Keep sanitized Compose sources in-repo with a confirmation-gated Ansible playbook, add repo-wide validation, tighten runbook ownership/STOP/review metadata, and archive stale research docs. Co-authored-by: Cursor <cursoragent@cursor.com>
4.4 KiB
Host inventory
Routine health, maintenance previews, and reviewed Compose reconciliations are run through Ansible. SSH endpoints below remain the access path for focused diagnosis and procedures that are deliberately interactive or destructive; see the Ansible operations runbook.
For a live-verified map of the internal LAN (gw, gfw, dns, ubnt, APs) and the software deployed there, see the LAN overview.
Ansible 列:✓ = 该主机在 ansible/inventory/hosts.yml
(执行真相),用其 inventory key(见括号注)跑 playbook;— = 不由 Ansible 管理,
原因是该平台无 ansible 覆盖或仅是公网别名/服务端点。
| Host | Role | SSH | IPv4 | Ansible | Status | Facts |
|---|---|---|---|---|---|---|
| mx2.windy.me | mailcow (primary MX prio 20) | ssh -4 windy@mx2.windy.me |
194.163.160.244 | ✓ (mx2) | active | hosts/mx2.windy.me.md |
| us2.wsvc.info | Vaultwarden/Postgres (+ Traefik, Soft Serve, …) | ssh -4 windy@us2.wsvc.info |
193.9.44.165 | ✓ (us2) | active | hosts/us2.wsvc.info.md |
| mx.windy.me | mail (secondary MX prio 30) | TBD | see AAAA/A | — (stub) | stub | — |
| repo.windy.me | Soft Serve git (on us2) | ssh -p 2222 windy@repo.windy.me |
193.9.44.165 | — (service on us2) | stub | see us2 |
| auth.wsvc.info | Vaultwarden public hostname | — (HTTPS) | → us2 | — (alias) | active | see us2 |
| us1.wsvc.info | PowerDNS secondary (ns2 host) | TBD | 202.91.35.141 | — (stub) | stub | Auth 5.0.5; see hk2 |
| us4.wsvc.info | WireGuard VPN | ssh -4 windy@us4.wsvc.info |
185.201.226.122 | ✓ (us4) | active | hosts/us4.wsvc.info.md |
| hk2.chans.xyz | PowerDNS auth (ns1) | ssh -4 windy@hk2.chans.xyz |
154.36.174.161 | ✓ (hk2) | active | hosts/hk2.chans.xyz.md |
| ns1.wsvc.info | PowerDNS public NS name | — (DNS) | → hk2 154.36.174.161 |
— (alias) | active | see hk2 |
| ns2.wsvc.info | Secondary NS (AXFR/NOTIFY peer) | — (DNS) | → us1 202.91.35.141 |
— (alias) | active | see hk2 |
| pdns.wsvc.info | Poweradmin UI | — (HTTPS) | → hk2 | — (alias) | active | see hk2 |
| pgweb.wsvc.info | PowerDNS Postgres UI | — (HTTPS) | → hk2 | — (alias) | active | see hk2 |
| synapse.chans.xyz | Matrix homeserver (ESS: Synapse + MAS + Element) | ssh -4 windy@synapse.chans.xyz |
169.58.86.13 |
✓ (matrix_vps) | active | hosts/synapse.chans.xyz.md |
| gfw.windy.lan | OpenWrt (ImmortalWrt) LAN gateway / OpenClash (PVE VM 140) | ssh -4 root@192.168.66.1 |
192.168.66.1 |
— (OpenWrt, no ansible) | active | hosts/gfw.windy.lan.md |
| dns.windy.lan | AdGuard Home LAN DNS + Mihomo explicit proxy (PVE VM 120) | ssh -4 windy@192.168.66.36 |
192.168.66.36 |
✓ (dns_windy_lan) | active | hosts/dns.windy.lan.md |
| gw | EdgeRouter X primary LAN gateway | ssh -4 zhiqiang@192.168.66.254 |
192.168.66.254 |
— (EdgeOS, no ansible) | active | hosts/gw.md |
| ubnt | UniFi Network Controller (PVE VM 160) | ssh -4 windy@192.168.66.46 |
192.168.66.46 |
✓ (ubnt) | active | hosts/ubnt.md |
| hass.windy.lan | Home Assistant (HAOS, PVE VM 180, LAN55) | ssh hassio@hass.windy.lan |
192.168.55.11 |
— (HAOS, no ansible) | active | hosts/hass.windy.lan.md |
status: stub = known to exist; fill hosts/<name>.md when next touched.
命名映射:ansible inventory key ↔ 本表主机名 —— matrix_vps ↔ synapse.chans.xyz、
dns_windy_lan ↔ dns.windy.lan。inventory key 不随主机名改(防止破坏 --limit 用法),
通过 inventory 内的 display_name 变量与文档交叉引用。
Matrix services (synapse.chans.xyz)
| URL | Service | Notes |
|---|---|---|
| https://chat.chans.xyz | Element Web | Matrix web client |
| https://synapse.chans.xyz | Synapse API | Client-Server + Federation API |
| https://account.chans.xyz | MAS | Matrix Authentication Service (local passwords) |
| https://admin.chans.xyz | Element Admin | Admin console (MAS admin auth) |
mrtc.chans.xyz |
MatrixRTC | Reserved – not deployed |