Prime bootstrapped infra-ops on vm-esh-nas with playbooks/bootstrap-infra-ops-user.yaml. It got the fleet-pinned uid/gid 850, NOPASSWD sudo with log_output, the docker group and a 0700 home. That let playbooks/restic-repository-file.yaml migrate the last restic host: the live profile matched the repo's pre-change sha, its units no longer carry the URL, its secrets are vaulted, and the live and repo profiles now match (a5ea75ea). All eight restic hosts are clean. The staged helper script is gone, both from Prime's home on the host and from the repo. The docs that described vm-esh-nas as lkraven-only are updated.
67 lines
2.6 KiB
Markdown
67 lines
2.6 KiB
Markdown
# vm-esh-nas
|
|
|
|
Docker VM on the `esh-pve-nas` hypervisor (10.0.50.55), at the ESH home
|
|
lab. Runs nas-adjacent containers that need local mounts of the shares
|
|
served by the Debian NAS at `10.0.50.50` — Filezilla, a Beszel agent, a
|
|
Dozzle agent, and Dockge.
|
|
|
|
## Network
|
|
|
|
- **LAN IP:** 10.0.50.154
|
|
- **FQDN:** `vm-esh-nas.esteban.net`
|
|
- **SSH:** `infra-ops@10.0.50.154`: the fleet ops identity, uid/gid 850, NOPASSWD sudo, docker group.
|
|
Bootstrapped by Prime on 2026-09-27. `lkraven@vm-esh-nas` (the `vm-esh-nas` alias) is the human
|
|
account, key auth, with password sudo only.
|
|
|
|
## Hardware (from latest snapshot)
|
|
|
|
- **OS:** Debian 12 (bookworm), kernel 6.1.0-32-amd64
|
|
- **CPU:** 4 cores, Intel Xeon W-1250 @ 3.30 GHz (shared with the host)
|
|
- **RAM:** 3.8 GB total, ~3.1 GB available
|
|
- **Root disk:** 125 GB at 7% used
|
|
- **NFS mounts (all from `10.0.50.50`):**
|
|
- `/mnt/share` — 96 TB, 4 TB used (general share)
|
|
- `/mnt/music` — 92 TB, empty
|
|
- `/mnt/books` — 92 TB, 96 GB used
|
|
- `/mnt/media` — 111 TB, 20 TB used
|
|
- All in `/etc/fstab`, reconnect on boot.
|
|
|
|
## What runs here
|
|
|
|
| Container | Image | Role |
|
|
|---|---|---|
|
|
| `beszel-agent` | henrygd/beszel-agent:latest | Metrics agent reporting to the hub on ana-docker |
|
|
| `dozzle-agent` | amir20/dozzle:latest | Log agent (exposed on port 7007) |
|
|
| `dockge-dockge-1` | louislam/dockge:latest | Local compose UI, port 5001 |
|
|
| `filezilla` | jlesage/filezilla | Web Filezilla on port 5800 (referenced in homepage bookmarks.yaml under UltraSeedbox) |
|
|
|
|
## Refresh state
|
|
|
|
```bash
|
|
scripts/refresh-server-info.sh vm-esh-nas
|
|
```
|
|
|
|
## Stack mirror layout
|
|
|
|
- `stacks-mirror/vm-esh-nas/beszel-agent-esh-nas/` — Beszel agent (canonical in `stacks/beszel/`)
|
|
- `filezilla` — canonical in `stacks/filezilla/`
|
|
- Other stacks (`dockge`, `dozzle-agent`) not yet canonicalized; run `sync-stacks.sh vm-esh-nas` to pull them into the mirror.
|
|
|
|
## Placement rule
|
|
|
|
NAS-adjacent Docker host. Good choice for anything that needs direct NFS
|
|
mounts (`/mnt/{share,music,books,media}`) without routing through another
|
|
VM. Low RAM ceiling (3.8 GB) — keep heavy workloads elsewhere.
|
|
|
|
## Known nits
|
|
|
|
- **Check restart policies after any reboot of this host.** `dockge`,
|
|
`dozzle-agent`, and `beszel-agent` carry restart policies; `filezilla` did
|
|
not, and stayed down silently for four days after the 2026-08-18 reboot
|
|
(fixed 2026-08-22 — `restart: unless-stopped`). Anything else added here
|
|
needs the policy set explicitly.
|
|
- `/opt/docker/compose` is world-writable (drwxrwxrwx). Harmless but
|
|
worth tightening at some point.
|
|
- `/opt/docker/conf` doesn't exist yet; stacks that need bind-mounted
|
|
config (Traefik, CrowdSec, etc.) would need to create it.
|