63 lines
3.0 KiB
Markdown
63 lines
3.0 KiB
Markdown
# pfi-tacticalrmm
|
|
|
|
Tactical RMM (remote monitoring + management) server at the Anaheim colo.
|
|
|
|
## Network
|
|
|
|
- **LAN IP:** 10.250.50.57
|
|
- **SSH:** `lkraven@pfi-tacticalrmm`
|
|
|
|
## Infrastructure
|
|
|
|
- **Hypervisor:** `pfi-pve` (VMID **111**)
|
|
- **Type:** Linux VM
|
|
- **Site:** Anaheim (PFI colo)
|
|
|
|
## Role
|
|
|
|
[TacticalRMM](https://tacticalrmm.com/) — open-source RMM platform.
|
|
Monitors and manages endpoints, pushes patches, runs scripts, etc.
|
|
|
|
## MeshCentral (bundled with TacticalRMM) — facts checked 2026-10-02
|
|
|
|
- Runs natively (`meshcentral.service`, user `tactical`, `/meshcentral`), Node 18.20.8, MeshCentral 1.2.0,
|
|
postgres-backed. Public at `https://rmm-mesh.phasefinal.com` (nginx terminates TLS, `tlsOffload`), MPS
|
|
(Intel AMT CIRA) at `rmm-mesh.phasefinal.com:4433`. 2FA is NOT forced (`force2factor` unset).
|
|
- **HYBRID since 2026-10-02 0812 (Prime: "hybrid, make it so").** `settings.WANonly` set false (backup
|
|
`config.json.bak-20261002-hybrid`); the log says "Hybrid (LAN + WAN) mode". All 14 connected agents came
|
|
back. **nh3-pve's AMT is in `PFI-AMT` as `nh3-pve-amt`** (10.100.250.61, TLS, admin): MeshCentral reached it
|
|
at once (AMT 16.1.25, activated, power on), so the old-TLS worry did not apply. ⚠ The path still runs
|
|
through nh3-scale (CT 107 ON nh3-pve): with nh3-pve down, this AMT is unreachable from here. KVM needs
|
|
an active iGPU output: the NanoKVM serves today; fit the 1080p dummy plug before it moves.
|
|
- Before 2026-10-02: `"WANonly": true` (TacticalRMM's install default). In that mode MeshCentral SILENTLY DROPS
|
|
"Add Intel AMT computer": `meshuser.js` line 2682, `if (args.wanonly == true) return;`. No error, no
|
|
event. LAN-mode AMT needs `WANonly` false (hybrid) + a service restart; CIRA works in WAN mode. TacticalRMM's
|
|
`update.sh` only touches the compression keys of `config.json`, so a WANonly change survives updates.
|
|
- Device groups: `TC2-MacMini` (agent group), `PFI-AMT` (mtype 1, Intel AMT only; created by Prime
|
|
2026-10-02, empty). 24 devices visible to Prime's account, 7 of them report Intel AMT.
|
|
- CLI access: `meshctrl.js` on this host with Prime's login token, vaulted
|
|
`pfi-tacticalrmm/meshcentral-login-token` (one line: `username: ~t:… password: …`). Example:
|
|
`sudo -n -u tactical node /meshcentral/node_modules/meshcentral/meshctrl.js listdevicegroups --url wss://rmm-mesh.phasefinal.com --loginuser <u> --loginpass <p>`.
|
|
Feed the credentials over stdin; never put them in a file or a log.
|
|
|
|
## Backup coverage
|
|
|
|
- **VM-image:** ✅ vzdump on pfi-pve (daily)
|
|
- **File-level restic:** ❌ not yet configured
|
|
|
|
TacticalRMM state (Postgres DB with inventory + automation history,
|
|
MeshCentral config, agent registrations) is critical if used in
|
|
production. Worth setting up app-consistent DB dumps + file-level
|
|
restic if it's the primary management plane.
|
|
|
|
## Refresh state
|
|
|
|
```bash
|
|
scripts/refresh-server-info.sh pfi-tacticalrmm
|
|
```
|
|
|
|
## Discovered via
|
|
|
|
`scripts/discover-fortigate.sh 10.250.250.1` on 2026-04-21 —
|
|
FortiGate DHCP lease (MAC `ba:fa:65:f6:46:25`).
|