● VERIFIED GUEST INVENTORY · 2026-09-24

OptiNation infrastructure atlas

Current host-reported inventory of the Proxmox guest estate, routing and Cloudflare edge. Revalidated after organization-wide SSH key deployment.

20
verified guests
7
accessible VMs
13
running CTs
100%
CT SSH coverage

Architecture

pve1 · 192.168.1.5 · Proxmox VE 9.1.9 ├─ 6 verified QEMU VMs └─ 7 running LXC containers · all SSH verified pve2 · 192.168.5.114 · Proxmox VE 9.1.19 ├─ 1 verified QEMU VM · 1 VM still unavailable └─ 6 running LXC containers · all SSH verified Production 192.168.1.0/24 ↔ HQ 192.168.5.0/24 ↔ firewall transit 192.168.11.0/24 Cloudflare WARP connector: CT 103 / 192.168.127.55 / overlay 100.96.0.36

Verified VM and container inventory

Roles below come from OS, service-manager and container-runtime data collected directly from each guest.

TypeNode/IDAddressIdentityCurrent role
VMpve1/108192.168.1.22tdai
Ubuntu 22.04.5
TreadDepth AI: llama-swap, Piper TTS, NVIDIA persistence, tread-depth services
VMpve1/110192.168.1.28master-control
Ubuntu 24.04.4
Cloudflare and Microsoft 365 read-only control services; Docker; Alloy/Wazuh/Zabbix
VMpve1/112192.168.1.32optination-phase-vault
Debian 12
Phase Secrets stack: frontend, backend, worker, PostgreSQL 15, Redis, nginx
VMpve1/113192.168.1.50optination-panel
Debian 12
OptiNation panel: Caddy, PostgreSQL 15, Redis, optination service
VMpve1/116192.168.1.44axigen-mail
Ubuntu 22.04.5
Axigen mail platform with Alloy, Wazuh and Zabbix monitoring
VMpve1/117192.168.1.26tfdatabase-wiki
Debian 12
MediaWiki 1.42, scanner, PostgreSQL 16 and MariaDB 10.11 in Docker
VMpve2/101192.168.5.153appliance
AlmaLinux 8.10
Zabbix server/appliance: MySQL, nginx, PHP-FPM, Postfix
CTpve1/102192.168.1.24corp
Debian 12
Corporate web stack: Apache, MariaDB, Redis, Postfix, Webmin
CTpve1/104192.168.1.25Prod-DNS-Server-2
Debian 12
Production DNS secondary plus Postfix and monitoring agents
CTpve1/105192.168.1.15mx1
Debian 13
Proxmox Mail Gateway: ClamAV, SMTP filter, Postfix, PostgreSQL 17
CTpve1/106192.168.1.13Forum
Ubuntu 25.04
Discourse application in Docker, published on HTTP 80
CTpve1/115192.168.1.111prod
Debian 12
Hosting/mail stack: Apache, Dovecot, Postfix, MariaDB, Redis, Rspamd, multi-version PHP
CTpve1/118192.168.1.30medusa-prod
Debian 12
Medusa storefront/backend with PostgreSQL 16 and Redis 7
CTpve1/119192.168.1.211soc
Ubuntu 20.04.6
Wazuh SOC: manager, indexer, dashboard, Filebeat, nginx
CTpve2/100192.168.5.9energonhub
Debian 12
Grafana, Telegraf, PDC agent and monitoring
CTpve2/103192.168.127.55CF-HQ
Ubuntu 20.04.6
Cloudflare WARP private-network connector; IPv4/IPv6 overlay addresses
CTpve2/104192.168.5.145pulse
Debian 12
Pulse service with Prometheus, Wazuh and Zabbix agents
CTpve2/107192.168.5.207nac
Debian 12
Network access control: FreeRADIUS, nginx and OptiNAC
CTpve2/108192.168.5.29teletraan-1
Debian 12
Nautobot: web, worker, beat, PostgreSQL 16 and Redis 7
CTpve2/120192.168.5.40treaddepth
Debian 13
TreadDepth MQTT using Eclipse Mosquitto 2 on TCP 1883

Coverage and exceptions

Running containers

All 13 running LXC containers on both nodes now accept the managed RSA key. Existing authorized keys were preserved and duplicate entries avoided.

QEMU VMs

Seven VMs are verified over SSH. VM 108 TDAI, previously key-denied by design, is now reachable after guest-agent key installation.

VM 100 · pve1 · 192.168.1.10

Guest agent responds, but writes to /root/.ssh/authorized_keys return Read-only file system. SSH remains key-denied. Investigate guest filesystem health.

VM 109 · pve2 · 192.168.5.120

QEMU guest agent is not running and SSH times out during banner exchange. Key installation and authenticated inventory remain incomplete.

Agent-unavailable VMs

Mail VM 101 and PacketFence VM 109 on pve1 did not provide guest-agent network data; their network-visible services remain in the wider discovery inventory.

Observability baseline

Most guests run Alloy, Wazuh and/or Zabbix agents. The SOC container hosts Wazuh manager, indexer and dashboard; the Zabbix appliance is VM 101 on pve2.

Cloudflare edge

Pages + Access

docs.optination.net is published through Cloudflare Pages and protected by the OptiNation Docs Access application using Authress.

Tunnels

PT HQ Edge Connector: healthy · 4 connections

opencode: down · 0 connections

Private routing

CF-HQ runs WARP on 192.168.127.55 with overlay IPv4 100.96.0.36 and Cloudflare IPv6 connectivity.

Identity

Authress custom identity endpoint remains prod-sso-auth-identity-gateway.optination.net.

Operational findings

This refresh was read-only except for the previously authorized SSH public-key additions. No application services, firewall rules or guest configurations were otherwise changed.

Method

Snapshot created 2026-09-24 from Proxmox VM/CT inventories plus non-interactive SSH probes collecting hostname, OS, kernel, addresses, uptime, running service names and active Docker/Podman workloads. Cloudflare tunnel state was read from the current account API.