servers: add new host dirs, refresh fleet snapshots, orientation doc

Bundles the inventory expansion since 2026-04-22:

- New host dirs (READMEs + ssh-target where dir name doesn't resolve):
    ana-nas, ana-wg, esh-vm-db, nh3-nas, pbs-ana, pbs-nh3.
- New PFI VM snapshots (registered + key-installed 2026-04-23):
    ana-filebot, pfi-ana-webhost, pfi-postgres, pfi-pteradactyl,
    pfi-tacticalrmm, sf-ana-container, sfsrv-ana (system + proxmox).
- servers/irv-ml1: ONBOARDING.md (the first-time setup notes from when
  the host was brought into the fleet) + ssh-target (10.100.79.3 over
  the WG tunnel — name doesn't DNS-resolve from this workstation).
- servers/{ana-ml2,pfi-pve,sf-r630}/README.md: updates to capture BMC
  IPs, the iDRAC vs OS hostname distinction (sf-r630 hardware =
  sfsrv-ana OS), and the ana-ml2 Supermicro BMC (10.250.250.50,
  distinct from the Dell R750xs iDRAC).
- configs/homepage/docker.yaml: irv-ml1-docker provider added so
  homepage auto-discovers irv-ml1's stacks over the WG tunnel.
- docs/orientation.md: narrative fleet overview written for fresh
  Claude sessions — sites, backup architecture, governing principles,
  gotchas, where-to-look guide. Pointed at from CLAUDE.md.
This commit is contained in:
vh
2026-04-24 21:56:46 -07:00
parent 574c72daa5
commit 60367b307f
31 changed files with 2391 additions and 26 deletions
+96
View File
@@ -0,0 +1,96 @@
# esh-vm-db
ESH-side database VM at `esteban.net`. Hosts **two database servers**:
- **PostgreSQL 15** on port 5432 — primary consumer is paperless-ngx
on esh-docker-vm (`paperless-ng` user/db).
- **MongoDB** on port 27017 — consumers unknown; document at next
inventory pass.
Discovered 2026-04-23 during the paperless-ngx password rotation —
paperless's `PAPERLESS_DBHOST: 10.0.50.60` pointed here rather than
the assumed pfi-postgres (VM 105). Up until that point this host was
invisible to inventory.
## Network
- **LAN IP:** 10.0.50.60
- **FQDN:** `esh-vm-db.esteban.net`
- **SSH:** `ssh esh-vm-db` (config alias → `lkraven@10.0.50.60`,
key auth).
- **Listening ports:** 22 (ssh), 111 (rpcbind — NFS mount support),
5432 (postgres), 27017 (mongo).
## Hardware
- **Hypervisor:** presumably esh-pve or esh-pve-nas (to be confirmed
— not yet queried from the PVE side).
- **CPU:** Intel Core i9-13900H (16 cores, mobile) — indicates this
VM lives on a mini-PC / NUC-class ESH host.
- **RAM:** 7.8 GB
- **Root disk:** 250 GB ext4 on `/dev/sda1`, 5.1 GB used (2%). Plenty
of headroom for both DBs.
- **OS:** Debian 12 (bookworm), kernel 6.1.0-23
- **Uptime:** 3+ weeks at last snapshot.
## What it runs
- **PostgreSQL 15 (apt package, `postgresql`)** — data directory
default (`/var/lib/postgresql/15/main` presumably — confirm with
`pg_lsclusters` on a future refresh). Local disk, not NFS —
consistent with the "DBs must live on local disk" principle we
adopted 2026-04-23.
- **MongoDB** — port 27017 bound to 0.0.0.0. DataPath + version to
be captured.
- **No Docker.** `server_inspect.sh` reports `docker not installed`
and `/opt/docker` absent — this host is bare-metal DB service,
not a container host.
## Storage
- `/dev/sda1` (250 GB ext4) — DB data + OS
- `/mnt/backup` mounted from `10.0.50.50:/mnt/backup` via NFS
(`defaults`). Purpose TBD — possibly for pg_dump outputs or other
backup staging. Review on next pass.
## Consumers
- **paperless-ngx** on esh-docker-vm — uses postgres user
`paperless-ng` against DB `paperless-ng` (confirmed 2026-04-23,
password rotated).
- **MongoDB consumers** — unknown; map these by checking connection
logs or by inventorying the other ESH-side Docker stacks for
`27017`/`mongodb` references.
## Backup coverage
**Not yet configured.** Same category as ana-ml2/irv-ml1/esh-vm-db
now (bare-metal DB host without vzdump awareness from the PVE side).
Next steps:
- Add to fleet PBS vzdump schedule (its hypervisor backs it up via
PBS-ANA if the hypervisor is onboarded).
- Draft `configs/restic/esh-vm-db/profiles.yaml` for file-level +
per-DB dumps (`pg_dumpall` for postgres, `mongodump` for mongo).
Target: `rest-server-ana` via the ESH → ANA cross-WAN path, same
as other ESH-side restic clients.
- `rest-server-ana`'s `.htpasswd` will need an `esh-vm-db` entry.
## Refresh state
```bash
scripts/refresh-server-info.sh esh-vm-db
```
## Follow-ups (do soon)
- Confirm hypervisor (likely esh-pve or esh-pve-nas) — `qm list`
on each and find VM with this name.
- Map MongoDB consumers.
- Configure backup (restic profile + per-DB dumps + vzdump coverage
on the hypervisor side).
- Audit postgres `pg_hba.conf` — is 5432 bound to 0.0.0.0 with
proper host-based auth, or is it over-exposed? paperless connects
from 10.0.50.45 (esh-docker-vm); other hosts shouldn't be able
to reach in.
+1
View File
@@ -0,0 +1 @@
lkraven@10.0.50.60
+80
View File
@@ -0,0 +1,80 @@
===== HOST =====
Hostname: esh-vm-db.esteban.net
Date: 2026-04-23T21:53:16-07:00
Uptime: up 3 weeks, 2 days, 23 hours, 22 minutes
OS: Debian GNU/Linux 12 (bookworm)
Kernel: 6.1.0-23-amd64
Arch: x86_64
===== HARDWARE =====
CPU cores: 16
CPU model: 13th Gen Intel(R) Core(TM) i9-13900H
MemTotal: 7.8 GB
MemAvailable: 7.2 GB
===== GPUS =====
nvidia-smi not present (no NVIDIA GPUs or driver not installed)
===== FILESYSTEMS (df) =====
Filesystem Size Used Avail Use% Mounted on
/dev/sda1 250G 5.1G 233G 3% /
10.0.50.50:/mnt/backup 92T 11G 92T 1% /mnt/backup
===== PERSISTENT MOUNTS (/etc/fstab, non-comment) =====
UUID=9022f0b6-4299-452a-a4a4-85e1623243ae / ext4 errors=remount-ro 0 1
UUID=6d90bc64-6f3e-41b9-8295-640ac854e5e5 none swap sw 0 0
/dev/sr0 /media/cdrom0 udf,iso9660 user,noauto 0 0
10.0.50.50:/mnt/backup /mnt/backup nfs defaults 0 0
===== TARGETED DATA PATHS =====
/opt (total: 4.0K)
total 8
drwxr-xr-x 2 root root 4096 2024-05-20 23:47 .
drwxr-xr-x 18 root root 4096 2024-08-13 17:35 ..
/srv (total: 2.8M)
total 12
drwxr-xr-x 3 root root 4096 2024-06-13 10:05 .
drwxr-xr-x 18 root root 4096 2024-08-13 17:35 ..
drwxrwxrwx 4 root root 4096 2024-06-13 10:44 backups
===== DOCKER =====
docker not installed
===== COMPOSE FILES (/opt/docker/compose/) =====
/opt/docker/compose not present
===== CONFIG LAYOUT (/opt/docker/conf/ — top 200 entries) =====
/opt/docker/conf not present
===== LISTENING PORTS =====
0.0.0.0:111
0.0.0.0:22
0.0.0.0:27017
0.0.0.0:5432
[::]:111
[::]:22
[::]:5432
===== MODEL / HUGGINGFACE CACHES =====
===== DOCKER-ADJACENT SYSTEMD SERVICES =====
(none matching)
===== DONE =====
Paste the above back into the chat, or pass a path as argv[1] to save.