Replace the KNELServerBuild README with a unified PFVCluster README covering both provisioning and cluster ops. Update AGENTS.md to document the merged repo layout, key scripts, and project context. Consolidate all documentation under docs/. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
2.2 KiB
2.2 KiB
PFVCluster
Unified infrastructure repo for the Known Element Enterprises Proxmox R&D cluster. Combines server provisioning, Proxmox cluster operations, and DNS infrastructure.
Directory Structure
provisioning/ Server provisioning (SetupNewSystem.sh, security hardening,
2FA, NTP/DNS config, SNMP, Dell OMSA)
tests/ Test suite + VM validation harness
dns-cluster-setup/ Technitium DNS cluster replication scripts
perf/ Proxmox performance tuning, fleet audit, iperf, switch diagnostics
netinfra/ pfv-netinfra-01/02 DNS/NTP setup + audit scripts
switches/ Switch configuration captures
docs/ All documentation (PROJECT.md, SECURITY.md, tailscale.md, etc.)
vendor/ Vendored KNELShellFramework
Quick Start
Provision a new server
sudo bash provisioning/SetupNewSystem.sh
Installs packages, applies security hardening (SSH, SCAP-STIG, 2FA, Wazuh), configures NTP/DNS/SNMP/syslog/postfix.
Validate provisioning on the sandbox VM
VM_ID=6000 ./tests/vm-validation.sh all
Snapshots, deploys, runs the test suite, auto-rolls back on failure.
Run the test suite
./tests/run-tests.sh all
Deploy DNS cluster setup
cd dns-cluster-setup/
./setup.sh all
Deploy perf tunings to hosts
cd perf/
./deploy-check.sh # read-only data collection
./deploy-tuning.sh # apply sysctl/tuned/NFS tunings
Key Documentation
| Doc | Contents |
|---|---|
docs/PROJECT.md |
Comprehensive fleet report (7 hosts, VM inventory, storage) |
docs/SECURITY.md |
Security architecture and hardening details |
docs/tailscale.md |
Tailscale vs managed DNS analysis |
docs/DEPLOYMENT.md |
Deployment procedures |
docs/TODO.md |
Pending hardware work (tsys2/4/5) |
dns-cluster-setup/README.md |
DNS cluster setup guide |
Architecture
- Proxmox hosts: 7 standalone PVE installs managed via PDM
- DNS: Technitium (authoritative) + Pi-hole (recursive) on pfv-netinfra-01/02
- NTP: pfv-netinfra-01/02 (redundant, LAN IPs)
- Production: Cloudron VPS in Reston VA (this cluster is R&D only)
- Backups: Proxmox Backup Server (PBS)