# Server Reference Card ## SSH Patterns ```bash # DigitalOcean (websites only — JARVIS/FusionPBX no longer here) sshpass -p 'Gonewalk1974!@#' ssh -o StrictHostKeyChecking=no root@165.22.1.228 'cmd' # PVE1 (hop node for everything else — password auth) sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.90 'cmd' # also reachable via FortiGate DDNS (survives WAN IP changes, which happen often): sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@orbisne.fortiddns.com 'cmd' # Any VM behind PVE1 — nested hop through PVE1 sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 \ 'ssh -o StrictHostKeyChecking=no root@ "cmd"' # PVE2 (local only, no external port-forward) sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.91 'cmd' # Run a command inside an LXC container (CT) via PVE1's pct sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'pct exec -- bash -c "cmd"' # Run a command inside a QEMU VM via guest agent (works even if network/SSH is down) sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'qm guest exec -- bash -c "cmd"' # guest-exec has no HOME env by default — many CLI tools need: export HOME=/root; ... # Local VMs using myron user + sudo sshpass -p 'Joker1974!' ssh -o StrictHostKeyChecking=no myron@10.48.200.18 'sudo cmd' # Synology NAS — needs password auth FORCED (pubkey silently preferred/fails otherwise) sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no -o PreferredAuthentications=password \ -o PubkeyAuthentication=no nas@10.48.200.249 'echo Joker1974!!! | sudo -S cmd' # scp to the NAS needs the legacy flag too: scp -O ... ``` **Password order to try if first fails:** `Joker1974!!!` → `Joker1974!` → `Gonewalk1974!@#` (DO only). **MediaStack-35's ad-hoc interactive SSH intermittently failed** (resolved as non-issue — the automated backup script's own key-based access always worked fine; root cause was never found, and it's moot now since that VM is destroyed). If a similarly-flaky interactive SSH pattern shows up on another host, don't assume it's a real access/security problem before checking whether an automated path using the same credentials still works. ## Server Map (current) | Host | IP | User | Password | Purpose | |------|----|------|----------|---------| | DO | 165.22.1.228 | root | Gonewalk1974!@# | Websites (CyberPanel/OLS), 7 sites | | PVE1 | orbisne.fortiddns.com (10.48.200.90) | root | Joker1974!!! | Primary hypervisor, SSH hop for everything | | PVE2 | 10.48.200.91 | root | Joker1974!!! | Secondary hypervisor | | JARVIS VM 211 | 10.48.200.211 | root | Joker1974!!! | JARVIS AI dashboard | | StreamHoard CT104 | 10.48.200.104 | root | Joker1974!!! (via `pct exec 104`) | Consolidated media server — see streamhoard.md | | NovaCPX VM120 | 10.48.200.110 | root | Joker1974!!! | Hosting panel + web.orbishosting.com dashboard | | FusionPBX VM130 | 10.48.200.130 | root | Joker1974!!! | FreeSWITCH PBX (on-prem now, not the old DO droplet) | | Ollama VM106 | 10.48.200.210 | root | Joker1974!!! | Local LLM (llama3.1:8b, llava:7b vision), port 11434 | | Home Assistant | 10.48.200.97 | — | — | HA VM 109/101 (web terminal only) | | Homebridge VM118 | 10.48.200.18 | myron | Joker1974! | HomeKit bridge | | NetworkBackup | 10.48.200.99 | myron | Joker1974! | PVE2 VM 302 | | NPM VM105 | 10.48.200.200 | — | — | Nginx Proxy Manager (Docker), admin `myronblair@outlook.com` | | Synology NAS | 10.48.200.249 | nas | Joker1974!!! | Media + MSP360 backup storage, DSM 7.3.2, Gitea | | FortiGate | 10.48.200.1 | admin | Joker1974!!! | Router/firewall — admin GUI on **:9443**, not 443 | **Destroyed 2026-07-23 — do not use these IPs/VMIDs for anything:** | Was | IP | VMID | |---|---|---| | Jellyfin | 10.48.200.33 | VM112 | | MediaStack | 10.48.200.35 | VM103 (also briefly `.136` mid-migration) | | WireGuard exit container | 10.48.200.67 / .19 | CT110 | `10.48.200.35` is currently squatted by an **unidentified rogue device** (SSH banner `OpenSSH_8.4p1`, exposes NFS shares named `TimeMachineBackup`/`Public`/`iTunes` — looks like an old Buffalo-brand NAS). Found during the migration, never tracked down/removed. Don't be surprised if that IP answers but isn't what you expect. ## Proxmox API ```bash # Accessible from anywhere via FortiGate DDNS (port 8006 forwarded) curl -sk "https://orbisne.fortiddns.com:8006/api2/json/..." \ -H "Authorization: PVEAPIToken=root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b" # Cluster API — gets VMs from BOTH PVE1 and PVE2 GET /api2/json/cluster/resources?type=vm ``` ## Key Paths on JARVIS VM (10.48.200.211) ``` /var/www/jarvis/ — JARVIS app root, IS the live git repo (push from it directly) /var/www/jarvis/public_html/ — web root (index.html, api.php, admin/) /var/www/jarvis/api/ — backend (config.php [gitignored], endpoints/, lib/) /var/www/jarvis/deploy/ — Arc Reactor source (reactor.py) /opt/jarvis-arc/reactor.py — Arc Reactor daemon (copy deploy/reactor.py here + restart to deploy) /var/backups/jarvis/ — daily backups (tar.gz, 7-day retention) /usr/local/bin/jarvis-backup.sh — backup script /var/www/jarvis/public_html/admin/downloads/INFRASTRUCTURE-REFERENCE.md — the master live infra doc (edit here first, gitignored, NOT in GitHub — relay-copy to VM110 through PVE1 after editing) ``` ## Key paths on StreamHoard CT104 (10.48.200.104) See [streamhoard.md](streamhoard.md) for full detail. ``` /opt/kino/ — docker-compose.yml, .env, app source (repo kino-app) /opt/streamhoard-config/ — migrated radarr/sonarr/prowlarr/qbittorrent config+library /mnt/nas/video/ — LXC mountpoint passthrough of the NAS media library (movies/tv) /mnt/nas-backups/ — LXC mountpoint passthrough for MSP360 destination ``` ## Key Paths on DO (165.22.1.228) ``` /home/tomsjavajive.com/public_html/ /home/epictravelexpeditions.com/public_html/ /home/parkerslingshotrentals.com/public_html/ /home/orbishosting.com/public_html/ — NOT the real public apex site (see sites.md) /home/orbis.orbishosting.com/public_html/ /home/tomtomgames.com/public_html/ /home/worktracking.orbishosting.com/public_html/ — ChuckCo Time Keeper (repo: chucko) ``` `.git` for all 7 sites lives OUTSIDE the web root at `/home//git-data` (a `gitdir:` pointer file sits in `public_html/.git`) — `git` commands from `public_html` work normally. ## PHP / OLS Notes (DO server) - Run scripts: `/usr/local/lsws/lsphp85/bin/lsphp /path/to/script.php` - Syntax check: `php8.3 -l file.php` (lsphp segfaults on -l) - Web server: OpenLiteSpeed (`lshttpd`), NOT apache/nginx - Cron bug: `*/3 * * * *` restarts `lshttpd` if any `.htaccess` is newer than `/usr/local/lsws/cgid` (a directory) — nothing re-touches that dir after restart, so editing `.htaccess` triggers a restart loop until you `touch /usr/local/lsws/cgid` manually. ## GitHub / Gitea - GitHub is source of truth; **Gitea (`gitea.orbishosting.com`, on the NAS) is a one-way, read-only mirror** — never push directly to Gitea. - `gh` CLI at `C:\Program Files\GitHub CLI\gh.exe` (Windows workstation), auth via `GH_TOKEN` env var, PAT scopes `repo`+`workflow` (no `read:org`, so use `GH_TOKEN` directly or `gh api`, not `gh auth login --with-token`). - After any GitHub push, trigger the mirror manually: `curl -X POST -u myron:Joker1974!!! https://gitea.orbishosting.com/api/v1/repos/myron//mirror-sync` - 5 repos are Gitea-only by design, never push to GitHub: `fortigate-config`, `infra-private`, `jarvis-secrets`, `msp360-config`, `proxmox-secrets` — these hold real credentials deliberately kept off a third-party cloud host.