b842212b06
Six PFI VMs/LXCs previously known only via proxmox_inspect.sh —
covered by vzdump but not in servers/, so operational context
(roles, backup posture, ssh target) was missing:
pfi-ana-webhost (VMID 110) — web workload
ana-filebot (LXC 112) — file-task automation
pfi-pteradactyl (VMID 107) — Pterodactyl game panel
pfi-tacticalrmm (VMID 111) — TacticalRMM remote-management
pfi-postgres (VMID 105) — shared Postgres (vaultwarden/gitea/
paperless backends)
ana-wg (LXC 113) — WireGuard VPN gateway
Plus three SureFire tenant hosts at the Anaheim colo:
sfsrv-ana — tenant Proxmox hypervisor (10.250.250.115:8006)
sf-ana-container — container workload on that Proxmox
sf-r630 — physical R630 (iDRAC 10.250.250.110 for PFI-side
hardware mgmt; OS is tenant-scoped)
Each server dir has README + ssh-target where applicable. SureFire
entries explicitly document tenancy scope: PFI provides hosting,
SureFire owns the OS; management actions need tenant coordination.
SureFire hosts have no ssh-target by default.
Homepage Infra - ANA gains two new cards:
- SFsrv-ANA (https://10.250.250.115:8006, si-proxmox icon)
- SF-R630-iDRAC (https://10.250.250.110, si-dell icon)
PFI-ANA-ML2 BMC gained an href since it has a usable web UI.
CLAUDE.md fleet table extended with all 9 new rows. Placement-rules
section notes the SureFire tenant boundary.
Memory: new project_surefire_tenant.md so future sessions know sf-*
hosts are tenant-scoped by default.
pfi-postgres
Shared Postgres cluster at the Anaheim colo.
Network
- LAN IP: 10.250.50.80
- Port: 5432
- SSH:
lkraven@pfi-postgres
Infrastructure
- Hypervisor:
pfi-pve(VMID 105) - Type: Linux VM
- Site: Anaheim (PFI colo)
Role
Shared Postgres server backing multiple ana-docker stacks:
| Consumer | DB | User |
|---|---|---|
| vaultwarden | vaultwarden |
vaultwarden |
| gitea | gitea |
gitea |
| paperless-ngx (on esh-docker-vm) | paperless-ng |
paperless-ng |
| (Likely others — audit as more stacks surface) |
Backup coverage
- VM-image: ✅ vzdump on pfi-pve (daily)
- App-consistent DB dumps: ✅ each dependent stack's host runs a
pre-backup hook that
pg_dumps its database from this server into its own restic stage:- ana-docker: vaultwarden + gitea (via
configs/restic/ana-docker/pre-backup.sh) - esh-docker-vm: paperless-ngx (via
configs/restic/esh-docker-vm/pre-backup.sh)
- ana-docker: vaultwarden + gitea (via
- File-level restic on this host: ❌ not configured. Optional — the VM-image + per-consumer pg_dumps together cover most recovery paths.
Known weak password (rotate)
The inline passwords currently in use for these databases are trivially weak:
gitea/giteapaperless-ng/paperless-ng
Rotation is on the post-backup-pipeline cleanup list. Exposed in the 2026-04-21 transcripts.
Refresh state
scripts/refresh-server-info.sh pfi-postgres
Discovered via
FortiGate DHCP (MAC c2:1f:cc:71:66:d0).