Files
esh-pfi-infrastructure/servers/esh-pve-2

esh-pve-2 — Minisforum MS-03, Proxmox VE 9 (ESH)

The second of the two MS-03s (the other is nh3-pve-2). Planned home of esh-dev, which will take over most of nh3-dev's sessions (Prime, 2026-10-02; the move itself is not yet planned). Standalone node, not in the ESH cluster (pve + esh-nas-pve, still on PVE 8.4).

  • Address: 10.0.10.70, DHCP, TEMPORARY. Prime: the permanent address "can wait". When it is chosen, reserve it on MAC 38:05:25:3b:9c:12 (see AMT below: the host and AMT share that MAC and that address).
  • Access: ssh infra-ops@10.0.10.70 (fleet key, NOPASSWD sudo, Defaults:infra-ops log_output), set up by Prime 2026-10-02. Web UI https://10.0.10.70:8006.
  • PVE 9.2.21, kernel 7.0.14-20-pve (2026-10-02 2210 boot).

Hardware

Board MS-03 (PTWSA), Intel Panther Lake
NICs nic1 I226-LM 2.5G (vPro/AMT), the only cabled port and vmbr0's port; nic0 RTL8127 10G; nic2/nic3 X710 SFP+
Boot disk Toshiba KXG60ZNV256G 256 GB, serial 199A3537K01N: ESP, LVM pve (root 70 G, swap 4 G, local-lvm 14 G)
VM disk Crucial CT1000E100SSD8 1 TB, serial 2611EAD0291A: whole-disk LVM-thin vmstore (913 GiB)

⚠ nvme0/nvme1 swap between boots (seen 2026-10-02: the 1 TB was nvme0 before the reboot and nvme1 after). Address disks by /dev/disk/by-id/… (serial), never nvmeXn1.

Disks and boot (2026-10-02, Prime)

playbooks/esh-pve-2-disk-prep.yaml, re-runnable:

  • Firmware boot entries: Boot0000 proxmox (256 GB, shim) first; Boot0006 UEFI OS (same ESP's fallback loader, kept); built-in EFI shell (inactive). Deleted Boot0005, the fallback loader of an older Proxmox install on the 1 TB drive. GRUB itself never listed that install: os-prober is not installed and PVE disables it.
  • 1 TB drive: held that old install (VG renamed pve-OLD-2E68F512 by the installer, thin pool 0.00% used). VG and PV removed, signatures wiped, GPT zapped, whole drive discarded, then pvesh create …/disks/lvmthin (the GUI path) made vmstore, content images,rootdir, node-restricted. Verified with a 1 GiB alloc/free, again after the reboot.
  • Format choice: LVM-thin, the PVE default and the same as the boot drive and esh-pve. ZFS was the alternative (checksums, compression, replication) but is heavy on a single DRAM-less consumer drive. Cheap to change only while vmstore is empty.

Intel AMT — phones home to MeshCentral (2026-10-02 2218)

  • AMT and Proxmox share the I226-LM port, its MAC and its IP (AMT DHCP, SharedMAC/SharedDynamicIP true): AMT answers on 10.0.10.70 for its own ports only. AMT 21.0.6, Admin Control Mode, MEBx password = the one on nh3-pve / nh3-pve-2, vaulted esh-pve-2/amt-admin.
  • Set over WS-Man before phone-home: KVM enabled, redirection listener on (IDER/SOL/KVM), OptInRequired 0 (no consent code). Then scripts/amt-cira-setup.py --apply (MPS rmm-mesh.phasefinal.com:4433, user CtDDEpGX0VLlJ1X9, periodic 10 s policy, random environment-detection domain).
  • MeshCentral device esh-pve-2-amt (group PFI-AMT; credentials + tls 1 set on the device). Tunnel arrives from ESH's public IP 128.177.138.182. Read back 2221: CIRA connected, power on, AMT 21.0.6.
  • ⚠ Manage it through MeshCentral. In phone-home ("outside") mode AMT refuses LAN management, so scripts/amt-wsman.py against 10.0.10.70 no longer works. Last resort: MEBx (Ctrl+P at boot), on site.
  • ⚠ Keep nic1 up. On these boards igc powers the PHY off when Linux downs the port, and AMT loses its link (auto-memory reference_ms01_amt_port_must_stay_up). Today it is vmbr0's bridge port, so it stays up. If vmbr0 ever moves to another NIC, give nic1 its own auto nic1 / iface nic1 inet manual.
  • ⚠ AMT must stay on DHCP for phone-home (Intel: CIRA does not work on a static IP). When the permanent address is chosen, make it a DHCP reservation on 38:05:25:3b:9c:12. If the host goes static, use that same address so the two keep sharing one IP.
  • Power schemes offered: "Mobile: ON in S0" and "ON in S0, ME Wake in S3, S4-5 (AC only)". Not checked which is active. Its twin nh3-pve-2 kept its tunnel while powered off (2026-10-02 2221), so this one probably does too.
  • KVM needs an active iGPU output. A 4K dummy plug blacked the AMT console on nh3-pve-2 once Linux took the display; use a 1080p plug.