mrcharles 290245349f docs(drift): fleet drift report with executive briefing format
Dedicated drift report covering package/service/tuning/security
inconsistencies across all 7 Proxmox hosts. Executive briefing at the
top (what needs decisions, quick severity summary), detailed matrices
in appendixes.

Key drift findings:
- lldpd inactive on tsys1 (blind spot in topology)
- tsys9 missing 2 SSH keys vs fleet standard
- iperf3 missing on tsys9, net-tools missing on tsys1/6/7
- sysstat missing on tsys5, nvme-cli missing on tsys4/5
- tsys4 tuning drift: 16MB TCP buffers, low backlog, wrong tuned profile
- rsyslog + snmpd + beszel inactive fleet-wide (Saturday OAM Day items)
- noatime only on tsys5 root fs (all others use relatime)

Added perf/scripts/probe-drift.sh as a portable reusable drift probe.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-07-30 23:27:54 -05:00
2024-10-12 03:38:27 +00:00

PFVCluster

Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster.

→ Current Status · → Documentation Index · → Agent Guidelines

Directory Structure

Directory Description
provisioning/ Server provisioning (SetupNewSystem.sh, security hardening, 2FA, NTP/DNS config, SNMP, Dell OMSA)
tests/ Test suite + VM validation harness
dns-cluster-setup/ Technitium DNS cluster replication scripts
k8s/ k3s cluster setup scripts (3-node HA control plane over Tailscale) + co-located docs
powerman/ Cyclades PM10i PDU management via powerman on pfv-tsys1
console/ Serial console management (ser2net + conman) for network switches on pfv-tsys4
ups/ UPS management (NUT) for APC Smart-UPS C 1500 on pfv-tsys1 — upsd on Tailscale
perf/ Proxmox performance tuning, fleet audit, iperf, switch diagnostics
proxmox/ Proxmox fleet docs: hardware audit, capacity analysis, k8s host planning
netinfra/ pfv-netinfra-01/02 DNS/NTP/DHCP setup + audit scripts
switches/ Switch configuration captures
awx/ Ansible AWX deployment on tsys-awx (k3s + AWX Operator 2.19.1, v24.6.1)
docs/ Server-build docs, documentation index (docmap), and archive
vendor/ Vendored KNELShellFramework

Quick Start

Provision a new server

sudo bash provisioning/SetupNewSystem.sh

Validate on the sandbox VM

VM_ID=6000 ./tests/vm-validation.sh all

Deploy DNS cluster

cd dns-cluster-setup/ && ./setup.sh all

Deploy perf tunings

cd perf/ && ./deploy-tuning.sh

Architecture

  • Proxmox hosts: 7 standalone PVE installs managed via PDM
  • DNS: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02
  • NTP: pfv-netinfra-01/02 (redundant, LAN IPs, stratum 2/3)
  • Production: Cloudron VPS in Reston VA (this cluster is R&D only)
  • Backups: Proxmox Backup Server (PBS)
S
Description
All things related to the PFV proxmox/k8s cluster .
Readme AGPL-3.0
6.8 MiB
Languages
Shell 69.6%
Python 25.8%
Perl 4.4%
Makefile 0.2%