NH3 site visit done: Secure Boot off, iGPU restored as boot VGA, AMT port cabled. - nh3-pve: NVIDIA 580.178.04 (DKMS, open modules) via pve-nvidia-host.yaml. - nh3-ml1 = CT 109 @ 10.100.50.80 via gpu-lxc.yaml; embed-rerank (TEI 1.9.4) deployed with HOST_NAME/HOST_IP labels. - Parity vs esh-ml1 (1,126 texts, 2 runs/host, controls): embed cosine min 0.999993 = own noise floor; overlap@10 1.000 vs MRL-256 positive control 0.684; rerank top-1 1.00, max diff 0.0014 vs floor 0.0020. On-box speed identical within rep spread. - gpu-lxc.yaml: first step upgrades lxc-pve to >= 6.0.0-2 (Proxmox fix #7006). With 6.0.0-1 every docker run in a nesting CT failed on runc 1.5's sysctl reopen; applied on nh3-pve (one package). - pve-nvidia-host.yaml: document that the headers meta drags in the newest kernel (nh3-pve went 6.8.12-11 -> -43 at the next reboot). - Monitoring: Beszel NVIDIA agent + 5 alerts, Kuma #29/#30, Homepage nh3-ml1-docker, Dozzle agent (hub 8 clients). DNS nh3-ml1.nh3.internal. - nh3-pve README: SB/IGFX/driver/kernel state, btmtk oops on -4x kernels, AMT cabled but unreachable on the network. Gateway routing to nh3-ml1 is not changed.
128 lines
8.8 KiB
YAML
128 lines
8.8 KiB
YAML
# Fleet internal DNS — the source of truth for *.internal names.
|
|
#
|
|
# THIS FILE IS AUTHORITATIVE. `scripts/dns-sync.sh` reconciles every resolver
|
|
# against it: names here are created, names removed here are deleted, and
|
|
# names edited here are updated. Do NOT add .internal names in the AdGuard UI
|
|
# — the next sync will delete them.
|
|
#
|
|
# WHAT THE SYNC WILL NOT TOUCH: any rewrite outside the `.internal` zone. The
|
|
# ESH resolver carries hand-made `esteban.net` entries that predate this file
|
|
# and are deliberately left alone. Authority is scoped to the zone, not to the
|
|
# resolver's whole table.
|
|
#
|
|
# NAMING: <host>.<site>.internal, sites `ana` / `esh` / `nh3` (operator,
|
|
# 2026-08-19). `.internal` is ICANN-reserved for exactly this use since 2024,
|
|
# which is why it is used here rather than `.local` (reserved for mDNS) or a
|
|
# made-up TLD that could later collide with a real one.
|
|
#
|
|
# EVERY name is published to EVERY resolver, so `ana-docker.ana.internal`
|
|
# resolves from ESH and NH3 too. The site label says where a host IS, not
|
|
# which resolver knows about it.
|
|
#
|
|
# ⚠️ THE v6 COLUMN IS EMPTY ON PURPOSE, AND MUST STAY DECLARATIVE.
|
|
# No fleet host has a global IPv6 address today (verified 2026-08-19: ESH's
|
|
# /56 is live only on esh-cameras, NH3's LANs are back to ipv6_interface_type
|
|
# none, the colo has no v6 at all). When v6 lands, do NOT paste in whatever
|
|
# `ip -6 addr` happens to show: SLAAC addresses are either EUI-64 (MAC-coupled)
|
|
# or privacy-extension (they rotate), and UniFi has no v6 equivalent of a DHCP
|
|
# reservation. A v6 address only belongs in this file once it has been pinned
|
|
# STATICALLY on the host itself — otherwise the record rots silently and the
|
|
# name starts lying, which is worse than having no record.
|
|
|
|
zone: internal
|
|
|
|
sites:
|
|
ana:
|
|
subnet: 10.250.0.0/16
|
|
resolver: 10.250.50.70 # ana-docker — AdGuard #3, stood up for this
|
|
# ⚠️ NOT 8080. ana-docker already has :8080 and :3000 taken, so this
|
|
# AdGuard's API is on 8053. The port lives here rather than in the script
|
|
# precisely so the odd one out cannot be forgotten.
|
|
api_port: 8053
|
|
description: Anaheim colo
|
|
esh:
|
|
subnet: 10.0.0.0/16
|
|
resolver: 10.0.50.45 # esh-docker-vm
|
|
api_port: 8080
|
|
description: ESH home lab (esteban.net)
|
|
nh3:
|
|
subnet: 10.100.0.0/16
|
|
resolver: 10.100.50.40 # nh3-docker
|
|
api_port: 8080
|
|
description: NH3 office
|
|
|
|
hosts:
|
|
# ---- ana: Anaheim colo ----
|
|
- {name: ana-docker, site: ana, v4: 10.250.50.70, note: general-purpose docker host}
|
|
# ---- fv: Fountain Valley colo (piggyback DNS until FV has its own resolver) ----
|
|
- {name: fv-ml1, site: fv, v4: 10.251.50.54, note: GPU inference, 4x RTX PRO 6000 Blackwell Max-Q (ex ana-ml2, relocated 2026-09-12)}
|
|
- {name: ana-nas, site: ana, v4: 10.250.50.50, note: CT109 on pfi-pve — NFS/SMB}
|
|
- {name: ana-filebot, site: ana, v4: 10.250.50.53, note: file-task automation}
|
|
- {name: ana-wg, site: ana, v4: 10.250.50.252, note: WireGuard host}
|
|
- {name: corviduo-dev, site: ana, v4: 10.250.50.152, note: Worldtree-team dev VM (PFI-hosted)}
|
|
- {name: pbs-ana, site: ana, v4: 10.250.50.90, note: Proxmox Backup Server — fleet primary}
|
|
- {name: pfi-ana-webhost, site: ana, v4: 10.250.50.52, note: web workload}
|
|
- {name: pfi-postgres, site: ana, v4: 10.250.50.80, note: shared Postgres}
|
|
- {name: pfi-pteradactyl, site: ana, v4: 10.250.50.55, note: game panel}
|
|
- {name: pfi-tacticalrmm, site: ana, v4: 10.250.50.57, note: TacticalRMM}
|
|
- {name: pfi-pve, site: ana, v4: 10.250.250.31, note: Proxmox hypervisor}
|
|
- {name: ana-gw, site: ana, v4: 10.250.0.1, note: FortiGate-80F edge}
|
|
- {name: pfi-pve-idrac, site: ana, v4: 10.250.250.30, note: iDRAC — OOB for pfi-pve}
|
|
- {name: fv-ml1-bmc, site: fv, v4: 10.251.250.50, note: BMC for fv-ml1 (Supermicro/ATEN; 802.1q VLAN tag must stay DISABLED)}
|
|
- {name: fv-gw, site: fv, v4: 10.251.50.1, note: OPNsense gateway vb-gateway, mesh subnet-router for 10.251.0.0/16; public 172.83.89.66 = fv.phasefinal.com}
|
|
# SureFire tenant hardware — PFI-managed under the hosting agreement.
|
|
- {name: sfsrv-ana, site: ana, v4: 10.250.250.115, note: SureFire tenant hypervisor}
|
|
- {name: sf-ana-container, site: ana, v4: 10.250.150.100, note: SureFire tenant container host}
|
|
- {name: sf-r630-idrac, site: ana, v4: 10.250.250.110, note: SureFire tenant R630 iDRAC}
|
|
|
|
# ---- nh3: NH3 office ----
|
|
- {name: nh3-docker, site: nh3, v4: 10.100.50.40, note: general-purpose docker host + AdGuard}
|
|
- {name: pfi-gx10, site: nh3, v4: 10.100.50.60, note: GB10 Grace Blackwell, 121 GB unified — DHCP RESERVATION on the UDM, not a host static, so the box stays portable}
|
|
- {name: nh3-dev, site: nh3, v4: 10.100.10.50, note: dev box, fleet sidecars, Claude sessions}
|
|
- {name: nh3-extdev, site: nh3, v4: 10.100.50.42, note: manager / external-dev box}
|
|
- {name: nh3-nas, site: nh3, v4: 10.100.50.50, note: Synology RS2418+}
|
|
- {name: nh3-pve, site: nh3, v4: 10.100.250.60, note: Proxmox hypervisor}
|
|
- {name: pbs-nh3, site: nh3, v4: 10.100.50.90, note: Proxmox Backup Server — DR mirror}
|
|
- {name: nh3-gw, site: nh3, v4: 10.100.0.1, note: UniFi UDM Pro SE — gateway + controller}
|
|
# Irvine is not its own DNS site: it is a single box (irv-ml1) reached over
|
|
# the headscale mesh, so it is named under nh3 rather than getting its own
|
|
# resolver. Its real LAN is 10.6.110.0/24 (Irvine), advertised fleet-wide as
|
|
# a mesh subnet route — NOT NH3's 10.100.79.0/24 (that wg0 lifeline is
|
|
# dormant post-cutover 2026-09-06). The mesh node IP is 100.64.0.6; we resolve
|
|
# to the LAN IP to match the host→LAN-IP model every other entry uses.
|
|
# Revisit if Irvine ever grows beyond this one host.
|
|
- {name: irv-ml1, site: nh3, v4: 10.6.110.50, note: GPU host (Irvine, via headscale mesh) — 3090 + A6000; mesh node 100.64.0.6}
|
|
|
|
# ---- esh: ESH home lab ----
|
|
- {name: esh-docker-vm, site: esh, v4: 10.0.50.45, note: general-purpose docker host + AdGuard}
|
|
- {name: esh-nas, site: esh, v4: 10.0.50.50, note: NAS}
|
|
- {name: esh-pve, site: esh, v4: 10.0.250.35, note: Proxmox hypervisor}
|
|
- {name: esh-pve-nas, site: esh, v4: 10.0.50.55, note: Proxmox hypervisor — storage/media}
|
|
- {name: esh-vm-db, site: esh, v4: 10.0.50.60, note: PostgreSQL + MongoDB}
|
|
- {name: esh-ml1, site: esh, v4: 10.0.50.80, note: CT110 on esh-pve — RTX 2000E Ada, embedding + reranking (TEI) + reward seat}
|
|
- {name: vm-esh-nas, site: esh, v4: 10.0.50.154, note: NAS-adjacent docker host}
|
|
- {name: esh-filebot, site: esh, v4: 10.0.50.70, note: restic / file-sync VM}
|
|
- {name: esh-gw, site: esh, v4: 10.0.250.1, note: esh-gw}
|
|
- {name: esh-udm, site: esh, v4: 10.0.0.1, note: UniFi UDM Pro Max — gateway + controller}
|
|
- {name: plex, site: esh, v4: 10.0.50.56, note: media server}
|
|
- {name: jellyfin, site: esh, v4: 10.0.50.57, note: media server}
|
|
- {name: brother, site: esh, v4: 10.0.90.125, note: Brother printer}
|
|
- {name: slzb-mr1u, site: esh, v4: 10.0.90.10, note: SMLIGHT SLZB-MR1U Zigbee/Thread coordinator (esh-iot VLAN 90, PoE on ESH-Media p4); Home Assistant at 10.0.50.46 connects to tcp/6638}
|
|
- {name: ana-scale, site: ana, v4: 10.250.50.45, note: CT114 on pfi-pve — headscale/tailscale subnet router for 10.250.0.0/16}
|
|
- {name: nh3-headscale, site: nh3, v4: 10.100.50.45, note: CT106 on nh3-pve — headscale control plane (public headscale.phasefinal.com:443)}
|
|
- {name: nh3-scale, site: nh3, v4: 10.100.50.46, note: CT107 on nh3-pve — subnet router for 10.100.0.0/16}
|
|
- {name: nh3-ml1, site: nh3, v4: 10.100.50.80, note: CT109 on nh3-pve — RTX 2000E Ada, second embedding + reranking backend (TEI)}
|
|
- {name: esh-scale, site: esh, v4: 10.0.50.65, note: CT108 on esh-pve — subnet router for 10.0.0.0/16}
|
|
|
|
# Service aliases — a name that points at whatever host currently runs it, so
|
|
# consumers reference the SERVICE rather than the box. Changing where something
|
|
# runs becomes a one-line edit here instead of a hunt through configs.
|
|
|
|
aliases:
|
|
- {name: searxng, site: nh3, target: nh3-docker, note: moved off ana-docker 2026-09-03 — colo egress (38.120.12.42) is CAPTCHA-gated by search engines; NH3 egresses residentially}
|
|
- {name: gateway, site: ana, target: ana-docker, note: LiteLLM gateway :4000}
|
|
- {name: booth, site: nh3, target: nh3-dev, note: The Booth :8090}
|
|
- {name: wherethef, site: nh3, target: nh3-dev, note: WhereTF :8093}
|
|
- {name: homepage, site: esh, target: esh-docker-vm, note: fleet dashboard :5100}
|
|
- {name: scriberr, site: fv, target: fv-ml1, note: transcription + diarization :8080 (GPU1)}
|