60367b307f
Bundles the inventory expansion since 2026-04-22:
- New host dirs (READMEs + ssh-target where dir name doesn't resolve):
ana-nas, ana-wg, esh-vm-db, nh3-nas, pbs-ana, pbs-nh3.
- New PFI VM snapshots (registered + key-installed 2026-04-23):
ana-filebot, pfi-ana-webhost, pfi-postgres, pfi-pteradactyl,
pfi-tacticalrmm, sf-ana-container, sfsrv-ana (system + proxmox).
- servers/irv-ml1: ONBOARDING.md (the first-time setup notes from when
the host was brought into the fleet) + ssh-target (10.100.79.3 over
the WG tunnel — name doesn't DNS-resolve from this workstation).
- servers/{ana-ml2,pfi-pve,sf-r630}/README.md: updates to capture BMC
IPs, the iDRAC vs OS hostname distinction (sf-r630 hardware =
sfsrv-ana OS), and the ana-ml2 Supermicro BMC (10.250.250.50,
distinct from the Dell R750xs iDRAC).
- configs/homepage/docker.yaml: irv-ml1-docker provider added so
homepage auto-discovers irv-ml1's stacks over the WG tunnel.
- docs/orientation.md: narrative fleet overview written for fresh
Claude sessions — sites, backup architecture, governing principles,
gotchas, where-to-look guide. Pointed at from CLAUDE.md.
nh3-nas
Synology RS2418+ at the NH3 site (PFI-NH3-NAS, 10.100.50.50).
Primary role is fleet storage: VM-image hosting for nh3-pve, the
NH3-side restic target, and as of 2026-04-22 the PBS-NH3 datastore
backend.
Network
- LAN IP: 10.100.50.50
- DSM web UI: https://10.100.50.50:5001
- SSH:
ssh nh3-nas(config alias →syncuser@10.100.50.50, key auth). Thesyncuseraccount was created specifically for automation/tooling access;adminretained as the DSM primary.
Hardware
- Model: Synology RS2418+ (denverton platform)
- CPU: Intel Atom C3538 @ 2.10 GHz, 4 cores
- RAM: 31.3 GB
- Kernel:
4.4.302+— DSM's custom kernel, not a vanilla Debian base. Implications: very old bash features only (4.x), BusyBox-ish userland for some tools, syno_acl layer on Btrfs. - Volume:
/volume1, Btrfs oncachedev_0(SSD-cached LVM). 42 TB total, 27 TB used (64%), 16 TB free.
Services running on the box
- DSM built-in NFS server — exports under
/etc/exportsmanaged via DSM Shared Folder UI. Active exports include:/volume1/Shared,/volume1/Media,/volume1/NetBackup,/volume1/Backup,/volume1/compose,/volume1/VMStorage,/volume1/devstor(legacy home-lab exports;all_squash)/volume1/pbs— dedicated share for PBS-NH3's datastore mount. Linux/POSIX mode 777, no syno_acl,no_root_squash + no_all_squash. Do NOT enable Advanced Permissions on this share — seedocs/runbooks/pbs-deployment.mdPhase 5.3 for the history.
- rest-server-nh3 (Docker via DSM ContainerManager) — restic
HTTP endpoint on port 8000, writes under
/volume1/Backup. Serves nh3-docker and nh3-dev restic clients.
What backs up to it
- nh3-docker + nh3-dev resticprofile timers (via rest-server-nh3)
- PBS-NH3 datastore (
backups-mirror), which receives the nightly sync pull from PBS-ANA
What backs up FROM it
Not currently backed up itself — the DSM side is the source-of-truth
for its own config. Future work: cross-site rsync of
/volume1/Backup/restic/... to the Ana NAS (10.250.50.50), blocked
previously on SSH-access to this host (now resolved with syncuser).
DSM-specific gotchas
- Docker: runs via DSM's ContainerManager package, not a native
dockerCLI.docker psover SSH returns empty; usesudo synopkg list | grep -i containerandsudo docker ...(DSM aliases the binary into root's PATH). - Home directories: live under
/var/services/homes/<user>/(not/home/<user>). SSH public keys go in~/.ssh/authorized_keyswhich maps to the DSM home. Home dir permission must be 755 (not 700) or sshd rejects keys silently after DSM updates reset it. - Btrfs mount options include
synoacl— POSIX permissions are projected through Synology's ACL layer. For share permissions to behave as plain POSIX, either turn off "Advanced Permissions" in DSM and flatten withchmod 777(which converts the share to "Linux mode",synoacltool -getwill confirm), or grant explicit ACL entries withsynoacltool -add.
Refresh state
Snapshot captured via scripts/refresh-server-info.sh nh3-nas —
updates system-details.txt alongside this README.