docs(pfi-tacticalrmm): MeshCentral facts — WAN-only mode silently drops AMT adds; CLI access via the vaulted login token
This commit is contained in:
@@ -18,6 +18,22 @@ Tactical RMM (remote monitoring + management) server at the Anaheim colo.
|
||||
[TacticalRMM](https://tacticalrmm.com/) — open-source RMM platform.
|
||||
Monitors and manages endpoints, pushes patches, runs scripts, etc.
|
||||
|
||||
## MeshCentral (bundled with TacticalRMM) — facts checked 2026-10-02
|
||||
|
||||
- Runs natively (`meshcentral.service`, user `tactical`, `/meshcentral`), Node 18.20.8, MeshCentral 1.2.0,
|
||||
postgres-backed. Public at `https://rmm-mesh.phasefinal.com` (nginx terminates TLS, `tlsOffload`), MPS
|
||||
(Intel AMT CIRA) at `rmm-mesh.phasefinal.com:4433`. 2FA is NOT forced (`force2factor` unset).
|
||||
- ⚠ **`"WANonly": true` (TacticalRMM's install default).** In that mode MeshCentral SILENTLY DROPS
|
||||
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
|
||||
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's
|
||||
`update.sh` only touches the compression keys of `config.json`, so a WANonly change survives updates.
|
||||
- Device groups: `TC2-MacMini` (agent group), `PFI-AMT` (mtype 1, Intel AMT only; created by Prime
|
||||
2026-10-02, empty). 24 devices visible to Prime's account, 7 of them report Intel AMT.
|
||||
- CLI access: `meshctrl.js` on this host with Prime's login token, vaulted
|
||||
`pfi-tacticalrmm/meshcentral-login-token` (one line: `username: ~t:… password: …`). Example:
|
||||
`sudo -n -u tactical node /meshcentral/node_modules/meshcentral/meshctrl.js listdevicegroups --url wss://rmm-mesh.phasefinal.com --loginuser <u> --loginpass <p>`.
|
||||
Feed the credentials over stdin; never put them in a file or a log.
|
||||
|
||||
## Backup coverage
|
||||
|
||||
- **VM-image:** ✅ vzdump on pfi-pve (daily)
|
||||
|
||||
Reference in New Issue
Block a user