fleet: register 9 hosts surfaced by gap-analysis audit

Six PFI VMs/LXCs previously known only via proxmox_inspect.sh —
covered by vzdump but not in servers/, so operational context
(roles, backup posture, ssh target) was missing:

  pfi-ana-webhost  (VMID 110)  — web workload
  ana-filebot      (LXC  112)  — file-task automation
  pfi-pteradactyl  (VMID 107)  — Pterodactyl game panel
  pfi-tacticalrmm  (VMID 111)  — TacticalRMM remote-management
  pfi-postgres     (VMID 105)  — shared Postgres (vaultwarden/gitea/
                                 paperless backends)
  ana-wg           (LXC  113)  — WireGuard VPN gateway

Plus three SureFire tenant hosts at the Anaheim colo:

  sfsrv-ana        — tenant Proxmox hypervisor (10.250.250.115:8006)
  sf-ana-container — container workload on that Proxmox
  sf-r630          — physical R630 (iDRAC 10.250.250.110 for PFI-side
                     hardware mgmt; OS is tenant-scoped)

Each server dir has README + ssh-target where applicable. SureFire
entries explicitly document tenancy scope: PFI provides hosting,
SureFire owns the OS; management actions need tenant coordination.
SureFire hosts have no ssh-target by default.

Homepage Infra - ANA gains two new cards:
  - SFsrv-ANA (https://10.250.250.115:8006, si-proxmox icon)
  - SF-R630-iDRAC (https://10.250.250.110, si-dell icon)
PFI-ANA-ML2 BMC gained an href since it has a usable web UI.

CLAUDE.md fleet table extended with all 9 new rows. Placement-rules
section notes the SureFire tenant boundary.

Memory: new project_surefire_tenant.md so future sessions know sf-*
hosts are tenant-scoped by default.
This commit is contained in:
vh
2026-04-21 14:29:43 -07:00
parent b33439499b
commit b842212b06
17 changed files with 405 additions and 1 deletions
+51
View File
@@ -0,0 +1,51 @@
# sfsrv-ana
**SureFire tenant Proxmox host** at the Anaheim colo. Third-party
equipment / workload — tracked here for inventory, backup coverage,
and network awareness.
## Tenancy
- **Owner:** SureFire (tenant)
- **PFI role:** hosting provider — provides rack, power, network
- **Management scope:** coordinate with SureFire before any action
## Network
- **LAN IP:** 10.250.250.115
- **Web UI:** https://10.250.250.115:8006 (Proxmox VE)
- **SSH:** not currently wired into this workspace (tenant equipment).
If PFI ever gains admin access, add `ssh-target` here.
## Infrastructure
- **Type:** Proxmox VE hypervisor (bare metal)
- **Site:** Anaheim (PFI colo)
Hosts SureFire's own VMs, including:
- `sf-ana-container` (10.250.150.100) on the container subnet
## Backup coverage
- **Not currently backed up by the PFI fleet.**
- User flagged this as **needing coverage** — open plan item. Options:
1. Coordinate tenant-side backup of SureFire VMs using their own
target.
2. If PFI is responsible for backups of tenant workloads under the
hosting agreement, deploy restic clients to SureFire VMs writing
into a segregated repo on `rest-server-ana` (e.g. a dedicated
htpasswd user + encryption key scoped to SureFire).
3. File-level Proxmox vzdump into shared NAS storage, same pattern
as pfi-pve.
- Decision pending.
## Refresh state
Not wired into `refresh-proxmox-info.sh` — would require SSH access as
root (same flow as pfi-pve / nh3-pve / etc.). Add an `ssh-target` when
ready.
## Discovered via
`scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 (MAC
`44:a8:42:33:d9:c3`).