docs: unified README and AGENTS.md for merged repo
Replace the KNELServerBuild README with a unified PFVCluster README covering both provisioning and cluster ops. Update AGENTS.md to document the merged repo layout, key scripts, and project context. Consolidate all documentation under docs/. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
This commit is contained in:
@@ -1,21 +1,70 @@
|
|||||||
# KNEL FetchApply
|
# PFVCluster
|
||||||
|
|
||||||
## Repo Issues
|
Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster.
|
||||||
https://projects.knownelement.com/project/reachableceo-vptechnicaloperations/timeline
|
Combines server provisioning, Proxmox cluster operations, and DNS infrastructure.
|
||||||
|
|
||||||
## Repo Discussion
|
## Directory Structure
|
||||||
https://community.turnsys.com/c/chieftechnologyandproductofficer/26
|
|
||||||
|
|
||||||
|
```
|
||||||
|
provisioning/ Server provisioning (SetupNewSystem.sh, security hardening,
|
||||||
|
2FA, NTP/DNS config, SNMP, Dell OMSA)
|
||||||
|
tests/ Test suite + VM validation harness
|
||||||
|
dns-cluster-setup/ Technitium DNS cluster replication scripts
|
||||||
|
perf/ Proxmox performance tuning, fleet audit, iperf, switch diagnostics
|
||||||
|
netinfra/ pfv-netinfra-01/02 DNS/NTP setup + audit scripts
|
||||||
|
switches/ Switch configuration captures
|
||||||
|
docs/ All documentation (PROJECT.md, SECURITY.md, tailscale.md, etc.)
|
||||||
|
vendor/ Vendored KNELShellFramework
|
||||||
|
```
|
||||||
|
|
||||||
## Repo discription
|
## Quick Start
|
||||||
Known Element Enterprises (the entity serving as the TSYS Group management company) (through it’s executive leader, the COO) provides core IT/back office systems/services/support on a hands off/fully delegated authortity basis to the CCO and the orgs/members.
|
|
||||||
|
|
||||||
One of those functions is the provisoning of Linux servers. This repository is the Infrastructure As Code (IAC) repository for TSYS.
|
### Provision a new server
|
||||||
|
```bash
|
||||||
|
sudo bash provisioning/SetupNewSystem.sh
|
||||||
|
```
|
||||||
|
Installs packages, applies security hardening (SSH, SCAP-STIG, 2FA, Wazuh),
|
||||||
|
configures NTP/DNS/SNMP/syslog/postfix.
|
||||||
|
|
||||||
In the future it will be used via FetchApply https://github.com/P5vc/fetch-apply
|
### Validate provisioning on the sandbox VM
|
||||||
|
```bash
|
||||||
|
VM_ID=6000 ./tests/vm-validation.sh all
|
||||||
|
```
|
||||||
|
Snapshots, deploys, runs the test suite, auto-rolls back on failure.
|
||||||
|
|
||||||
## Usage
|
### Run the test suite
|
||||||
|
```bash
|
||||||
|
./tests/run-tests.sh all
|
||||||
|
```
|
||||||
|
|
||||||
git clone this repo
|
### Deploy DNS cluster setup
|
||||||
cd FetchApply/ProjectCode
|
```bash
|
||||||
bash SetupNewSystem.sh
|
cd dns-cluster-setup/
|
||||||
|
./setup.sh all
|
||||||
|
```
|
||||||
|
|
||||||
|
### Deploy perf tunings to hosts
|
||||||
|
```bash
|
||||||
|
cd perf/
|
||||||
|
./deploy-check.sh # read-only data collection
|
||||||
|
./deploy-tuning.sh # apply sysctl/tuned/NFS tunings
|
||||||
|
```
|
||||||
|
|
||||||
|
## Key Documentation
|
||||||
|
|
||||||
|
| Doc | Contents |
|
||||||
|
|-----|----------|
|
||||||
|
| `docs/PROJECT.md` | Comprehensive fleet report (7 hosts, VM inventory, storage) |
|
||||||
|
| `docs/SECURITY.md` | Security architecture and hardening details |
|
||||||
|
| `docs/tailscale.md` | Tailscale vs managed DNS analysis |
|
||||||
|
| `docs/DEPLOYMENT.md` | Deployment procedures |
|
||||||
|
| `docs/TODO.md` | Pending hardware work (tsys2/4/5) |
|
||||||
|
| `dns-cluster-setup/README.md` | DNS cluster setup guide |
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|
- **Proxmox hosts**: 7 standalone PVE installs managed via PDM
|
||||||
|
- **DNS**: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02
|
||||||
|
- **NTP**: pfv-netinfra-01/02 (redundant, LAN IPs)
|
||||||
|
- **Production**: Cloudron VPS in Reston VA (this cluster is R&D only)
|
||||||
|
- **Backups**: Proxmox Backup Server (PBS)
|
||||||
|
|||||||
Reference in New Issue
Block a user