Files
esh-pfi-infrastructure/servers/sfsrv-ana
vh 60367b307f servers: add new host dirs, refresh fleet snapshots, orientation doc
Bundles the inventory expansion since 2026-04-22:

- New host dirs (READMEs + ssh-target where dir name doesn't resolve):
    ana-nas, ana-wg, esh-vm-db, nh3-nas, pbs-ana, pbs-nh3.
- New PFI VM snapshots (registered + key-installed 2026-04-23):
    ana-filebot, pfi-ana-webhost, pfi-postgres, pfi-pteradactyl,
    pfi-tacticalrmm, sf-ana-container, sfsrv-ana (system + proxmox).
- servers/irv-ml1: ONBOARDING.md (the first-time setup notes from when
  the host was brought into the fleet) + ssh-target (10.100.79.3 over
  the WG tunnel — name doesn't DNS-resolve from this workstation).
- servers/{ana-ml2,pfi-pve,sf-r630}/README.md: updates to capture BMC
  IPs, the iDRAC vs OS hostname distinction (sf-r630 hardware =
  sfsrv-ana OS), and the ana-ml2 Supermicro BMC (10.250.250.50,
  distinct from the Dell R750xs iDRAC).
- configs/homepage/docker.yaml: irv-ml1-docker provider added so
  homepage auto-discovers irv-ml1's stacks over the WG tunnel.
- docs/orientation.md: narrative fleet overview written for fresh
  Claude sessions — sites, backup architecture, governing principles,
  gotchas, where-to-look guide. Pointed at from CLAUDE.md.
2026-04-24 21:56:46 -07:00
..

sfsrv-ana

SureFire-client Proxmox hypervisor at the Anaheim colo. Client-owned equipment but PFI-managed under the hosting agreement — we have SSH and are responsible for operations.

Client context

  • Client: SureFire (SF prefix is SF-client hosts)
  • PFI role: full-service managed host (rack, power, network, OS ops, backups)

Network

  • LAN IP: 10.250.250.115
  • FQDN: not yet in DNS / /etc/hosts — add a line to the workstation's hosts file to make short-name resolution work:
    10.250.250.115  sfsrv-ana
    
  • Web UI: https://10.250.250.115:8006 (Proxmox VE)
  • SSH: root@10.250.250.115 (key auth — same pattern as other PVE nodes)

Infrastructure

  • Type: Proxmox VE hypervisor (bare metal)
  • Site: Anaheim (PFI colo)

Hosts SureFire's VMs, including:

  • sf-ana-container (10.250.150.100) on the dedicated SF container subnet

Backup coverage

  • VM-image: status unknown — probe with scripts/refresh-proxmox-info.sh sfsrv-ana once SSH is verified. If no vzdump jobs are configured, set them up the same as pfi-pve (daily 01:00 into a network target).
  • File-level restic: not yet configured.

This is on the open work list — once we've validated SSH + refreshed the Proxmox snapshot, add a configs/restic/sfsrv-ana/ profile if it's running hosted workloads whose state we care about beyond the VM-image layer.

Refresh state

scripts/refresh-proxmox-info.sh sfsrv-ana

Discovered via

scripts/discover-fortigate.sh 10.250.250.1 on 2026-04-21 (MAC 44:a8:42:33:d9:c3).