The box is physically at Fountain Valley, renamed, renumbered onto 10.251/16, and serving inference again. This lands the repo half of that. Host: hostname ana-ml2 -> fv-ml1, pinned to 10.251.50.54 by a dnsmasq reservation so the address the runbook, DNS and LiteLLM all assume is the address it actually has. Its headscale node is renamed too. The sweep ran from scripts/fv-ml1-rename-sweep.sh, whose allowlist is the reason this diff touches current-state files and not the record. Dated persistent-memory entries, archival-memory and incident notes still say ana-ml2 in 31 and 62 places respectively, because that is what the box was when those things happened. Rewriting them would make the history lie. LiteLLM was the load-bearing piece and needed more than the api_base sed the runbook describes. Twenty api_base entries repointed, but a grep-and-verify pass also caught a LIVE pass_through_endpoints target for the scalar-judge reward route still on the old address -- an api_base-only substitution would have left it dead. Four prose references describing current state were repointed as well; one historical note recording where a hand-test was run is deliberately left pointing at 10.250.50.54. Two facts in the server tables were wrong and are corrected here. The site is Fountain Valley, not Anaheim. And the box has FOUR RTX PRO 6000 Blackwell Max-Q, not two -- verified by nvidia-smi -L and independently by PCI enumeration of four GB202GL devices. That is 391 GB of VRAM rather than 196, which changes what fits on it. DNS: fv-ml1, fv-ml1-bmc and fv-gw added under the fv site via the piggyback approach, scriberr re-homed, and the ana-ml2 records removed. Applied to all three resolvers. The BMC record carries a warning that its 802.1q VLAN tag must stay disabled -- it shipped tagging VLAN 250 into an untagged port, which made it invisible to every network-side diagnostic and is the reason it appeared dead through several cable changes. Verified end to end: summarizer and sec both answer through the Anaheim gateway across the mesh to FV seats on different ports.
126 lines
8.5 KiB
YAML
126 lines
8.5 KiB
YAML
# Fleet internal DNS — the source of truth for *.internal names.
|
|
#
|
|
# THIS FILE IS AUTHORITATIVE. `scripts/dns-sync.sh` reconciles every resolver
|
|
# against it: names here are created, names removed here are deleted, and
|
|
# names edited here are updated. Do NOT add .internal names in the AdGuard UI
|
|
# — the next sync will delete them.
|
|
#
|
|
# WHAT THE SYNC WILL NOT TOUCH: any rewrite outside the `.internal` zone. The
|
|
# ESH resolver carries hand-made `esteban.net` entries that predate this file
|
|
# and are deliberately left alone. Authority is scoped to the zone, not to the
|
|
# resolver's whole table.
|
|
#
|
|
# NAMING: <host>.<site>.internal, sites `ana` / `esh` / `nh3` (operator,
|
|
# 2026-08-19). `.internal` is ICANN-reserved for exactly this use since 2024,
|
|
# which is why it is used here rather than `.local` (reserved for mDNS) or a
|
|
# made-up TLD that could later collide with a real one.
|
|
#
|
|
# EVERY name is published to EVERY resolver, so `ana-docker.ana.internal`
|
|
# resolves from ESH and NH3 too. The site label says where a host IS, not
|
|
# which resolver knows about it.
|
|
#
|
|
# ⚠️ THE v6 COLUMN IS EMPTY ON PURPOSE, AND MUST STAY DECLARATIVE.
|
|
# No fleet host has a global IPv6 address today (verified 2026-08-19: ESH's
|
|
# /56 is live only on esh-cameras, NH3's LANs are back to ipv6_interface_type
|
|
# none, the colo has no v6 at all). When v6 lands, do NOT paste in whatever
|
|
# `ip -6 addr` happens to show: SLAAC addresses are either EUI-64 (MAC-coupled)
|
|
# or privacy-extension (they rotate), and UniFi has no v6 equivalent of a DHCP
|
|
# reservation. A v6 address only belongs in this file once it has been pinned
|
|
# STATICALLY on the host itself — otherwise the record rots silently and the
|
|
# name starts lying, which is worse than having no record.
|
|
|
|
zone: internal
|
|
|
|
sites:
|
|
ana:
|
|
subnet: 10.250.0.0/16
|
|
resolver: 10.250.50.70 # ana-docker — AdGuard #3, stood up for this
|
|
# ⚠️ NOT 8080. ana-docker already has :8080 and :3000 taken, so this
|
|
# AdGuard's API is on 8053. The port lives here rather than in the script
|
|
# precisely so the odd one out cannot be forgotten.
|
|
api_port: 8053
|
|
description: Anaheim colo
|
|
esh:
|
|
subnet: 10.0.0.0/16
|
|
resolver: 10.0.50.45 # esh-docker-vm
|
|
api_port: 8080
|
|
description: ESH home lab (esteban.net)
|
|
nh3:
|
|
subnet: 10.100.0.0/16
|
|
resolver: 10.100.50.40 # nh3-docker
|
|
api_port: 8080
|
|
description: NH3 office
|
|
|
|
hosts:
|
|
# ---- ana: Anaheim colo ----
|
|
- {name: ana-docker, site: ana, v4: 10.250.50.70, note: general-purpose docker host}
|
|
# ---- fv: Fountain Valley colo (piggyback DNS until FV has its own resolver) ----
|
|
- {name: fv-ml1, site: fv, v4: 10.251.50.54, note: GPU inference, 4x RTX PRO 6000 Blackwell Max-Q (ex ana-ml2, relocated 2026-09-12)}
|
|
- {name: ana-nas, site: ana, v4: 10.250.50.50, note: CT109 on pfi-pve — NFS/SMB}
|
|
- {name: ana-filebot, site: ana, v4: 10.250.50.53, note: file-task automation}
|
|
- {name: ana-wg, site: ana, v4: 10.250.50.252, note: WireGuard host}
|
|
- {name: corviduo-dev, site: ana, v4: 10.250.50.152, note: Worldtree-team dev VM (PFI-hosted)}
|
|
- {name: pbs-ana, site: ana, v4: 10.250.50.90, note: Proxmox Backup Server — fleet primary}
|
|
- {name: pfi-ana-webhost, site: ana, v4: 10.250.50.52, note: web workload}
|
|
- {name: pfi-postgres, site: ana, v4: 10.250.50.80, note: shared Postgres}
|
|
- {name: pfi-pteradactyl, site: ana, v4: 10.250.50.55, note: game panel}
|
|
- {name: pfi-tacticalrmm, site: ana, v4: 10.250.50.57, note: TacticalRMM}
|
|
- {name: pfi-pve, site: ana, v4: 10.250.250.31, note: Proxmox hypervisor}
|
|
- {name: ana-gw, site: ana, v4: 10.250.0.1, note: FortiGate-80F edge}
|
|
- {name: pfi-pve-idrac, site: ana, v4: 10.250.250.30, note: iDRAC — OOB for pfi-pve}
|
|
- {name: fv-ml1-bmc, site: fv, v4: 10.251.250.50, note: BMC for fv-ml1 (Supermicro/ATEN; 802.1q VLAN tag must stay DISABLED)}
|
|
- {name: fv-gw, site: fv, v4: 10.251.50.1, note: OPNsense gateway vb-gateway, mesh subnet-router for 10.251.0.0/16; public 172.83.89.66 = fv.phasefinal.com}
|
|
# SureFire tenant hardware — PFI-managed under the hosting agreement.
|
|
- {name: sfsrv-ana, site: ana, v4: 10.250.250.115, note: SureFire tenant hypervisor}
|
|
- {name: sf-ana-container, site: ana, v4: 10.250.150.100, note: SureFire tenant container host}
|
|
- {name: sf-r630-idrac, site: ana, v4: 10.250.250.110, note: SureFire tenant R630 iDRAC}
|
|
|
|
# ---- nh3: NH3 office ----
|
|
- {name: nh3-docker, site: nh3, v4: 10.100.50.40, note: general-purpose docker host + AdGuard}
|
|
- {name: pfi-gx10, site: nh3, v4: 10.100.50.60, note: GB10 Grace Blackwell, 121 GB unified — DHCP RESERVATION on the UDM, not a host static, so the box stays portable}
|
|
- {name: nh3-dev, site: nh3, v4: 10.100.10.50, note: dev box, fleet sidecars, Claude sessions}
|
|
- {name: nh3-extdev, site: nh3, v4: 10.100.50.42, note: manager / external-dev box}
|
|
- {name: nh3-nas, site: nh3, v4: 10.100.50.50, note: Synology RS2418+}
|
|
- {name: nh3-pve, site: nh3, v4: 10.100.250.60, note: Proxmox hypervisor}
|
|
- {name: pbs-nh3, site: nh3, v4: 10.100.50.90, note: Proxmox Backup Server — DR mirror}
|
|
- {name: nh3-gw, site: nh3, v4: 10.100.0.1, note: UniFi UDM Pro SE — gateway + controller}
|
|
# Irvine is not its own DNS site: it is a single box (irv-ml1) reached over
|
|
# the headscale mesh, so it is named under nh3 rather than getting its own
|
|
# resolver. Its real LAN is 10.6.110.0/24 (Irvine), advertised fleet-wide as
|
|
# a mesh subnet route — NOT NH3's 10.100.79.0/24 (that wg0 lifeline is
|
|
# dormant post-cutover 2026-09-06). The mesh node IP is 100.64.0.6; we resolve
|
|
# to the LAN IP to match the host→LAN-IP model every other entry uses.
|
|
# Revisit if Irvine ever grows beyond this one host.
|
|
- {name: irv-ml1, site: nh3, v4: 10.6.110.50, note: GPU host (Irvine, via headscale mesh) — 3090 + A6000; mesh node 100.64.0.6}
|
|
|
|
# ---- esh: ESH home lab ----
|
|
- {name: esh-docker-vm, site: esh, v4: 10.0.50.45, note: general-purpose docker host + AdGuard}
|
|
- {name: esh-nas, site: esh, v4: 10.0.50.50, note: NAS}
|
|
- {name: esh-pve, site: esh, v4: 10.0.250.35, note: Proxmox hypervisor}
|
|
- {name: esh-pve-nas, site: esh, v4: 10.0.50.55, note: Proxmox hypervisor — storage/media}
|
|
- {name: esh-vm-db, site: esh, v4: 10.0.50.60, note: PostgreSQL + MongoDB}
|
|
- {name: vm-esh-nas, site: esh, v4: 10.0.50.154, note: NAS-adjacent docker host}
|
|
- {name: esh-filebot, site: esh, v4: 10.0.50.70, note: restic / file-sync VM}
|
|
- {name: esh-gw, site: esh, v4: 10.0.250.1, note: esh-gw}
|
|
- {name: esh-udm, site: esh, v4: 10.0.0.1, note: UniFi UDM Pro Max — gateway + controller}
|
|
- {name: plex, site: esh, v4: 10.0.50.56, note: media server}
|
|
- {name: jellyfin, site: esh, v4: 10.0.50.57, note: media server}
|
|
- {name: brother, site: esh, v4: 10.0.90.125, note: Brother printer}
|
|
- {name: slzb-mr1u, site: esh, v4: 10.0.90.10, note: SMLIGHT SLZB-MR1U Zigbee/Thread coordinator (esh-iot VLAN 90, PoE on ESH-Media p4); Home Assistant at 10.0.50.46 connects to tcp/6638}
|
|
- {name: ana-scale, site: ana, v4: 10.250.50.45, note: CT114 on pfi-pve — headscale/tailscale subnet router for 10.250.0.0/16}
|
|
- {name: nh3-headscale, site: nh3, v4: 10.100.50.45, note: CT106 on nh3-pve — headscale control plane (public headscale.phasefinal.com:443)}
|
|
- {name: nh3-scale, site: nh3, v4: 10.100.50.46, note: CT107 on nh3-pve — subnet router for 10.100.0.0/16}
|
|
- {name: esh-scale, site: esh, v4: 10.0.50.65, note: CT108 on esh-pve — subnet router for 10.0.0.0/16}
|
|
|
|
# Service aliases — a name that points at whatever host currently runs it, so
|
|
# consumers reference the SERVICE rather than the box. Changing where something
|
|
# runs becomes a one-line edit here instead of a hunt through configs.
|
|
|
|
aliases:
|
|
- {name: searxng, site: nh3, target: nh3-docker, note: moved off ana-docker 2026-09-03 — colo egress (38.120.12.42) is CAPTCHA-gated by search engines; NH3 egresses residentially}
|
|
- {name: gateway, site: ana, target: ana-docker, note: LiteLLM gateway :4000}
|
|
- {name: booth, site: nh3, target: nh3-dev, note: The Booth :8090}
|
|
- {name: wherethef, site: nh3, target: nh3-dev, note: WhereTF :8093}
|
|
- {name: homepage, site: esh, target: esh-docker-vm, note: fleet dashboard :5100}
|
|
- {name: scriberr, site: fv, target: fv-ml1, note: transcription + diarization :8080 (GPU1)}
|