Pinky was missing from the map entirely. Documents its purpose (Docker/Linux-only workloads, esp. Android SDK/emulator builds) and the current SSH access gap (root's key not authorized, user is malin) found while chasing an apuntiq Android build.
50 lines
4.8 KiB
Markdown
50 lines
4.8 KiB
Markdown
---
|
|
name: server-fleet-map
|
|
description: Use when deciding WHICH host a piece of work belongs on, or when you need a host's connection details. Reference map of the FreeBSD/bastille jail fleet and what each host is actually for.
|
|
---
|
|
|
|
# Server Fleet Map
|
|
|
|
All hosts reachable over Tailscale (`root@<host>`, SSH key
|
|
`/root/.ssh/id_ed25519` unless noted). Each host has a distinct
|
|
**purpose** — check this before assuming a new site/service belongs on
|
|
whichever host you happen to already be connected to.
|
|
|
|
| Host | Tailscale IP | Purpose | Notes |
|
|
|---|---|---|---|
|
|
| **staging** | `100.104.61.54` | Dev/staging — pre-production testing, throwaway experiments | New jail IPs here need the same arp-scan discipline as everywhere else on this shared LAN (see `bastille-jail-provisioning` skill) — this is where that gotcha was first found. |
|
|
| **venus** | `100.109.251.127` (LAN `192.168.0.33`) | Corporate — internal business sites/tools, the iWP.es plugin-subscription platform, and other CloudHost-org first-party projects | Bastille jails, combined web+db (local MariaDB, no shared external DB host). New jails typically created via `bastille clone -a <known-good-base>` rather than from scratch. |
|
|
| **granja** | `100.98.197.28` | Affiliate network — the travel/tourism site network (menorca.ro, palma.ro, and similar) | No public interface configured directly; sits behind a reverse-proxy manager (NPM) over Tailscale. See `docs/server-granja.md` for the local-curl-simulates-NPM testing trick. |
|
|
| **funky** | `100.127.21.100` (LAN `192.168.0.218`) | Customers — sites migrated from the old Linux affiliate fleet, actual paying-customer properties (e.g. news.easycut.es, photomouse.ro) | Combined web+db+valkey, bastille jails. Migration target that absorbed several now-decommissioned Linux hosts (maagar, shoe, proton). |
|
|
| **gringo** | `100.95.46.79` (LAN `192.168.168.68`) | Internal apps/tools host — replacement for the old Linux Docker host barky-1 | ~45 Bastille VNET jails on `10.20.0.0/24` (APIs, dashboards, Gitea, analytics, productivity tools). Default-deny outbound pf model; NPM dedicated ports `8000 + last octet`. See `docs/server-gringo.md`. |
|
|
| **zamolxis** | `100.115.128.41` | Standalone (non-jailed) FreeBSD site host | Not part of the granja/external-fleet jail families — a single site (Newspaper/tagDiv theme, PHP 8.5) running directly on the host, not in a jail. |
|
|
| **cabrera** | `100.100.108.19`, SSH port `79` | External Linux affiliate-network host (BTPanel-style) | Part of the older Linux fleet (alongside raptor/maagar/formentor/moonie/spunky/proton/shoe — several since decommissioned/migrated to funky). Hosts easycut.es's main WooCommerce e-commerce site directly (not jailed). |
|
|
| **pinky** | `100.78.228.127` (`pinky.taild32c88.ts.net`) | Linux/Docker-only workloads — genuine Docker containers, or a Linux-only build toolchain (the **Android SDK + emulator** for Capacitor APK builds, e.g. Bauxa) | Not part of the FreeBSD/Bastille fleet above — **SSH user is `malin`, not `root`**, and as of 2026-08-13 `root`'s standard key is not authorized here (`Permission denied (publickey)`; `tailscale ssh` also fails). No working credentials for this host as of that date — same blocker hit independently by two unrelated tasks (SMS gateway deploy, apuntiq Android build). Don't default work here just because it's Linux-flavored — see "How to decide" below; this host is for genuinely Docker/Linux-specific needs only. See `docs/server-pinky.md` in granja. |
|
|
|
|
## How to decide where new work belongs
|
|
|
|
1. **What kind of thing is it?** A corporate/internal tool → venus. A
|
|
customer's production site → funky. A new affiliate-network travel
|
|
site → granja. A quick experiment or something not ready for anything
|
|
resembling production → staging. **Default to FreeBSD (gringo) even
|
|
for Linux-shaped work** — only use pinky if it genuinely needs Docker
|
|
or a Linux-only toolchain (e.g. the Android SDK/emulator); "it's
|
|
Linux/Docker-based elsewhere in this project" is not by itself a
|
|
reason to put a stateless piece on pinky.
|
|
2. **Does it already have an established host from a related sibling
|
|
project?** (e.g. another CloudHost-org first-party tool already lives
|
|
on venus) — match that, don't scatter related things across hosts
|
|
without a reason.
|
|
3. **When genuinely unsure, ask** rather than guessing — which host
|
|
something lives on affects DNS, backup scope, and who has access to
|
|
it later.
|
|
|
|
## Gitea (separate from any of the above)
|
|
|
|
`https://devops.cloudhost.es` — not one of the site-hosting fleet, this
|
|
is the internal git/CI host. Orgs seen so far: `CloudHost` (main
|
|
internal projects + this skills repo), `iWP.es` (the plugin-subscription
|
|
product and its forked/rebranded plugins), `InformatiQ` (the security
|
|
plugin), `External` (mirrors of third-party repos for internal
|
|
reference).
|