- Replace all Jellyfin/MediaStack/WireGuard-CT110 references (destroyed 2026-07-23) with StreamHoard/CT104 throughout; add streamhoard.md covering the full consolidated stack, MSP360 backup setup, and migration incidents - Split FusionPBX/SignalWire/landline content into its own voip.md (was scattered across jarvis.md and sites.md, and referenced the old destroyed DO droplet IP) - Fix stale facts: JARVIS webhook port (:1972 -> 80/https), rotated registration key/GitHub PAT, FortiGate admin port (9443 not 443), current WAN-IP-drift/VIP gotchas - Add reference.md for repo inventory notes, assistant hard limits, ZeroTraceGPT IQ, payments migration status - Update gotchas.md with unprivileged-LXC mount limitations and MSP360 dpkg-repack gotcha
7.5 KiB
Server Reference Card
SSH Patterns
# DigitalOcean (websites only — JARVIS/FusionPBX no longer here)
sshpass -p 'Gonewalk1974!@#' ssh -o StrictHostKeyChecking=no root@165.22.1.228 'cmd'
# PVE1 (hop node for everything else — password auth)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.90 'cmd'
# also reachable via FortiGate DDNS (survives WAN IP changes, which happen often):
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@orbisne.fortiddns.com 'cmd'
# Any VM behind PVE1 — nested hop through PVE1
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 \
'ssh -o StrictHostKeyChecking=no root@<VM_IP> "cmd"'
# PVE2 (local only, no external port-forward)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.91 'cmd'
# Run a command inside an LXC container (CT) via PVE1's pct
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'pct exec <CTID> -- bash -c "cmd"'
# Run a command inside a QEMU VM via guest agent (works even if network/SSH is down)
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'qm guest exec <VMID> -- bash -c "cmd"'
# guest-exec has no HOME env by default — many CLI tools need: export HOME=/root; ...
# Local VMs using myron user + sudo
sshpass -p 'Joker1974!' ssh -o StrictHostKeyChecking=no myron@10.48.200.18 'sudo cmd'
# Synology NAS — needs password auth FORCED (pubkey silently preferred/fails otherwise)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no -o PreferredAuthentications=password \
-o PubkeyAuthentication=no nas@10.48.200.249 'echo Joker1974!!! | sudo -S cmd'
# scp to the NAS needs the legacy flag too: scp -O ...
Password order to try if first fails: Joker1974!!! → Joker1974! → Gonewalk1974!@# (DO only).
MediaStack-35's ad-hoc interactive SSH intermittently failed (resolved as non-issue — the automated backup script's own key-based access always worked fine; root cause was never found, and it's moot now since that VM is destroyed). If a similarly-flaky interactive SSH pattern shows up on another host, don't assume it's a real access/security problem before checking whether an automated path using the same credentials still works.
Server Map (current)
| Host | IP | User | Password | Purpose |
|---|---|---|---|---|
| DO | 165.22.1.228 | root | Gonewalk1974!@# | Websites (CyberPanel/OLS), 7 sites |
| PVE1 | orbisne.fortiddns.com (10.48.200.90) | root | Joker1974!!! | Primary hypervisor, SSH hop for everything |
| PVE2 | 10.48.200.91 | root | Joker1974!!! | Secondary hypervisor |
| JARVIS VM 211 | 10.48.200.211 | root | Joker1974!!! | JARVIS AI dashboard |
| StreamHoard CT104 | 10.48.200.104 | root | Joker1974!!! (via pct exec 104) |
Consolidated media server — see streamhoard.md |
| NovaCPX VM120 | 10.48.200.110 | root | Joker1974!!! | Hosting panel + web.orbishosting.com dashboard |
| FusionPBX VM130 | 10.48.200.130 | root | Joker1974!!! | FreeSWITCH PBX (on-prem now, not the old DO droplet) |
| Ollama VM106 | 10.48.200.210 | root | Joker1974!!! | Local LLM (llama3.1:8b, llava:7b vision), port 11434 |
| Home Assistant | 10.48.200.97 | — | — | HA VM 109/101 (web terminal only) |
| Homebridge VM118 | 10.48.200.18 | myron | Joker1974! | HomeKit bridge |
| NetworkBackup | 10.48.200.99 | myron | Joker1974! | PVE2 VM 302 |
| NPM VM105 | 10.48.200.200 | — | — | Nginx Proxy Manager (Docker), admin myronblair@outlook.com |
| Synology NAS | 10.48.200.249 | nas | Joker1974!!! | Media + MSP360 backup storage, DSM 7.3.2, Gitea |
| FortiGate | 10.48.200.1 | admin | Joker1974!!! | Router/firewall — admin GUI on :9443, not 443 |
Destroyed 2026-07-23 — do not use these IPs/VMIDs for anything:
| Was | IP | VMID |
|---|---|---|
| Jellyfin | 10.48.200.33 | VM112 |
| MediaStack | 10.48.200.35 | VM103 (also briefly .136 mid-migration) |
| WireGuard exit container | 10.48.200.67 / .19 | CT110 |
10.48.200.35 is currently squatted by an unidentified rogue device (SSH banner OpenSSH_8.4p1, exposes NFS shares named TimeMachineBackup/Public/iTunes — looks like an old Buffalo-brand NAS). Found during the migration, never tracked down/removed. Don't be surprised if that IP answers but isn't what you expect.
Proxmox API
# Accessible from anywhere via FortiGate DDNS (port 8006 forwarded)
curl -sk "https://orbisne.fortiddns.com:8006/api2/json/..." \
-H "Authorization: PVEAPIToken=root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b"
# Cluster API — gets VMs from BOTH PVE1 and PVE2
GET /api2/json/cluster/resources?type=vm
Key Paths on JARVIS VM (10.48.200.211)
/var/www/jarvis/ — JARVIS app root, IS the live git repo (push from it directly)
/var/www/jarvis/public_html/ — web root (index.html, api.php, admin/)
/var/www/jarvis/api/ — backend (config.php [gitignored], endpoints/, lib/)
/var/www/jarvis/deploy/ — Arc Reactor source (reactor.py)
/opt/jarvis-arc/reactor.py — Arc Reactor daemon (copy deploy/reactor.py here + restart to deploy)
/var/backups/jarvis/ — daily backups (tar.gz, 7-day retention)
/usr/local/bin/jarvis-backup.sh — backup script
/var/www/jarvis/public_html/admin/downloads/INFRASTRUCTURE-REFERENCE.md — the master live infra doc (edit here first, gitignored, NOT in GitHub — relay-copy to VM110 through PVE1 after editing)
Key paths on StreamHoard CT104 (10.48.200.104)
See streamhoard.md for full detail.
/opt/kino/ — docker-compose.yml, .env, app source (repo kino-app)
/opt/streamhoard-config/ — migrated radarr/sonarr/prowlarr/qbittorrent config+library
/mnt/nas/video/ — LXC mountpoint passthrough of the NAS media library (movies/tv)
/mnt/nas-backups/ — LXC mountpoint passthrough for MSP360 destination
Key Paths on DO (165.22.1.228)
/home/tomsjavajive.com/public_html/
/home/epictravelexpeditions.com/public_html/
/home/parkerslingshotrentals.com/public_html/
/home/orbishosting.com/public_html/ — NOT the real public apex site (see sites.md)
/home/orbis.orbishosting.com/public_html/
/home/tomtomgames.com/public_html/
/home/worktracking.orbishosting.com/public_html/ — ChuckCo Time Keeper (repo: chucko)
.git for all 7 sites lives OUTSIDE the web root at /home/<site>/git-data (a gitdir: pointer file sits in public_html/.git) — git commands from public_html work normally.
PHP / OLS Notes (DO server)
- Run scripts:
/usr/local/lsws/lsphp85/bin/lsphp /path/to/script.php - Syntax check:
php8.3 -l file.php(lsphp segfaults on -l) - Web server: OpenLiteSpeed (
lshttpd), NOT apache/nginx - Cron bug:
*/3 * * * *restartslshttpdif any.htaccessis newer than/usr/local/lsws/cgid(a directory) — nothing re-touches that dir after restart, so editing.htaccesstriggers a restart loop until youtouch /usr/local/lsws/cgidmanually.
GitHub / Gitea
- GitHub is source of truth; Gitea (
gitea.orbishosting.com, on the NAS) is a one-way, read-only mirror — never push directly to Gitea. ghCLI atC:\Program Files\GitHub CLI\gh.exe(Windows workstation), auth viaGH_TOKENenv var, PAT scopesrepo+workflow(noread:org, so useGH_TOKENdirectly orgh api, notgh auth login --with-token).- After any GitHub push, trigger the mirror manually:
curl -X POST -u myron:Joker1974!!! https://gitea.orbishosting.com/api/v1/repos/myron/<repo>/mirror-sync - 5 repos are Gitea-only by design, never push to GitHub:
fortigate-config,infra-private,jarvis-secrets,msp360-config,proxmox-secrets— these hold real credentials deliberately kept off a third-party cloud host.