b842212b06
Six PFI VMs/LXCs previously known only via proxmox_inspect.sh —
covered by vzdump but not in servers/, so operational context
(roles, backup posture, ssh target) was missing:
pfi-ana-webhost (VMID 110) — web workload
ana-filebot (LXC 112) — file-task automation
pfi-pteradactyl (VMID 107) — Pterodactyl game panel
pfi-tacticalrmm (VMID 111) — TacticalRMM remote-management
pfi-postgres (VMID 105) — shared Postgres (vaultwarden/gitea/
paperless backends)
ana-wg (LXC 113) — WireGuard VPN gateway
Plus three SureFire tenant hosts at the Anaheim colo:
sfsrv-ana — tenant Proxmox hypervisor (10.250.250.115:8006)
sf-ana-container — container workload on that Proxmox
sf-r630 — physical R630 (iDRAC 10.250.250.110 for PFI-side
hardware mgmt; OS is tenant-scoped)
Each server dir has README + ssh-target where applicable. SureFire
entries explicitly document tenancy scope: PFI provides hosting,
SureFire owns the OS; management actions need tenant coordination.
SureFire hosts have no ssh-target by default.
Homepage Infra - ANA gains two new cards:
- SFsrv-ANA (https://10.250.250.115:8006, si-proxmox icon)
- SF-R630-iDRAC (https://10.250.250.110, si-dell icon)
PFI-ANA-ML2 BMC gained an href since it has a usable web UI.
CLAUDE.md fleet table extended with all 9 new rows. Placement-rules
section notes the SureFire tenant boundary.
Memory: new project_surefire_tenant.md so future sessions know sf-*
hosts are tenant-scoped by default.
sf-r630
SureFire tenant physical server at the Anaheim colo — Dell PowerEdge R630. Owner operates the OS; PFI provides rack + network.
Tenancy
- Owner: SureFire (tenant)
- PFI role: hosting provider
Network
- iDRAC BMC IP: 10.250.250.110 (on the management subnet)
- OS-side LAN IP: unknown — not surfaced via our DHCP discovery. May be static, on a non-DHCP interface, or assigned to a different subnet served by SureFire's own gear.
- iDRAC Web UI: https://10.250.250.110/
Infrastructure
- Type: Physical Dell PowerEdge R630
- Site: Anaheim (PFI colo)
- Management: iDRAC only from the PFI side (power, console, hardware health). OS-level access is tenant-scoped.
Backup coverage
- Not applicable from the PFI side — tenant equipment. If hosting terms require PFI to provide backup, coordinate with SureFire on in-VM or OS-agent approach.
Discovered via
scripts/discover-fortigate.sh 10.250.250.1 on 2026-04-21 — DHCP
lease on the management interface (MAC 74:e6:e2:fe:2c:7c, VCI
iDRAC).