a95717e810
pfi-gx10 moved from desk Wi-Fi (10.100.10.226, VLAN 10) to the rack on 10.100.50.60 (nh3-servers, VLAN 50), reachable as pfi-gx10.nh3.internal. The address is a DHCP RESERVATION on the UDM, not a host static. Operator ruling during the move, and the better design: a host-side static works until the box moves and is then a stale netplan file on a machine whose address you no longer know. The pre-written playbook wrote a host static; it is kept for its safety ordering and annotated as retired. The port arrived on the native VLAN, not the server VLAN, so switch port 22 was repointed first. port_overrides is a whole-array PUT — two unrelated overrides on ports 21 and 23 were read, preserved and written back, with the original array backed up to a file before the change. Wi-Fi stayed up as the escape hatch until the wired path was proven from outside, and was downed last as its own step. The step worth keeping: while Wi-Fi was up, traffic to nh3-dev still preferred wlP9s9 because that interface sits directly on the userland subnet, so reachability proved nothing about the wired path. `ping -I enP7s7` across the VLAN boundary is what actually settled it before the hatch came down.
docs/
Navigation map for the documentation tree. New session? Read
orientation.md first — it's the narrative overview
of the fleet, backup architecture, governing principles, and gotchas,
and it points at everything else.
Tree
docs/
├── orientation.md # start here — fleet overview + where-to-look guide
├── runbooks/ # ops runbooks (recovery, deployment phases)
│ ├── disaster-recovery.md
│ ├── nh3-prune-ritual.md
│ └── pbs-deployment.md
└── pfi/ # PFI-specific reference (services, models, VMs)
├── docker-stack.md
├── model-list.md
├── proxmox-vms.md
├── recommended-model-settings.md
├── vm-102-matrix-appservice.md
└── vm-102-matrix-synapse.md
What goes where
runbooks/— step-by-step ops procedures. Anything you'd reach for during an incident or while standing up new infrastructure. Examples: disaster recovery (blast-radius tiers + restoration steps), PBS deployment (9-phase rollout). New runbook → new file here.pfi/— PFI-specific reference material that's too narrow for the top-level CLAUDE.md but doesn't change incident response. AI model inventory, recommended inference settings, Matrix bridge config, Proxmox VM map. New stable reference → new file here.- Top-level (
docs/orientation.md,docs/README.md) — narrative guides about the workspace itself, not about specific infra.
Cross-references
- Fleet topology + servers table: top-level
CLAUDE.md. - Open work + recent milestones: top-level
STATUS.md. - Durable cross-session facts:
~/.claude/projects/-home-lkraven-development-eshpfi-management/memory/.
Conventions
- Markdown, GitHub-flavored. CommonMark renders fine in most viewers.
- File names are lowercase-kebab-case, descriptive. No dates in filenames — git history covers that.
- One topic per file. If a file grows past ~500 lines, look for a natural split before adding more.
- No checked-in binaries or checksums. Build/release artifacts belong
in a build pipeline or
tools/, notdocs/.