# PFVCluster Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster. Combines server provisioning, Proxmox cluster operations, and DNS infrastructure. ## Directory Structure | Directory | Description | |-----------|-------------| | [`provisioning/`](provisioning/) | Server provisioning (SetupNewSystem.sh, security hardening, 2FA, NTP/DNS config, SNMP, Dell OMSA) | | [`tests/`](tests/) | Test suite + VM validation harness | | [`dns-cluster-setup/`](dns-cluster-setup/) | Technitium DNS cluster replication scripts | | [`perf/`](perf/) | Proxmox performance tuning, fleet audit, iperf, switch diagnostics | | [`netinfra/`](netinfra/) | pfv-netinfra-01/02 DNS/NTP setup + audit scripts | | [`switches/`](switches/) | Switch configuration captures | | [`docs/`](docs/) | All documentation | | [`vendor/`](vendor/) | Vendored KNELShellFramework | ## Quick Start ### Provision a new server ```bash sudo bash provisioning/SetupNewSystem.sh ``` Installs packages, applies security hardening (SSH, SCAP-STIG, 2FA, Wazuh), configures NTP/DNS/SNMP/syslog/postfix. ### Validate provisioning on the sandbox VM ```bash VM_ID=6000 ./tests/vm-validation.sh all ``` Snapshots, deploys, runs the test suite, auto-rolls back on failure. ### Run the test suite ```bash ./tests/run-tests.sh all ``` ### Deploy DNS cluster setup ```bash cd dns-cluster-setup/ ./setup.sh all ``` ### Deploy perf tunings to hosts ```bash cd perf/ ./deploy-check.sh # read-only data collection ./deploy-tuning.sh # apply sysctl/tuned/NFS tunings ``` ## Key Documentation | Doc | Contents | |-----|----------| | [`docs/PROJECT.md`](docs/PROJECT.md) | Comprehensive fleet report (7 hosts, VM inventory, storage) | | [`docs/SECURITY.md`](docs/SECURITY.md) | Security architecture and hardening details | | [`docs/tailscale.md`](docs/tailscale.md) | Tailscale vs managed DNS analysis (resolved) | | [`docs/DEPLOYMENT.md`](docs/DEPLOYMENT.md) | Deployment procedures | | [`docs/TODO.md`](docs/TODO.md) | Pending hardware work (tsys2/4/5) | | [`docs/K8S.md`](docs/K8S.md) | Kubernetes architecture deep-dive | | [`dns-cluster-setup/README.md`](dns-cluster-setup/README.md) | DNS cluster setup guide | | [`tests/README.md`](tests/README.md) | Test suite documentation | ## Architecture - **Proxmox hosts**: 7 standalone PVE installs managed via PDM - **DNS**: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02 - **NTP**: pfv-netinfra-01/02 (redundant, LAN IPs) - **Production**: Cloudron VPS in Reston VA (this cluster is R&D only) - **Backups**: Proxmox Backup Server (PBS)