PFI to provide backup, coordinate with SureFire on
|
||||
in-VM or OS-agent approach.
|
||||
- **VM-image:** N/A (bare-metal physical)
|
||||
- **File-level restic:** not yet configured
|
||||
- Pending OS identification + SSH access
|
||||
- Follow the `configs/restic/ana-ml2/` template when setting up
|
||||
(both are bare-metal hosts; similar source list + no DB hooks by
|
||||
default unless SF apps run databases)
|
||||
|
||||
## Refresh state
|
||||
|
||||
Once the OS IP is known and an `ssh-target` is in place:
|
||||
```bash
|
||||
scripts/refresh-server-info.sh sf-r630
|
||||
```
|
||||
|
||||
## Discovered via
|
||||
|
||||
`scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 — DHCP
|
||||
lease on the management interface (MAC `74:e6:e2:fe:2c:7c`, VCI
|
||||
`iDRAC`).
|
||||
`scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 — iDRAC's
|
||||
DHCP lease on the management interface (MAC `74:e6:e2:fe:2c:7c`,
|
||||
VCI `iDRAC`).
|
||||
|
||||
Reference in New Issue
Block a user