ops: infra-ops identity bootstrapped on all four PVE hypervisors; docs updated
This commit is contained in:
@@ -69,7 +69,7 @@ downloaded on any).
|
||||
|
||||
| need | have |
|
||||
|---|---|
|
||||
| provision LXCs on all three PVEs | `ssh root@` works on pfi-pve, nh3-pve, esh-pve (`infra-ops@` is refused on all three PVE hosts) |
|
||||
| provision LXCs on all three PVEs | `infra-ops@` with NOPASSWD sudo on all four PVE hosts since 2026-09-06 (elway `bootstrap-infra-ops-user.yaml`; PVE needed `sudo` installed first); `root@` also works |
|
||||
| public DNS name + DDNS | Cloudflare all-zones DNS-edit token, vault `nh3-dev/.config/cloudflare/infra-ops-dns-token` |
|
||||
| NH3 UDM port-forward 443 → nh3-headscale; static routes on both UDMs | UDM API keys, vault `unifi/pfi-udmse-api-key`, `unifi/esh-udmpm-api-key` (classic `/rest/*` read+write) |
|
||||
| colo static route toward ana-mesh-rtr | FortiGate infra-ops SSH pw vaulted; reachable at 10.250.0.1 via the tunnel (`execute backup config` first). Moot once OPNsense lands |
|
||||
|
||||
@@ -6,8 +6,7 @@ guest-agent IPs. Earlier versions of this file described guests that no longer e
|
||||
version is the live state._
|
||||
|
||||
**Hypervisor:** `pfi-pve` — Dell PowerEdge R750xs, Xeon Silver 4310 (48 threads), 188 GB,
|
||||
Proxmox VE 8.3.5, `https://10.250.250.31:8006`, `ssh root@10.250.250.31`
|
||||
(`infra-ops` is refused here). iDRAC `https://10.250.250.30`.
|
||||
Proxmox VE 8.3.5, `https://10.250.250.31:8006`, `ssh infra-ops@10.250.250.31` (NOPASSWD sudo, since 2026-09-06) or `root@`. iDRAC `https://10.250.250.30`.
|
||||
|
||||
**Storage:**
|
||||
|
||||
|
||||
Reference in New Issue
Block a user