# esh-pve-2 — Minisforum MS-03, Proxmox VE 9 (ESH) The second of the two MS-03s (the other is `nh3-pve-2`). Planned home of **`esh-dev`**, which will take over most of nh3-dev's sessions (Prime, 2026-10-02; the move itself is not yet planned). Standalone node, **not** in the ESH cluster (`pve` + `esh-nas-pve`, still on PVE 8.4). - **Address: `10.0.10.70`, DHCP, TEMPORARY.** Prime: the permanent address "can wait". When it is chosen, reserve it on MAC `38:05:25:3b:9c:12` (see AMT below: the host and AMT share that MAC and that address). - **Access:** `ssh infra-ops@10.0.10.70` (fleet key, NOPASSWD sudo, `Defaults:infra-ops log_output`), set up by Prime 2026-10-02. Web UI `https://10.0.10.70:8006`. - PVE 9.2.21, kernel 7.0.14-20-pve (2026-10-02 2210 boot). ## Hardware | | | |---|---| | Board | MS-03 (`PTWSA`), Intel Panther Lake | | NICs | `nic1` **I226-LM 2.5G (vPro/AMT)**, the only cabled port and vmbr0's port; `nic0` RTL8127 10G; `nic2`/`nic3` X710 SFP+ | | Boot disk | Toshiba KXG60ZNV256G 256 GB, serial `199A3537K01N`: ESP, LVM `pve` (root 70 G, swap 4 G, `local-lvm` 14 G) | | VM disk | Crucial CT1000E100SSD8 1 TB, serial `2611EAD0291A`: whole-disk LVM-thin **`vmstore`** (913 GiB) | ⚠ **`nvme0`/`nvme1` swap between boots** (seen 2026-10-02: the 1 TB was `nvme0` before the reboot and `nvme1` after). Address disks by `/dev/disk/by-id/…` (serial), never `nvmeXn1`. ## Disks and boot (2026-10-02, Prime) `playbooks/esh-pve-2-disk-prep.yaml`, re-runnable: - **Firmware boot entries:** `Boot0000 proxmox` (256 GB, shim) first; `Boot0006 UEFI OS` (same ESP's fallback loader, kept); built-in EFI shell (inactive). Deleted `Boot0005`, the fallback loader of an older Proxmox install on the 1 TB drive. GRUB itself never listed that install: `os-prober` is not installed and PVE disables it. - **1 TB drive:** held that old install (VG renamed `pve-OLD-2E68F512` by the installer, thin pool 0.00% used). VG and PV removed, signatures wiped, GPT zapped, whole drive discarded, then `pvesh create …/disks/lvmthin` (the GUI path) made `vmstore`, content `images,rootdir`, node-restricted. Verified with a 1 GiB alloc/free, again after the reboot. - **Format choice: LVM-thin**, the PVE default and the same as the boot drive and esh-pve. ZFS was the alternative (checksums, compression, replication) but is heavy on a single DRAM-less consumer drive. Cheap to change only while `vmstore` is empty. ## Intel AMT — phones home to MeshCentral (2026-10-02 2218) - **AMT and Proxmox share the I226-LM port, its MAC and its IP** (AMT DHCP, `SharedMAC`/`SharedDynamicIP` true): AMT answers on `10.0.10.70` for its own ports only. AMT 21.0.6, **Admin Control Mode**, MEBx password = the one on nh3-pve / nh3-pve-2, vaulted `esh-pve-2/amt-admin`. - Set over WS-Man before phone-home: KVM enabled, redirection listener on (IDER/SOL/KVM), **OptInRequired 0** (no consent code). Then `scripts/amt-cira-setup.py --apply` (MPS `rmm-mesh.phasefinal.com:4433`, user `CtDDEpGX0VLlJ1X9`, periodic 10 s policy, random environment-detection domain). - **MeshCentral device `esh-pve-2-amt`** (group `PFI-AMT`; credentials + `tls` 1 set on the device). Tunnel arrives from ESH's public IP `128.177.138.182`. Read back 2221: CIRA connected, power on, AMT 21.0.6. - ⚠ **Manage it through MeshCentral.** In phone-home ("outside") mode AMT refuses LAN management, so `scripts/amt-wsman.py` against `10.0.10.70` no longer works. Last resort: MEBx (Ctrl+P at boot), on site. - ⚠ **Keep `nic1` up.** On these boards igc powers the PHY off when Linux downs the port, and AMT loses its link (auto-memory `reference_ms01_amt_port_must_stay_up`). Today it is vmbr0's bridge port, so it stays up. If vmbr0 ever moves to another NIC, give `nic1` its own `auto nic1` / `iface nic1 inet manual`. - ⚠ **AMT must stay on DHCP** for phone-home (Intel: CIRA does not work on a static IP). When the permanent address is chosen, make it a DHCP reservation on `38:05:25:3b:9c:12`. If the host goes static, use that same address so the two keep sharing one IP. - Power schemes offered: "Mobile: ON in S0" and "ON in S0, ME Wake in S3, S4-5 (AC only)". Not checked which is active. Its twin nh3-pve-2 kept its tunnel while powered off (2026-10-02 2221), so this one probably does too. - ⚠ **If "HW Connect" sticks at "Setup…" after a power cycle, look for a stale second tunnel** (2026-10-02 2247; fix in `servers/pfi-tacticalrmm/README.md`). Because AMT shares `nic1`, the link drops whenever Linux starts or stops, and AMT can leave its old tunnel half-open. - Remote desktop works only while the host is ON (AMT mirrors the iGPU). Power it up from MeshCentral first. AMT itself stays reachable when the host is off (both MS-03s, 2026-10-02 2229). - Display: a 1080p HDMI plug is fitted (`HDMI-A-1` connected, 1920x1080, 2026-10-02 2241). - **KVM needs an active iGPU output.** A 4K dummy plug blacked the AMT console on nh3-pve-2 once Linux took the display; use a 1080p plug.