Current infrastructure inventory
This is the canonical record for physical hosts, VMs, LXCs, and cloud/VPS hosts. Runtime facts were verified read-only on 2026-07-17 unless a row says otherwise.
Evidence fields
Verified means observed through a read-only command. User-confirmed means
provided by the environment owner. Historical is retained evidence that is
not current. Unverified states the next safe check.
Hosts and guests
| ID/name | Role | State and resources | Network | Confidence / evidence |
|---|---|---|---|---|
pve |
Proxmox host | PVE 9.2.4, kernel 7.0.14-4-pve; local and local-lvm active |
192.168.2.10; tailnet 100.64.0.1 |
Verified 2026-07-17: pveversion, pvesm status, Headscale node list |
VM 100 router |
OPNsense firewall | Running; 4 cores, 4096 MiB, 32 GiB; PCI WAN NICs plus vmbr0 virtio |
LAN/DMZ/WAN values last verified 2026-07-02 | Running/config verified 2026-07-17: qm list, qm config 100; guest agent configured but not running |
VM 108 |
Debian live/recovery guest | Stopped; 2 cores, 2048 MiB, 32 GiB | vmbr0; no documented address |
Verified 2026-07-17: qm config 108; purpose/owner unverified |
CT 101 podman-lxc |
Rootless application/data host | Running; 4 cores, 8192 MiB, 64 GiB; unprivileged | DHCP 192.168.2.20, VLAN 2 |
Verified 2026-07-17: pct config, hostname -I, rootless Podman status |
CT 102 technitium-dns |
DNS | Running; 2 cores, 1024 MiB, 8 GiB; unprivileged | DHCP 192.168.2.2, VLAN 2 |
Verified 2026-07-17: listeners and DNS queries |
CT 103 caddy-ingress |
HTTPS ingress | Running; 2 cores, 1024 MiB, 8 GiB; unprivileged | DHCP 192.168.2.3, VLAN 2 |
Verified 2026-07-17: Caddy v2.11.4, listeners, route checks |
CT 104 khysite |
Separate website workload | Running; 2 cores, 512 MiB, 8 GiB; unprivileged | DHCP 192.168.2.5, VLAN 2 |
Guest state verified 2026-07-17; service internals unverified |
CT 105 ts-router |
Headscale/Tailscale subnet router | Running; 1 core, 512 MiB, 8 GiB; unprivileged | 192.168.2.120, tailnet 100.64.0.3 |
Verified 2026-07-17: Proxmox and Headscale |
CT 106 rustdesk |
RustDesk ID/relay | Running; 1 core, 1024 MiB, 8 GiB; unprivileged | Static 192.168.2.70, VLAN 2 |
Guest state verified 2026-07-17; service verified 2026-07-02 |
CT 107 mail-recovery-fauzia |
Recovery workload | Stopped | Not applicable while stopped | Verified 2026-07-17: pct list; owner, data, and retirement status unverified |
ovps-me (vnic-head) |
Public Headscale/Headplane/Caddy VPS | Rootless Podman containers running | Public addressing intentionally omitted | Verified 2026-07-17: Headscale and podman ps |
Current application runtime
CT 101 runs Podman 5.4.2 as podsvc. On 2026-07-17 these containers and
user units were running: PostgreSQL, Forgejo, Forgejo runner, Vaultwarden,
Adminer, Dozzle, docs-static, and kh3-dev-site-static. Images and ports are
canonical in the service catalog.
Storage
| Storage | State | Use | Confidence |
|---|---|---|---|
local |
Active, 41.32% used | ISO, templates, local files | Verified 2026-07-17 |
local-lvm |
Active, 19.21% used | VM/LXC disks | Verified 2026-07-17 |
DIR01 |
Not configured in current pvesm status |
Historical guest storage | Historical |
network-backup-syn |
Not configured in current pvesm status |
Historical NAS backup target | Historical; do not run legacy backup scripts unchanged |
media |
Not configured in current pvesm status |
Historical NAS media mount | Historical |
The current NAS address, backup schedule, retention, owner, and tested restore target are Unverified. Next safe check: review Proxmox backup jobs and the approved NAS management/DHCP record without printing credentials.
Verification commands
ssh pvessh 'pveversion; qm list; pct list; pvesm status'
ssh pvessh 'qm config 100; qm config 108'
ssh pvessh 'for id in 101 102 103 104 105 106 107; do pct config "$id"; done'
ssh ovps-me 'sudo -iu podsvc podman exec headscale headscale nodes list'
Expected: VM 100 and CTs 101–106 are running; VM 108 and CT 107 are
stopped unless a separately documented operation changed them.
Unverified items
- VM
108and CT107ownership, data classification, recovery priority, and intended lifecycle. - CT
104deployment source, owner, backup, and reconstruction procedure. - NAS identity, address, health, snapshots, backup jobs, and retention.
- Current OPNsense runtime details after 2026-07-02. SSH authentication failed on 2026-07-17 and the QEMU guest agent was not running.