Files
esh-pfi-infrastructure/servers/pfi-postgres/README.md
T
vh b842212b06 fleet: register 9 hosts surfaced by gap-analysis audit
Six PFI VMs/LXCs previously known only via proxmox_inspect.sh —
covered by vzdump but not in servers/, so operational context
(roles, backup posture, ssh target) was missing:

  pfi-ana-webhost  (VMID 110)  — web workload
  ana-filebot      (LXC  112)  — file-task automation
  pfi-pteradactyl  (VMID 107)  — Pterodactyl game panel
  pfi-tacticalrmm  (VMID 111)  — TacticalRMM remote-management
  pfi-postgres     (VMID 105)  — shared Postgres (vaultwarden/gitea/
                                 paperless backends)
  ana-wg           (LXC  113)  — WireGuard VPN gateway

Plus three SureFire tenant hosts at the Anaheim colo:

  sfsrv-ana        — tenant Proxmox hypervisor (10.250.250.115:8006)
  sf-ana-container — container workload on that Proxmox
  sf-r630          — physical R630 (iDRAC 10.250.250.110 for PFI-side
                     hardware mgmt; OS is tenant-scoped)

Each server dir has README + ssh-target where applicable. SureFire
entries explicitly document tenancy scope: PFI provides hosting,
SureFire owns the OS; management actions need tenant coordination.
SureFire hosts have no ssh-target by default.

Homepage Infra - ANA gains two new cards:
  - SFsrv-ANA (https://10.250.250.115:8006, si-proxmox icon)
  - SF-R630-iDRAC (https://10.250.250.110, si-dell icon)
PFI-ANA-ML2 BMC gained an href since it has a usable web UI.

CLAUDE.md fleet table extended with all 9 new rows. Placement-rules
section notes the SureFire tenant boundary.

Memory: new project_surefire_tenant.md so future sessions know sf-*
hosts are tenant-scoped by default.
2026-04-21 14:29:43 -07:00

58 lines
1.5 KiB
Markdown

# pfi-postgres
Shared Postgres cluster at the Anaheim colo.
## Network
- **LAN IP:** 10.250.50.80
- **Port:** 5432
- **SSH:** `lkraven@pfi-postgres`
## Infrastructure
- **Hypervisor:** `pfi-pve` (VMID **105**)
- **Type:** Linux VM
- **Site:** Anaheim (PFI colo)
## Role
Shared Postgres server backing multiple ana-docker stacks:
| Consumer | DB | User |
|---|---|---|
| vaultwarden | `vaultwarden` | `vaultwarden` |
| gitea | `gitea` | `gitea` |
| paperless-ngx (on esh-docker-vm) | `paperless-ng` | `paperless-ng` |
| (Likely others — audit as more stacks surface) |
## Backup coverage
- **VM-image:** ✅ vzdump on pfi-pve (daily)
- **App-consistent DB dumps:** ✅ each dependent stack's host runs a
pre-backup hook that `pg_dump`s its database from this server into
its own restic stage:
- ana-docker: vaultwarden + gitea (via `configs/restic/ana-docker/pre-backup.sh`)
- esh-docker-vm: paperless-ngx (via `configs/restic/esh-docker-vm/pre-backup.sh`)
- **File-level restic on this host:** ❌ not configured. Optional — the
VM-image + per-consumer pg_dumps together cover most recovery paths.
## Known weak password (rotate)
The inline passwords currently in use for these databases are
trivially weak:
- `gitea` / `gitea`
- `paperless-ng` / `paperless-ng`
Rotation is on the post-backup-pipeline cleanup list. Exposed in the
2026-04-21 transcripts.
## Refresh state
```bash
scripts/refresh-server-info.sh pfi-postgres
```
## Discovered via
FortiGate DHCP (MAC `c2:1f:cc:71:66:d0`).