Files
vps/inventory/hosts.md
T
windyboy c0c975584a docs(plane): 自托管 Plane 落地事实入仓库 + plane-health runbook + hardening 草稿
记录源 Linear→Plane (2026-09-03 起, Plane MCP) + plane.chans.xyz 服务行/upstream 段;
inventory + hosts/synapse.chans.xyz.md 补 Plane 部署事实 (Helm plane-ce-1.8.0 / app v1.4.1,
ns plane, IngressRoute/自有证书 issuer/PVC 5+5Gi local-path/无备份层);
新增 runbooks/plane-health.md (只读健康检查) 与 docs/plane-hardening/ 草稿
(values.hardened.yaml、secrets.yaml.example 占位、backup/ CronJob), 均为未应用设计稿;
.gitignore 增加 .tmp-* agent 临时文件。
2026-09-13 19:12:32 +08:00

4.7 KiB
Raw Blame History

Host inventory

Routine health, maintenance previews, and reviewed Compose reconciliations are run through Ansible. SSH endpoints below remain the access path for focused diagnosis and procedures that are deliberately interactive or destructive; see the Ansible operations runbook.

For a live-verified map of the internal LAN (gw, gfw, dns, ubnt, APs) and the software deployed there, see the LAN overview.

Ansible 列 = 该主机在 ansible/inventory/hosts.yml (执行真相),用其 inventory key(见括号注)跑 playbook = 不由 Ansible 管理, 原因是该平台无 ansible 覆盖或仅是公网别名/服务端点。

Host Role SSH IPv4 Ansible Status Facts
mx2.windy.me mailcow (primary MX prio 20) ssh -4 windy@mx2.windy.me 194.163.160.244 ✓ (mx2) active hosts/mx2.windy.me.md
us2.wsvc.info Vaultwarden/Postgres (+ Traefik, Soft Serve, …) ssh -4 windy@us2.wsvc.info 193.9.44.165 ✓ (us2) active hosts/us2.wsvc.info.md
mx.windy.me mail (secondary MX prio 30) TBD see AAAA/A — (stub) stub
repo.windy.me Soft Serve git (on us2) ssh -p 2222 windy@repo.windy.me 193.9.44.165 — (service on us2) stub see us2
auth.wsvc.info Vaultwarden public hostname — (HTTPS) → us2 — (alias) active see us2
us1.wsvc.info PowerDNS secondary (ns2 host) TBD 202.91.35.141 — (stub) stub Auth 5.0.5; see hk2
us4.wsvc.info WireGuard VPN ssh -4 windy@us4.wsvc.info 185.201.226.122 ✓ (us4) active hosts/us4.wsvc.info.md
hk2.chans.xyz PowerDNS auth (ns1) ssh -4 windy@hk2.chans.xyz 154.36.174.161 ✓ (hk2) active hosts/hk2.chans.xyz.md
ns1.wsvc.info PowerDNS public NS name — (DNS) → hk2 154.36.174.161 — (alias) active see hk2
ns2.wsvc.info Secondary NS (AXFR/NOTIFY peer) — (DNS) → us1 202.91.35.141 — (alias) active see hk2
pdns.wsvc.info Poweradmin UI — (HTTPS) → hk2 — (alias) active see hk2
pgweb.wsvc.info PowerDNS Postgres UI — (HTTPS) → hk2 — (alias) active see hk2
synapse.chans.xyz Matrix homeserver (ESS: Synapse + MAS + Element) ssh -4 windy@synapse.chans.xyz 169.58.86.13 ✓ (matrix_vps) active hosts/synapse.chans.xyz.md
gfw.windy.lan OpenWrt (ImmortalWrt) LAN gateway / OpenClash (PVE VM 140) ssh -4 root@192.168.66.1 192.168.66.1 — (OpenWrt, no ansible) active hosts/gfw.windy.lan.md
dns.windy.lan AdGuard Home LAN DNS + Mihomo explicit proxy (PVE VM 120) ssh -4 windy@192.168.66.36 192.168.66.36 ✓ (dns_windy_lan) active hosts/dns.windy.lan.md
gw EdgeRouter X primary LAN gateway ssh -4 zhiqiang@192.168.66.254 192.168.66.254 — (EdgeOS, no ansible) active hosts/gw.md
ubnt UniFi Network Controller (PVE VM 160) ssh -4 windy@192.168.66.46 192.168.66.46 ✓ (ubnt) active hosts/ubnt.md
hass.windy.lan Home Assistant (HAOS, x88 Pro physical box, LAN55) ssh hassio@hass.windy.lan 192.168.55.11 — (HAOS, no ansible) active hosts/hass.windy.lan.md
pgdb TimescaleDB PG18 (Docker) — HA recorder backend (PVE VM, LAN55) ssh -4 windy@192.168.55.15 192.168.55.15 — (no ansible) active hosts/pgdb.md

status: stub = known to exist; fill hosts/<name>.md when next touched.

命名映射ansible inventory key ↔ 本表主机名 —— matrix_vpssynapse.chans.xyzdns_windy_landns.windy.lan。inventory key 不随主机名改(防止破坏 --limit 用法), 通过 inventory 内的 display_name 变量与文档交叉引用。

Matrix services (synapse.chans.xyz)

URL Service Notes
https://chat.chans.xyz Element Web Matrix web client
https://synapse.chans.xyz Synapse API Client-Server + Federation API
https://account.chans.xyz MAS Matrix Authentication Service (local passwords)
https://admin.chans.xyz Element Admin Admin console (MAS admin auth)
https://plane.chans.xyz Plane Project management (Helm plane-ce v1.4.1, ns plane)
mrtc.chans.xyz MatrixRTC Reserved not deployed