● VERIFIED GUEST INVENTORY · 2026-09-24
OptiNation infrastructure atlas
Current host-reported inventory of the Proxmox guest estate, routing and Cloudflare edge. Revalidated after organization-wide SSH key deployment.
Architecture
Verified VM and container inventory
Roles below come from OS, service-manager and container-runtime data collected directly from each guest.
| Type | Node/ID | Address | Identity | Current role |
|---|---|---|---|---|
| VM | pve1/108 | 192.168.1.22 | tdai Ubuntu 22.04.5 | TreadDepth AI: llama-swap, Piper TTS, NVIDIA persistence, tread-depth services |
| VM | pve1/110 | 192.168.1.28 | master-control Ubuntu 24.04.4 | Cloudflare and Microsoft 365 read-only control services; Docker; Alloy/Wazuh/Zabbix |
| VM | pve1/112 | 192.168.1.32 | optination-phase-vault Debian 12 | Phase Secrets stack: frontend, backend, worker, PostgreSQL 15, Redis, nginx |
| VM | pve1/113 | 192.168.1.50 | optination-panel Debian 12 | OptiNation panel: Caddy, PostgreSQL 15, Redis, optination service |
| VM | pve1/116 | 192.168.1.44 | axigen-mail Ubuntu 22.04.5 | Axigen mail platform with Alloy, Wazuh and Zabbix monitoring |
| VM | pve1/117 | 192.168.1.26 | tfdatabase-wiki Debian 12 | MediaWiki 1.42, scanner, PostgreSQL 16 and MariaDB 10.11 in Docker |
| VM | pve2/101 | 192.168.5.153 | appliance AlmaLinux 8.10 | Zabbix server/appliance: MySQL, nginx, PHP-FPM, Postfix |
| CT | pve1/102 | 192.168.1.24 | corp Debian 12 | Corporate web stack: Apache, MariaDB, Redis, Postfix, Webmin |
| CT | pve1/104 | 192.168.1.25 | Prod-DNS-Server-2 Debian 12 | Production DNS secondary plus Postfix and monitoring agents |
| CT | pve1/105 | 192.168.1.15 | mx1 Debian 13 | Proxmox Mail Gateway: ClamAV, SMTP filter, Postfix, PostgreSQL 17 |
| CT | pve1/106 | 192.168.1.13 | Forum Ubuntu 25.04 | Discourse application in Docker, published on HTTP 80 |
| CT | pve1/115 | 192.168.1.111 | prod Debian 12 | Hosting/mail stack: Apache, Dovecot, Postfix, MariaDB, Redis, Rspamd, multi-version PHP |
| CT | pve1/118 | 192.168.1.30 | medusa-prod Debian 12 | Medusa storefront/backend with PostgreSQL 16 and Redis 7 |
| CT | pve1/119 | 192.168.1.211 | soc Ubuntu 20.04.6 | Wazuh SOC: manager, indexer, dashboard, Filebeat, nginx |
| CT | pve2/100 | 192.168.5.9 | energonhub Debian 12 | Grafana, Telegraf, PDC agent and monitoring |
| CT | pve2/103 | 192.168.127.55 | CF-HQ Ubuntu 20.04.6 | Cloudflare WARP private-network connector; IPv4/IPv6 overlay addresses |
| CT | pve2/104 | 192.168.5.145 | pulse Debian 12 | Pulse service with Prometheus, Wazuh and Zabbix agents |
| CT | pve2/107 | 192.168.5.207 | nac Debian 12 | Network access control: FreeRADIUS, nginx and OptiNAC |
| CT | pve2/108 | 192.168.5.29 | teletraan-1 Debian 12 | Nautobot: web, worker, beat, PostgreSQL 16 and Redis 7 |
| CT | pve2/120 | 192.168.5.40 | treaddepth Debian 13 | TreadDepth MQTT using Eclipse Mosquitto 2 on TCP 1883 |
Coverage and exceptions
Running containers
All 13 running LXC containers on both nodes now accept the managed RSA key. Existing authorized keys were preserved and duplicate entries avoided.
QEMU VMs
Seven VMs are verified over SSH. VM 108 TDAI, previously key-denied by design, is now reachable after guest-agent key installation.
VM 100 · pve1 · 192.168.1.10
Guest agent responds, but writes to /root/.ssh/authorized_keys return Read-only file system. SSH remains key-denied. Investigate guest filesystem health.
VM 109 · pve2 · 192.168.5.120
QEMU guest agent is not running and SSH times out during banner exchange. Key installation and authenticated inventory remain incomplete.
Agent-unavailable VMs
Mail VM 101 and PacketFence VM 109 on pve1 did not provide guest-agent network data; their network-visible services remain in the wider discovery inventory.
Observability baseline
Most guests run Alloy, Wazuh and/or Zabbix agents. The SOC container hosts Wazuh manager, indexer and dashboard; the Zabbix appliance is VM 101 on pve2.
Cloudflare edge
Pages + Access
docs.optination.net is published through Cloudflare Pages and protected by the OptiNation Docs Access application using Authress.
Tunnels
PT HQ Edge Connector: healthy · 4 connections
opencode: down · 0 connections
Private routing
CF-HQ runs WARP on 192.168.127.55 with overlay IPv4 100.96.0.36 and Cloudflare IPv6 connectivity.
Identity
Authress custom identity endpoint remains prod-sso-auth-identity-gateway.optination.net.
Operational findings
- Repair VM 100 filesystem/key path before relying on direct SSH administration.
- Restore QEMU Guest Agent and SSH responsiveness on pve2 VM 109.
- The opencode Cloudflare tunnel remains down.
- The prod hosting CT retains an unusually broad multi-version PHP and mail stack.
- Ubuntu 20.04 guests (SOC and CF-HQ) should be tracked for lifecycle planning.
Method
Snapshot created 2026-09-24 from Proxmox VM/CT inventories plus non-interactive SSH probes collecting hostname, OS, kernel, addresses, uptime, running service names and active Docker/Podman workloads. Cloudflare tunnel state was read from the current account API.