Beszel agents are installed and verified across the fleet but the artifacts that produced them were never committed, so the deployment existed only on the hosts. Adds the per-host agent environment files (PORT, NICS, EXTRA_FILESYSTEMS and the hub's PUBLIC key), the systemd unit, the guest install script, the Synology compose, and the elway playbooks for native, guest-stage, guest-install and Synology paths. The two dated memory detail files covering the priority-1 and priority-2 waves ship alongside, per the convention that memory lands with the work it describes. No credentials here. The KEY= value in every host env is the Beszel hub's public ed25519 key, identical across all nine and public by design; the agent README says so explicitly. The nh3-nas sudo password referenced in the runbook prose lives in Vaultwarden and the helper scripts named there never contained it. ⚠ Overlapping VMIDs across hypervisors are a standing trap and are recorded in the priority-2 notes: pfi-pve 105=postgres and 100=pbs-ana, nh3-pve 105=pbs-nh3. ⚠ PBS-NH3's export was ~75.5% used at capture; resource checks are not job success monitoring and should not be read as such.
949 B
Priority 2 complete
pfi-postgres, esh-vm-db, pbs-ana, pbs-nh3 have native unprivileged 0.18.7 agents, enabled at boot and fresh hub samples verified 2026-09-12 01:56Z. Sixteen new Disk/CPU/Memory/Status rules verified, existing infra-ops bridge route retained. Fleet 17/18 up; only known ana-ml2 outage. DB/PBS services verified running, Postgres accepts connections; no application or VM restarts performed.
ESH uses existing infra-ops sudo. Other three: lkraven key SSH works, sudo needs password, no matching vault entries. Deployed through EXISTING Proxmox guest agents (no account/access changes): pfi-pve 105=postgres, 100=pbs-ana; nh3-pve 105=pbs-nh3. Never confuse overlapping VMIDs. Canonical stage/install playbooks and host envs saved; runbook configs/beszel-agent/PRIORITY2.md. PBS-NH3 export ~75.5% used; PBS-ANA ~6.6%. Resource checks are not job-success monitoring. Local changes still uncommitted, awaiting main-branch approval.