Skip to content

Current infrastructure inventory

This is the canonical record for physical hosts, VMs, LXCs, and cloud/VPS hosts. Runtime facts were verified read-only on 2026-07-17 unless a row says otherwise.

Evidence fields

Verified means observed through a read-only command. User-confirmed means provided by the environment owner. Historical is retained evidence that is not current. Unverified states the next safe check.

Hosts and guests

ID/name Role State and resources Network Confidence / evidence
pve Proxmox host PVE 9.2.4, kernel 7.0.14-4-pve; local and local-lvm active 192.168.2.10; tailnet 100.64.0.1 Verified 2026-07-17: pveversion, pvesm status, Headscale node list
VM 100 router OPNsense firewall Running; 4 cores, 4096 MiB, 32 GiB; PCI WAN NICs plus vmbr0 virtio LAN/DMZ/WAN values last verified 2026-07-02 Running/config verified 2026-07-17: qm list, qm config 100; guest agent configured but not running
VM 108 Debian live/recovery guest Stopped; 2 cores, 2048 MiB, 32 GiB vmbr0; no documented address Verified 2026-07-17: qm config 108; purpose/owner unverified
CT 101 podman-lxc Rootless application/data host Running; 4 cores, 8192 MiB, 64 GiB; unprivileged DHCP 192.168.2.20, VLAN 2 Verified 2026-07-17: pct config, hostname -I, rootless Podman status
CT 102 technitium-dns DNS Running; 2 cores, 1024 MiB, 8 GiB; unprivileged DHCP 192.168.2.2, VLAN 2 Verified 2026-07-17: listeners and DNS queries
CT 103 caddy-ingress HTTPS ingress Running; 2 cores, 1024 MiB, 8 GiB; unprivileged DHCP 192.168.2.3, VLAN 2 Verified 2026-07-17: Caddy v2.11.4, listeners, route checks
CT 104 khysite Separate website workload Running; 2 cores, 512 MiB, 8 GiB; unprivileged DHCP 192.168.2.5, VLAN 2 Guest state verified 2026-07-17; service internals unverified
CT 105 ts-router Headscale/Tailscale subnet router Running; 1 core, 512 MiB, 8 GiB; unprivileged 192.168.2.120, tailnet 100.64.0.3 Verified 2026-07-17: Proxmox and Headscale
CT 106 rustdesk RustDesk ID/relay Running; 1 core, 1024 MiB, 8 GiB; unprivileged Static 192.168.2.70, VLAN 2 Guest state verified 2026-07-17; service verified 2026-07-02
CT 107 mail-recovery-fauzia Recovery workload Stopped Not applicable while stopped Verified 2026-07-17: pct list; owner, data, and retirement status unverified
ovps-me (vnic-head) Public Headscale/Headplane/Caddy VPS Rootless Podman containers running Public addressing intentionally omitted Verified 2026-07-17: Headscale and podman ps

Current application runtime

CT 101 runs Podman 5.4.2 as podsvc. On 2026-07-17 these containers and user units were running: PostgreSQL, Forgejo, Forgejo runner, Vaultwarden, Adminer, Dozzle, docs-static, and kh3-dev-site-static. Images and ports are canonical in the service catalog.

Storage

Storage State Use Confidence
local Active, 41.32% used ISO, templates, local files Verified 2026-07-17
local-lvm Active, 19.21% used VM/LXC disks Verified 2026-07-17
DIR01 Not configured in current pvesm status Historical guest storage Historical
network-backup-syn Not configured in current pvesm status Historical NAS backup target Historical; do not run legacy backup scripts unchanged
media Not configured in current pvesm status Historical NAS media mount Historical

The current NAS address, backup schedule, retention, owner, and tested restore target are Unverified. Next safe check: review Proxmox backup jobs and the approved NAS management/DHCP record without printing credentials.

Verification commands

ssh pvessh 'pveversion; qm list; pct list; pvesm status'
ssh pvessh 'qm config 100; qm config 108'
ssh pvessh 'for id in 101 102 103 104 105 106 107; do pct config "$id"; done'
ssh ovps-me 'sudo -iu podsvc podman exec headscale headscale nodes list'

Expected: VM 100 and CTs 101106 are running; VM 108 and CT 107 are stopped unless a separately documented operation changed them.

Unverified items

  • VM 108 and CT 107 ownership, data classification, recovery priority, and intended lifecycle.
  • CT 104 deployment source, owner, backup, and reconstruction procedure.
  • NAS identity, address, health, snapshots, backup jobs, and retention.
  • Current OPNsense runtime details after 2026-07-02. SSH authentication failed on 2026-07-17 and the QEMU guest agent was not running.