fleet: register 9 hosts surfaced by gap-analysis audit

Six PFI VMs/LXCs previously known only via proxmox_inspect.sh —
covered by vzdump but not in servers/, so operational context
(roles, backup posture, ssh target) was missing:

  pfi-ana-webhost  (VMID 110)  — web workload
  ana-filebot      (LXC  112)  — file-task automation
  pfi-pteradactyl  (VMID 107)  — Pterodactyl game panel
  pfi-tacticalrmm  (VMID 111)  — TacticalRMM remote-management
  pfi-postgres     (VMID 105)  — shared Postgres (vaultwarden/gitea/
                                 paperless backends)
  ana-wg           (LXC  113)  — WireGuard VPN gateway

Plus three SureFire tenant hosts at the Anaheim colo:

  sfsrv-ana        — tenant Proxmox hypervisor (10.250.250.115:8006)
  sf-ana-container — container workload on that Proxmox
  sf-r630          — physical R630 (iDRAC 10.250.250.110 for PFI-side
                     hardware mgmt; OS is tenant-scoped)

Each server dir has README + ssh-target where applicable. SureFire
entries explicitly document tenancy scope: PFI provides hosting,
SureFire owns the OS; management actions need tenant coordination.
SureFire hosts have no ssh-target by default.

Homepage Infra - ANA gains two new cards:
  - SFsrv-ANA (https://10.250.250.115:8006, si-proxmox icon)
  - SF-R630-iDRAC (https://10.250.250.110, si-dell icon)
PFI-ANA-ML2 BMC gained an href since it has a usable web UI.

CLAUDE.md fleet table extended with all 9 new rows. Placement-rules
section notes the SureFire tenant boundary.

Memory: new project_surefire_tenant.md so future sessions know sf-*
hosts are tenant-scoped by default.
This commit is contained in:
vh
2026-04-21 14:29:43 -07:00
parent b33439499b
commit b842212b06
17 changed files with 405 additions and 1 deletions
+36
View File
@@ -0,0 +1,36 @@
# sf-r630
**SureFire tenant physical server** at the Anaheim colo — Dell
PowerEdge R630. Owner operates the OS; PFI provides rack + network.
## Tenancy
- **Owner:** SureFire (tenant)
- **PFI role:** hosting provider
## Network
- **iDRAC BMC IP:** 10.250.250.110 (on the management subnet)
- **OS-side LAN IP:** unknown — not surfaced via our DHCP discovery.
May be static, on a non-DHCP interface, or assigned to a different
subnet served by SureFire's own gear.
- **iDRAC Web UI:** https://10.250.250.110/
## Infrastructure
- **Type:** Physical Dell PowerEdge R630
- **Site:** Anaheim (PFI colo)
- **Management:** iDRAC only from the PFI side (power, console, hardware
health). OS-level access is tenant-scoped.
## Backup coverage
- Not applicable from the PFI side — tenant equipment. If hosting
terms require PFI to provide backup, coordinate with SureFire on
in-VM or OS-agent approach.
## Discovered via
`scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 — DHCP
lease on the management interface (MAC `74:e6:e2:fe:2c:7c`, VCI
`iDRAC`).