fed29be04e
The coordinator arrived on esh-userland (VLAN 10) at a DHCP-assigned 10.0.10.58. It now sits on esh-iot (VLAN 90) at 10.0.90.10, reserved on the UDM and named slzb-mr1u.esh.internal. Address on the network side, not the device — the pfi-gx10 ruling: a reservation moves with the hardware, a device-side static goes stale. 10.0.90.10 is below the 10.0.90.40-250 pool so it cannot be handed out. The MAC is locally administered (ea:f6:0a:ca:f5:b4, no OUI), which is exactly the case where a reservation can silently stop matching. The PoE power-cycle that makes the device re-DHCP is also the stability test, so it cost nothing: it rebooted and came back on exactly 10.0.90.10, which only happens if the MAC held. ESH-Media carried 8 port_overrides and that PUT is a whole-array replace, so the array was diffed to prove exactly one field on one port changed before sending, and read back after. Inter-VLAN reachability needed no firewall work and was proven from inside the HA container before the move, against existing IoT devices. Testing from the Docker host would have proven the wrong thing — HA runs on a macvlan address, 10.0.50.46, not the host's 10.0.50.45. Documented but NOT fixed: the HA container cannot resolve any .internal name (its resolver is Docker's 127.0.0.11, upstream excludes the fleet AdGuard). Pre-existing, verified against names that predate this change. HA should be configured with the IP; changing the DNS of a live home-automation stack is ha-dev's call.
114 lines
7.3 KiB
YAML
114 lines
7.3 KiB
YAML
# Fleet internal DNS — the source of truth for *.internal names.
|
|
#
|
|
# THIS FILE IS AUTHORITATIVE. `scripts/dns-sync.sh` reconciles every resolver
|
|
# against it: names here are created, names removed here are deleted, and
|
|
# names edited here are updated. Do NOT add .internal names in the AdGuard UI
|
|
# — the next sync will delete them.
|
|
#
|
|
# WHAT THE SYNC WILL NOT TOUCH: any rewrite outside the `.internal` zone. The
|
|
# ESH resolver carries hand-made `esteban.net` entries that predate this file
|
|
# and are deliberately left alone. Authority is scoped to the zone, not to the
|
|
# resolver's whole table.
|
|
#
|
|
# NAMING: <host>.<site>.internal, sites `ana` / `esh` / `nh3` (operator,
|
|
# 2026-08-19). `.internal` is ICANN-reserved for exactly this use since 2024,
|
|
# which is why it is used here rather than `.local` (reserved for mDNS) or a
|
|
# made-up TLD that could later collide with a real one.
|
|
#
|
|
# EVERY name is published to EVERY resolver, so `ana-docker.ana.internal`
|
|
# resolves from ESH and NH3 too. The site label says where a host IS, not
|
|
# which resolver knows about it.
|
|
#
|
|
# ⚠️ THE v6 COLUMN IS EMPTY ON PURPOSE, AND MUST STAY DECLARATIVE.
|
|
# No fleet host has a global IPv6 address today (verified 2026-08-19: ESH's
|
|
# /56 is live only on esh-cameras, NH3's LANs are back to ipv6_interface_type
|
|
# none, the colo has no v6 at all). When v6 lands, do NOT paste in whatever
|
|
# `ip -6 addr` happens to show: SLAAC addresses are either EUI-64 (MAC-coupled)
|
|
# or privacy-extension (they rotate), and UniFi has no v6 equivalent of a DHCP
|
|
# reservation. A v6 address only belongs in this file once it has been pinned
|
|
# STATICALLY on the host itself — otherwise the record rots silently and the
|
|
# name starts lying, which is worse than having no record.
|
|
|
|
zone: internal
|
|
|
|
sites:
|
|
ana:
|
|
subnet: 10.250.0.0/16
|
|
resolver: 10.250.50.70 # ana-docker — AdGuard #3, stood up for this
|
|
# ⚠️ NOT 8080. ana-docker already has :8080 and :3000 taken, so this
|
|
# AdGuard's API is on 8053. The port lives here rather than in the script
|
|
# precisely so the odd one out cannot be forgotten.
|
|
api_port: 8053
|
|
description: Anaheim colo
|
|
esh:
|
|
subnet: 10.0.0.0/16
|
|
resolver: 10.0.50.45 # esh-docker-vm
|
|
api_port: 8080
|
|
description: ESH home lab (esteban.net)
|
|
nh3:
|
|
subnet: 10.100.0.0/16
|
|
resolver: 10.100.50.40 # nh3-docker
|
|
api_port: 8080
|
|
description: NH3 office
|
|
|
|
hosts:
|
|
# ---- ana: Anaheim colo ----
|
|
- {name: ana-docker, site: ana, v4: 10.250.50.70, note: general-purpose docker host}
|
|
- {name: ana-ml2, site: ana, v4: 10.250.50.54, note: GPU inference, dual RTX PRO 6000}
|
|
- {name: ana-nas, site: ana, v4: 10.250.50.50, note: CT109 on pfi-pve — NFS/SMB}
|
|
- {name: ana-filebot, site: ana, v4: 10.250.50.53, note: file-task automation}
|
|
- {name: ana-wg, site: ana, v4: 10.250.50.252, note: WireGuard host}
|
|
- {name: corviduo-dev, site: ana, v4: 10.250.50.152, note: Worldtree-team dev VM (PFI-hosted)}
|
|
- {name: pbs-ana, site: ana, v4: 10.250.50.90, note: Proxmox Backup Server — fleet primary}
|
|
- {name: pfi-ana-webhost, site: ana, v4: 10.250.50.52, note: web workload}
|
|
- {name: pfi-postgres, site: ana, v4: 10.250.50.80, note: shared Postgres}
|
|
- {name: pfi-pteradactyl, site: ana, v4: 10.250.50.55, note: game panel}
|
|
- {name: pfi-tacticalrmm, site: ana, v4: 10.250.50.57, note: TacticalRMM}
|
|
- {name: pfi-pve, site: ana, v4: 10.250.250.31, note: Proxmox hypervisor}
|
|
- {name: ana-gw, site: ana, v4: 10.250.0.1, note: FortiGate-80F edge}
|
|
- {name: pfi-pve-idrac, site: ana, v4: 10.250.250.30, note: iDRAC — OOB for pfi-pve}
|
|
- {name: ana-ml2-bmc, site: ana, v4: 10.250.250.50, note: BMC for ana-ml2}
|
|
# SureFire tenant hardware — PFI-managed under the hosting agreement.
|
|
- {name: sfsrv-ana, site: ana, v4: 10.250.250.115, note: SureFire tenant hypervisor}
|
|
- {name: sf-ana-container, site: ana, v4: 10.250.150.100, note: SureFire tenant container host}
|
|
- {name: sf-r630-idrac, site: ana, v4: 10.250.250.110, note: SureFire tenant R630 iDRAC}
|
|
|
|
# ---- nh3: NH3 office ----
|
|
- {name: nh3-docker, site: nh3, v4: 10.100.50.40, note: general-purpose docker host + AdGuard}
|
|
- {name: pfi-gx10, site: nh3, v4: 10.100.50.60, note: GB10 Grace Blackwell, 121 GB unified — DHCP RESERVATION on the UDM, not a host static, so the box stays portable}
|
|
- {name: nh3-dev, site: nh3, v4: 10.100.10.50, note: dev box, fleet sidecars, Claude sessions}
|
|
- {name: nh3-extdev, site: nh3, v4: 10.100.50.42, note: manager / external-dev box}
|
|
- {name: nh3-nas, site: nh3, v4: 10.100.50.50, note: Synology RS2418+}
|
|
- {name: nh3-pve, site: nh3, v4: 10.100.250.60, note: Proxmox hypervisor}
|
|
- {name: pbs-nh3, site: nh3, v4: 10.100.50.90, note: Proxmox Backup Server — DR mirror}
|
|
- {name: nh3-gw, site: nh3, v4: 10.100.0.1, note: UniFi UDM Pro SE — gateway + controller}
|
|
# Irvine is not its own zone: irv-ml1 is reachable only through NH3's
|
|
# WireGuard tunnel and is numbered out of NH3's 10.100.79.0/24, so it is
|
|
# named under nh3. Revisit if Irvine ever becomes a site in its own right.
|
|
- {name: irv-ml1, site: nh3, v4: 10.100.79.3, note: GPU host (Irvine, via WG) — 3090 + A6000}
|
|
|
|
# ---- esh: ESH home lab ----
|
|
- {name: esh-docker-vm, site: esh, v4: 10.0.50.45, note: general-purpose docker host + AdGuard}
|
|
- {name: esh-nas, site: esh, v4: 10.0.50.50, note: NAS}
|
|
- {name: esh-pve, site: esh, v4: 10.0.250.35, note: Proxmox hypervisor}
|
|
- {name: esh-pve-nas, site: esh, v4: 10.0.50.55, note: Proxmox hypervisor — storage/media}
|
|
- {name: esh-vm-db, site: esh, v4: 10.0.50.60, note: PostgreSQL + MongoDB}
|
|
- {name: vm-esh-nas, site: esh, v4: 10.0.50.154, note: NAS-adjacent docker host}
|
|
- {name: esh-filebot, site: esh, v4: 10.0.50.70, note: restic / file-sync VM}
|
|
- {name: esh-gw, site: esh, v4: 10.0.250.1, note: esh-gw}
|
|
- {name: esh-udm, site: esh, v4: 10.0.0.1, note: UniFi UDM Pro Max — gateway + controller}
|
|
- {name: plex, site: esh, v4: 10.0.50.56, note: media server}
|
|
- {name: jellyfin, site: esh, v4: 10.0.50.57, note: media server}
|
|
- {name: brother, site: esh, v4: 10.0.90.125, note: Brother printer}
|
|
- {name: slzb-mr1u, site: esh, v4: 10.0.90.10, note: SMLIGHT SLZB-MR1U Zigbee/Thread coordinator (esh-iot VLAN 90, PoE on ESH-Media p4); Home Assistant at 10.0.50.46 connects to tcp/6638}
|
|
|
|
# Service aliases — a name that points at whatever host currently runs it, so
|
|
# consumers reference the SERVICE rather than the box. Changing where something
|
|
# runs becomes a one-line edit here instead of a hunt through configs.
|
|
aliases:
|
|
- {name: searxng, site: nh3, target: nh3-docker, note: moved off ana-docker 2026-09-03 — colo egress (38.120.12.42) is CAPTCHA-gated by search engines; NH3 egresses residentially}
|
|
- {name: gateway, site: ana, target: ana-docker, note: LiteLLM gateway :4000}
|
|
- {name: booth, site: nh3, target: nh3-dev, note: The Booth :8090}
|
|
- {name: homepage, site: esh, target: esh-docker-vm, note: fleet dashboard :5100}
|
|
- {name: scriberr, site: ana, target: ana-ml2, note: transcription + diarization :8080 (GPU1)}
|