Files
ai-context/servers.md
T
Myron Blair 4fad312f87 Full rewrite for current infra state — StreamHoard consolidation, VoIP split out, dead references purged
- Replace all Jellyfin/MediaStack/WireGuard-CT110 references (destroyed 2026-07-23) with
  StreamHoard/CT104 throughout; add streamhoard.md covering the full consolidated stack,
  MSP360 backup setup, and migration incidents
- Split FusionPBX/SignalWire/landline content into its own voip.md (was scattered across
  jarvis.md and sites.md, and referenced the old destroyed DO droplet IP)
- Fix stale facts: JARVIS webhook port (:1972 -> 80/https), rotated registration key/GitHub
  PAT, FortiGate admin port (9443 not 443), current WAN-IP-drift/VIP gotchas
- Add reference.md for repo inventory notes, assistant hard limits, ZeroTraceGPT IQ, payments
  migration status
- Update gotchas.md with unprivileged-LXC mount limitations and MSP360 dpkg-repack gotcha
2026-07-25 22:47:31 -05:00

7.5 KiB

Server Reference Card

SSH Patterns

# DigitalOcean (websites only — JARVIS/FusionPBX no longer here)
sshpass -p 'Gonewalk1974!@#' ssh -o StrictHostKeyChecking=no root@165.22.1.228 'cmd'

# PVE1 (hop node for everything else — password auth)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.90 'cmd'
# also reachable via FortiGate DDNS (survives WAN IP changes, which happen often):
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@orbisne.fortiddns.com 'cmd'

# Any VM behind PVE1 — nested hop through PVE1
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 \
  'ssh -o StrictHostKeyChecking=no root@<VM_IP> "cmd"'

# PVE2 (local only, no external port-forward)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no root@10.48.200.91 'cmd'

# Run a command inside an LXC container (CT) via PVE1's pct
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'pct exec <CTID> -- bash -c "cmd"'

# Run a command inside a QEMU VM via guest agent (works even if network/SSH is down)
sshpass -p 'Joker1974!!!' ssh root@10.48.200.90 'qm guest exec <VMID> -- bash -c "cmd"'
# guest-exec has no HOME env by default — many CLI tools need: export HOME=/root; ...

# Local VMs using myron user + sudo
sshpass -p 'Joker1974!' ssh -o StrictHostKeyChecking=no myron@10.48.200.18 'sudo cmd'

# Synology NAS — needs password auth FORCED (pubkey silently preferred/fails otherwise)
sshpass -p 'Joker1974!!!' ssh -o StrictHostKeyChecking=no -o PreferredAuthentications=password \
  -o PubkeyAuthentication=no nas@10.48.200.249 'echo Joker1974!!! | sudo -S cmd'
# scp to the NAS needs the legacy flag too: scp -O ...

Password order to try if first fails: Joker1974!!!Joker1974!Gonewalk1974!@# (DO only).

MediaStack-35's ad-hoc interactive SSH intermittently failed (resolved as non-issue — the automated backup script's own key-based access always worked fine; root cause was never found, and it's moot now since that VM is destroyed). If a similarly-flaky interactive SSH pattern shows up on another host, don't assume it's a real access/security problem before checking whether an automated path using the same credentials still works.

Server Map (current)

Host IP User Password Purpose
DO 165.22.1.228 root Gonewalk1974!@# Websites (CyberPanel/OLS), 7 sites
PVE1 orbisne.fortiddns.com (10.48.200.90) root Joker1974!!! Primary hypervisor, SSH hop for everything
PVE2 10.48.200.91 root Joker1974!!! Secondary hypervisor
JARVIS VM 211 10.48.200.211 root Joker1974!!! JARVIS AI dashboard
StreamHoard CT104 10.48.200.104 root Joker1974!!! (via pct exec 104) Consolidated media server — see streamhoard.md
NovaCPX VM120 10.48.200.110 root Joker1974!!! Hosting panel + web.orbishosting.com dashboard
FusionPBX VM130 10.48.200.130 root Joker1974!!! FreeSWITCH PBX (on-prem now, not the old DO droplet)
Ollama VM106 10.48.200.210 root Joker1974!!! Local LLM (llama3.1:8b, llava:7b vision), port 11434
Home Assistant 10.48.200.97 HA VM 109/101 (web terminal only)
Homebridge VM118 10.48.200.18 myron Joker1974! HomeKit bridge
NetworkBackup 10.48.200.99 myron Joker1974! PVE2 VM 302
NPM VM105 10.48.200.200 Nginx Proxy Manager (Docker), admin myronblair@outlook.com
Synology NAS 10.48.200.249 nas Joker1974!!! Media + MSP360 backup storage, DSM 7.3.2, Gitea
FortiGate 10.48.200.1 admin Joker1974!!! Router/firewall — admin GUI on :9443, not 443

Destroyed 2026-07-23 — do not use these IPs/VMIDs for anything:

Was IP VMID
Jellyfin 10.48.200.33 VM112
MediaStack 10.48.200.35 VM103 (also briefly .136 mid-migration)
WireGuard exit container 10.48.200.67 / .19 CT110

10.48.200.35 is currently squatted by an unidentified rogue device (SSH banner OpenSSH_8.4p1, exposes NFS shares named TimeMachineBackup/Public/iTunes — looks like an old Buffalo-brand NAS). Found during the migration, never tracked down/removed. Don't be surprised if that IP answers but isn't what you expect.

Proxmox API

# Accessible from anywhere via FortiGate DDNS (port 8006 forwarded)
curl -sk "https://orbisne.fortiddns.com:8006/api2/json/..." \
  -H "Authorization: PVEAPIToken=root@pam!jarvis=c45b5feb-f9a9-445d-a626-14fbb959f78b"

# Cluster API — gets VMs from BOTH PVE1 and PVE2
GET /api2/json/cluster/resources?type=vm

Key Paths on JARVIS VM (10.48.200.211)

/var/www/jarvis/              — JARVIS app root, IS the live git repo (push from it directly)
/var/www/jarvis/public_html/  — web root (index.html, api.php, admin/)
/var/www/jarvis/api/          — backend (config.php [gitignored], endpoints/, lib/)
/var/www/jarvis/deploy/       — Arc Reactor source (reactor.py)
/opt/jarvis-arc/reactor.py    — Arc Reactor daemon (copy deploy/reactor.py here + restart to deploy)
/var/backups/jarvis/          — daily backups (tar.gz, 7-day retention)
/usr/local/bin/jarvis-backup.sh — backup script
/var/www/jarvis/public_html/admin/downloads/INFRASTRUCTURE-REFERENCE.md — the master live infra doc (edit here first, gitignored, NOT in GitHub — relay-copy to VM110 through PVE1 after editing)

Key paths on StreamHoard CT104 (10.48.200.104)

See streamhoard.md for full detail.

/opt/kino/                 — docker-compose.yml, .env, app source (repo kino-app)
/opt/streamhoard-config/   — migrated radarr/sonarr/prowlarr/qbittorrent config+library
/mnt/nas/video/            — LXC mountpoint passthrough of the NAS media library (movies/tv)
/mnt/nas-backups/          — LXC mountpoint passthrough for MSP360 destination

Key Paths on DO (165.22.1.228)

/home/tomsjavajive.com/public_html/
/home/epictravelexpeditions.com/public_html/
/home/parkerslingshotrentals.com/public_html/
/home/orbishosting.com/public_html/       — NOT the real public apex site (see sites.md)
/home/orbis.orbishosting.com/public_html/
/home/tomtomgames.com/public_html/
/home/worktracking.orbishosting.com/public_html/  — ChuckCo Time Keeper (repo: chucko)

.git for all 7 sites lives OUTSIDE the web root at /home/<site>/git-data (a gitdir: pointer file sits in public_html/.git) — git commands from public_html work normally.

PHP / OLS Notes (DO server)

  • Run scripts: /usr/local/lsws/lsphp85/bin/lsphp /path/to/script.php
  • Syntax check: php8.3 -l file.php (lsphp segfaults on -l)
  • Web server: OpenLiteSpeed (lshttpd), NOT apache/nginx
  • Cron bug: */3 * * * * restarts lshttpd if any .htaccess is newer than /usr/local/lsws/cgid (a directory) — nothing re-touches that dir after restart, so editing .htaccess triggers a restart loop until you touch /usr/local/lsws/cgid manually.

GitHub / Gitea

  • GitHub is source of truth; Gitea (gitea.orbishosting.com, on the NAS) is a one-way, read-only mirror — never push directly to Gitea.
  • gh CLI at C:\Program Files\GitHub CLI\gh.exe (Windows workstation), auth via GH_TOKEN env var, PAT scopes repo+workflow (no read:org, so use GH_TOKEN directly or gh api, not gh auth login --with-token).
  • After any GitHub push, trigger the mirror manually: curl -X POST -u myron:Joker1974!!! https://gitea.orbishosting.com/api/v1/repos/myron/<repo>/mirror-sync
  • 5 repos are Gitea-only by design, never push to GitHub: fortigate-config, infra-private, jarvis-secrets, msp360-config, proxmox-secrets — these hold real credentials deliberately kept off a third-party cloud host.