servers: add new host dirs, refresh fleet snapshots, orientation doc

Bundles the inventory expansion since 2026-04-22:

- New host dirs (READMEs + ssh-target where dir name doesn't resolve):
    ana-nas, ana-wg, esh-vm-db, nh3-nas, pbs-ana, pbs-nh3.
- New PFI VM snapshots (registered + key-installed 2026-04-23):
    ana-filebot, pfi-ana-webhost, pfi-postgres, pfi-pteradactyl,
    pfi-tacticalrmm, sf-ana-container, sfsrv-ana (system + proxmox).
- servers/irv-ml1: ONBOARDING.md (the first-time setup notes from when
  the host was brought into the fleet) + ssh-target (10.100.79.3 over
  the WG tunnel — name doesn't DNS-resolve from this workstation).
- servers/{ana-ml2,pfi-pve,sf-r630}/README.md: updates to capture BMC
  IPs, the iDRAC vs OS hostname distinction (sf-r630 hardware =
  sfsrv-ana OS), and the ana-ml2 Supermicro BMC (10.250.250.50,
  distinct from the Dell R750xs iDRAC).
- configs/homepage/docker.yaml: irv-ml1-docker provider added so
  homepage auto-discovers irv-ml1's stacks over the WG tunnel.
- docs/orientation.md: narrative fleet overview written for fresh
  Claude sessions — sites, backup architecture, governing principles,
  gotchas, where-to-look guide. Pointed at from CLAUDE.md.
This commit is contained in:
vh
2026-04-24 21:56:46 -07:00
parent 574c72daa5
commit 60367b307f
31 changed files with 2391 additions and 26 deletions
+75
View File
@@ -0,0 +1,75 @@
# nh3-nas
Synology RS2418+ at the NH3 site (`PFI-NH3-NAS`, `10.100.50.50`).
Primary role is fleet storage: VM-image hosting for nh3-pve, the
NH3-side restic target, and as of 2026-04-22 the PBS-NH3 datastore
backend.
## Network
- **LAN IP:** 10.100.50.50
- **DSM web UI:** <https://10.100.50.50:5001>
- **SSH:** `ssh nh3-nas` (config alias → `syncuser@10.100.50.50`,
key auth). The `syncuser` account was created specifically for
automation/tooling access; `admin` retained as the DSM primary.
## Hardware
- **Model:** Synology RS2418+ (denverton platform)
- **CPU:** Intel Atom C3538 @ 2.10 GHz, 4 cores
- **RAM:** 31.3 GB
- **Kernel:** `4.4.302+` — DSM's custom kernel, not a vanilla Debian
base. Implications: very old bash features only (4.x), BusyBox-ish
userland for some tools, syno_acl layer on Btrfs.
- **Volume:** `/volume1`, Btrfs on `cachedev_0` (SSD-cached LVM).
42 TB total, 27 TB used (64%), 16 TB free.
## Services running on the box
- **DSM built-in NFS server** — exports under `/etc/exports` managed
via DSM Shared Folder UI. Active exports include:
- `/volume1/Shared`, `/volume1/Media`, `/volume1/NetBackup`,
`/volume1/Backup`, `/volume1/compose`, `/volume1/VMStorage`,
`/volume1/devstor` (legacy home-lab exports; `all_squash`)
- `/volume1/pbs` — dedicated share for PBS-NH3's datastore mount.
Linux/POSIX mode 777, no syno_acl, `no_root_squash + no_all_squash`.
Do NOT enable Advanced Permissions on this share — see
`docs/runbooks/pbs-deployment.md` Phase 5.3 for the history.
- **rest-server-nh3** (Docker via DSM ContainerManager) — restic
HTTP endpoint on port 8000, writes under `/volume1/Backup`. Serves
nh3-docker and nh3-dev restic clients.
## What backs up to it
- nh3-docker + nh3-dev resticprofile timers (via rest-server-nh3)
- PBS-NH3 datastore (`backups-mirror`), which receives the nightly
sync pull from PBS-ANA
## What backs up FROM it
Not currently backed up itself — the DSM side is the source-of-truth
for its own config. Future work: cross-site rsync of
`/volume1/Backup/restic/...` to the Ana NAS (`10.250.50.50`), blocked
previously on SSH-access to this host (now resolved with `syncuser`).
## DSM-specific gotchas
- **Docker:** runs via DSM's ContainerManager package, not a native
`docker` CLI. `docker ps` over SSH returns empty; use
`sudo synopkg list | grep -i container` and
`sudo docker ...` (DSM aliases the binary into root's PATH).
- **Home directories:** live under `/var/services/homes/<user>/` (not
`/home/<user>`). SSH public keys go in `~/.ssh/authorized_keys`
which maps to the DSM home. Home dir permission must be 755 (not
700) or sshd rejects keys silently after DSM updates reset it.
- **Btrfs mount options** include `synoacl` — POSIX permissions are
projected through Synology's ACL layer. For share permissions to
behave as plain POSIX, either turn off "Advanced Permissions" in
DSM *and* flatten with `chmod 777` (which converts the share to
"Linux mode", `synoacltool -get` will confirm), or grant explicit
ACL entries with `synoacltool -add`.
## Refresh state
Snapshot captured via `scripts/refresh-server-info.sh nh3-nas` —
updates `system-details.txt` alongside this README.
+1
View File
@@ -0,0 +1 @@
syncuser@10.100.50.50
+126
View File
@@ -0,0 +1,126 @@
===== HOST =====
Hostname: PFI-NH3-NAS
Date: 2026-04-22T23:46:21-07:00
Uptime: up 3 days, 9 hours, 26 minutes
Kernel: 4.4.302+
Arch: x86_64
===== HARDWARE =====
CPU cores: 4
CPU model: Intel(R) Atom(TM) CPU C3538 @ 2.10GHz
MemTotal: 31.3 GB
MemAvailable: 29.5 GB
===== GPUS =====
nvidia-smi not present (no NVIDIA GPUs or driver not installed)
===== FILESYSTEMS (df) =====
Filesystem Size Used Avail Use% Mounted on
/dev/md0 2.3G 1.5G 749M 67% /
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1
/dev/loop0 27M 767K 24M 4% /tmp/SynologyAuthService
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/Backup
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/compose
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/devstor
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/docker
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/homes
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/Media
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/Music
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/NetBackup
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/Shared
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/VMStorage
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/web
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/web_packages
/dev/mapper/cachedev_0 42T 27T 16T 64% /volume1/@appdata/ContainerManager/all_shares/pbs
===== PERSISTENT MOUNTS (/etc/fstab, non-comment) =====
none /proc proc defaults 0 0
/dev/root / ext4 defaults 1 1
/dev/mapper/cachedev_0 /volume1 btrfs auto_reclaim_space,ssd,synoacl,relatime,nodev 0 0
===== TARGETED DATA PATHS =====
/opt (total: 4.0K)
===== DOCKER =====
docker not installed
===== COMPOSE FILES (/opt/docker/compose/) =====
/opt/docker/compose not present
===== CONFIG LAYOUT (/opt/docker/conf/ — top 200 entries) =====
/opt/docker/conf not present
===== LISTENING PORTS =====
0.0.0.0:111
0.0.0.0:139
0.0.0.0:161
0.0.0.0:2022
0.0.0.0:2049
0.0.0.0:22
0.0.0.0:4045
0.0.0.0:443
0.0.0.0:445
0.0.0.0:5000
0.0.0.0:5001
0.0.0.0:5357
0.0.0.0:662
0.0.0.0:80
0.0.0.0:8000
0.0.0.0:873
0.0.0.0:892
10.100.250.50:3260
10.100.50.50:3260
127.0.0.1:33304
127.0.0.1:512
127.0.0.1:5432
:::111
:::139
:::161
:::2022
:::2049
:::22
:::22000
:::3261
:::3263
:::3264
:::3265
:::4045
:::443
:::445
:::5000
:::5001
:::5357
:::6281
:::662
:::80
:::8000
:::8384
:::873
:::892
fe80::211:32ff:fe9:3260
fe80::ee0d:9aff:fe:3260
===== MODEL / HUGGINGFACE CACHES =====
===== DOCKER-ADJACENT SYSTEMD SERVICES =====
pkg-ContainerManager-dockerd.service running
pkg-ContainerManager-event-watcherd.service running
pkg-ContainerManager-termd.service running
===== DONE =====
Paste the above back into the chat, or pass a path as argv[1] to save.