# sfsrv-ana **SureFire tenant Proxmox host** at the Anaheim colo. Third-party equipment / workload — tracked here for inventory, backup coverage, and network awareness. ## Tenancy - **Owner:** SureFire (tenant) - **PFI role:** hosting provider — provides rack, power, network - **Management scope:** coordinate with SureFire before any action ## Network - **LAN IP:** 10.250.250.115 - **Web UI:** https://10.250.250.115:8006 (Proxmox VE) - **SSH:** not currently wired into this workspace (tenant equipment). If PFI ever gains admin access, add `ssh-target` here. ## Infrastructure - **Type:** Proxmox VE hypervisor (bare metal) - **Site:** Anaheim (PFI colo) Hosts SureFire's own VMs, including: - `sf-ana-container` (10.250.150.100) on the container subnet ## Backup coverage - **Not currently backed up by the PFI fleet.** - User flagged this as **needing coverage** — open plan item. Options: 1. Coordinate tenant-side backup of SureFire VMs using their own target. 2. If PFI is responsible for backups of tenant workloads under the hosting agreement, deploy restic clients to SureFire VMs writing into a segregated repo on `rest-server-ana` (e.g. a dedicated htpasswd user + encryption key scoped to SureFire). 3. File-level Proxmox vzdump into shared NAS storage, same pattern as pfi-pve. - Decision pending. ## Refresh state Not wired into `refresh-proxmox-info.sh` — would require SSH access as root (same flow as pfi-pve / nh3-pve / etc.). Add an `ssh-target` when ready. ## Discovered via `scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 (MAC `44:a8:42:33:d9:c3`).