ops(pfi-tacticalrmm): MeshCentral to hybrid mode; nh3-pve AMT added and connected

This commit is contained in:
vh
2026-10-02 08:14:19 -07:00
parent a967bb95a6
commit 8b81579bca
2 changed files with 8 additions and 1 deletions
+7 -1
View File
@@ -23,7 +23,13 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc.
- Runs natively (`meshcentral.service`, user `tactical`, `/meshcentral`), Node 18.20.8, MeshCentral 1.2.0,
postgres-backed. Public at `https://rmm-mesh.phasefinal.com` (nginx terminates TLS, `tlsOffload`), MPS
(Intel AMT CIRA) at `rmm-mesh.phasefinal.com:4433`. 2FA is NOT forced (`force2factor` unset).
- ⚠ **`"WANonly": true` (TacticalRMM's install default).** In that mode MeshCentral SILENTLY DROPS
- **HYBRID since 2026-10-02 0812 (Prime: "hybrid, make it so").** `settings.WANonly` set false (backup
`config.json.bak-20261002-hybrid`); the log says "Hybrid (LAN + WAN) mode". All 14 connected agents came
back. **nh3-pve's AMT is in `PFI-AMT` as `nh3-pve-amt`** (10.100.250.61, TLS, admin): MeshCentral reached it
at once (AMT 16.1.25, activated, power on), so the old-TLS worry did not apply. ⚠ The path still runs
through nh3-scale (CT 107 ON nh3-pve): with nh3-pve down, this AMT is unreachable from here. KVM needs
an active iGPU output: the NanoKVM serves today; fit the 1080p dummy plug before it moves.
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's
`update.sh` only touches the compression keys of `config.json`, so a WANonly change survives updates.