a7fbad60ab910604fe2d71de59ae16854d7ae39b
Comprehensive documentation gardening across the merged repo: - tailscale.md: fully rewritten with current ground truth. The netinfra pair now runs production Technitium with all knel.net records replicated. Both LAN IPs resolve knel.net device names and recurse externally. The old "NXDOMAIN / zone is stale" findings are replaced with the resolved state and current recommendations. - AGENTS.md: rewritten with Gitea-compatible clickable relative links to all key scripts and docs. Autonomous commit/push policy prominently documented. SSH user corrected to localuser. - README.md: directory table and docs table now use clickable links. - All .md cross-references converted to Gitea-renderable relative links. - Stale path references (ProjectCode/, Project-Tests/, ProjectDocs/) updated to current names (provisioning/, tests/) across all docs. - Stale repo name "FetchApply" / "KNELServerBuild" updated to "PFVCluster" in actionable docs; historical AI-review docs tagged with an HTML comment notice. - REFACTORING-EXAMPLES.md: tagged as historical (pre-refactor patterns). - tests/README.md, dns-cluster-setup/README.md, docs/DEPLOYMENT.md, docs/SECURITY.md: path references fixed to current structure. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
PFVCluster
Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster. Combines server provisioning, Proxmox cluster operations, and DNS infrastructure.
Directory Structure
| Directory | Description |
|---|---|
provisioning/ |
Server provisioning (SetupNewSystem.sh, security hardening, 2FA, NTP/DNS config, SNMP, Dell OMSA) |
tests/ |
Test suite + VM validation harness |
dns-cluster-setup/ |
Technitium DNS cluster replication scripts |
perf/ |
Proxmox performance tuning, fleet audit, iperf, switch diagnostics |
netinfra/ |
pfv-netinfra-01/02 DNS/NTP setup + audit scripts |
switches/ |
Switch configuration captures |
docs/ |
All documentation |
vendor/ |
Vendored KNELShellFramework |
Quick Start
Provision a new server
sudo bash provisioning/SetupNewSystem.sh
Installs packages, applies security hardening (SSH, SCAP-STIG, 2FA, Wazuh), configures NTP/DNS/SNMP/syslog/postfix.
Validate provisioning on the sandbox VM
VM_ID=6000 ./tests/vm-validation.sh all
Snapshots, deploys, runs the test suite, auto-rolls back on failure.
Run the test suite
./tests/run-tests.sh all
Deploy DNS cluster setup
cd dns-cluster-setup/
./setup.sh all
Deploy perf tunings to hosts
cd perf/
./deploy-check.sh # read-only data collection
./deploy-tuning.sh # apply sysctl/tuned/NFS tunings
Key Documentation
| Doc | Contents |
|---|---|
docs/PROJECT.md |
Comprehensive fleet report (7 hosts, VM inventory, storage) |
docs/SECURITY.md |
Security architecture and hardening details |
docs/tailscale.md |
Tailscale vs managed DNS analysis (resolved) |
docs/DEPLOYMENT.md |
Deployment procedures |
docs/TODO.md |
Pending hardware work (tsys2/4/5) |
docs/K8S.md |
Kubernetes architecture deep-dive |
dns-cluster-setup/README.md |
DNS cluster setup guide |
tests/README.md |
Test suite documentation |
Architecture
- Proxmox hosts: 7 standalone PVE installs managed via PDM
- DNS: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02
- NTP: pfv-netinfra-01/02 (redundant, LAN IPs)
- Production: Cloudron VPS in Reston VA (this cluster is R&D only)
- Backups: Proxmox Backup Server (PBS)
Languages
Shell
69.6%
Python
25.8%
Perl
4.4%
Makefile
0.2%