Skip to content

Services Overview

Service Map

ServiceHostIPPortPurpose
Grafanaenergonhub (PVE2 CT100)192.168.5.93000Unified NOC dashboard
Wazuh DashboardSOC (PVE2 CT105)192.168.5.211443SIEM / security dashboard
Wazuh ManagerSOC (PVE2 CT105)192.168.5.2111514/1515Agent mgmt
OpenSearchSOC (PVE2 CT105)192.168.5.2119200Log indexer
ZabbixPVE2 VM101192.168.5.xInfrastructure monitoring
Proxmox Mail Gatewaypmg-backup-mx (PVE2 CT106)192.168.5.154MX backup / mail filtering
Hestia Control PanelPVE1 VM111192.168.1.20Web hosting panel
ISPConfigPVE2 CT102192.168.5.209Web hosting panel (backup)
TDAIPVE1 VM108192.168.1.22AI / automation platform
master-controlPVE1 VM110192.168.1.21Docker control plane
optination-phase-vaultPVE1 VM112192.168.1.32Secrets / vault (Docker)
optination-panelPVE1 VM113192.168.1.50OptiNation management
CF-HQPVE2 CT103192.168.127.55Cloudflare Zero Trust

Grafana

  • URL: http://192.168.5.9:3000
  • Dashboard: optination-unified-noc (UID: optination-unified-noc)
  • Auth: admin / Admin2026!
  • Datasources: Prometheus, Loki, Infinity (for static/JSON panels)
  • Panels include: network topology (nodeGraph), host status, Wazuh alerts

Mail Stack

INTERNET → PMG (192.168.5.154) → Internal mail servers
→ mx1 (PVE1 CT105 — 192.168.1.15)
→ mx2 / pmg-backup (PVE2 CT106)
  • PMG handles spam filtering, anti-virus, and quarantine
  • mx1 is the primary mail gateway for optination.net
  • MX backup via CT106 (pmg-backup-mx)

Cloudflare Integration

  • CF-HQ (CT103) runs the Cloudflare Zero Trust connector on VLAN127
  • Cloudflare SSH CA available for short-lived SSH certificate auth
  • For machine-to-machine: use internal SSH CA (Cloudflare for external access only)

Proxmox Backup

  • PBS (Proxmox Backup Server) monitored as Wazuh agent 007 (pbs)
  • Location: separate host (not PVE1 or PVE2)

Domain / DNS

DomainHostIP
optination.netCT115 (prod)192.168.1.111 / 199.119.84.164
mail.optination-hosting.localVM111192.168.1.20
mx1.mail-gateway.edge.optination.netCT105 PVE1192.168.1.15
afterschooltoysco.comHestiaCP (VM111)(migration pending)
planettoysutah.comVarious