Proxmox and Tailscale¶
Current role¶
Proxmox hosts the internal LXC workloads. Tailscale is the management path.
Workload map¶
| ID | Host/workload | Purpose |
|---|---|---|
| 101 | edge-gateway | Nginx Proxy Manager + Cloudflare Tunnel |
| 102 | n8n-app | n8n |
| 103 | homepage | Homepage dashboard (updated to v1.13.2, 2026-08-07) |
| 106 | exzen-staging | exzen-core staging (serves telegram-staging-api.exzentcg.com) |
| 107 | dev-shell | dev Postgres/Redis and dev worktree — superseded by Hermes, decommission candidate |
| 108 | shopee-print | Otto + printer |
| 109 | hermes | Hermes dashboard/agent |
Non-Proxmox tailnet host: ampere (OCI ARM64 VM, 100.85.99.41) — hosts the tcg-platform staging stack since 2026-08-13, after CT 105 (tcg-staging) was decommissioned and destroyed (its LVM volume was removed). See Systems/tcg-platform.md.
Notable risk areas¶
- Discovery found no configured Proxmox backup jobs.
- Single physical NVMe; no mirror/redundancy.
- LXC 107 exposed broad Postgres/Redis listeners without effective firewall enforcement.
- IPv6 firewall posture remained unresolved.
- Some
.envand backup files existed in deployed directories. - Routine automation still uses broad root SSH rather than a dedicated least-privilege Proxmox identity.
Recent housekeeping (2026-08-07)¶
- Reclaimed the LVM-thin pool from ~52% to ~28% used: removed 7 stale Claude git worktrees (~11 GB) and tool caches on CT 107, dropped an orphaned
pre_n8n_2335snapshot on CT 102, and ranpct fstrimacross all containers. - CT 107 (
dev-shell) is flagged as a decommission candidate — superseded by Hermes (CT 109).
These are current-state notes, not a request to create generic runbook pages.