30ddb37b34302b95162e8dbbffdd7f2ab9cd8205
Commit 33b5c76 claimed to harden Pi-hole on both DNS nodes but only
modified markdown — the working docker-compose.yml, gravity-validate.sh,
healthcheck, and autoheal config were never written to the repo, leaving
the DNS hardening unreproducible from version control.
This commits the live, verified-working config from the boxes into
netinfra/pihole/:
- docker-compose.yml (shm_size 1024M root-cause fix, healthcheck, autoheal)
- gravity-validate.sh (pre-start SQLite header check, auto-quarantine corrupt DB)
- .env.example (web UI password templated; real .env gitignored)
Defends against the gravity.db / /dev/shm corruption production outage.
The live password is templated as ${PIHOLE_WEB_PASSWORD} so no secret
enters git.
[#376]
PFVCluster
Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster.
→ Current Status · → Documentation Index · → Agent Guidelines
Directory Structure
| Directory | Description |
|---|---|
dcinfra/ |
Data-center infrastructure: PDU (powerman/), serial console (console/), UPS (ups/) |
netinfra/ |
DNS/NTP/DHCP setup + audit scripts, DNS cluster replication (dns-cluster-setup/), switch captures (switches/), DHCP config (dhcp/) |
k8s/ |
k3s cluster setup scripts (HA control plane over Tailscale) + co-located docs |
proxmox/ |
Proxmox fleet docs (hardware audit, capacity, storage, k8s host planning) + performance tuning (perf/) |
awx/ |
Ansible AWX deployment (k3s + AWX Operator) |
tests/ |
Test suite + VM validation harness + remote.sh SSH chokepoint |
docs/ |
Server-build docs, documentation index (docmap), and archive |
archive/ |
Historical/superseded code (provisioning → replaced by KNELIAC project) |
vendor/ |
Vendored KNELShellFramework |
Quick Start
Provision a new server
sudo bash provisioning/SetupNewSystem.sh
Validate on the sandbox VM
VM_ID=6000 ./tests/vm-validation.sh all
Deploy DNS cluster
cd dns-cluster-setup/ && ./setup.sh all
Deploy perf tunings
cd perf/ && ./deploy-tuning.sh
Architecture
- Proxmox hosts: 7 standalone PVE installs managed via PDM
- DNS: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02
- NTP: pfv-netinfra-01/02 (redundant, LAN IPs, stratum 2/3)
- Production: Cloudron VPS in Reston VA (this cluster is R&D only)
- Backups: Proxmox Backup Server (PBS)
Languages
Shell
69.6%
Python
25.8%
Perl
4.4%
Makefile
0.2%