Fleet-wide Linux access + naming audit, run 2026-08-26 from the workstation (ultix-streaming) via scripts/audit-fleet.sh in the PFVCluster repo (Redmine #446). Read-only — nothing was changed on any system.
Summary
| Check | Result |
|---|---|
| Linux machines on tailnet | 75 (74 peers + workstation itself) |
| Online | 74 |
| Offline (any OS) | 1 — stlp-3dscanner (last seen 2026-02-03, ~7 months) |
| DNS name → correct Tailscale IP | 74/74 peers OK (100%); workstation ultix-streaming.knel.net is the 1 mismatch |
| SSH login with expected user | 54 OK / 19 FAIL / 1 offline |
| Root escalation (sudo -n) | 54/54 verified (every host that accepted SSH; Proxmox logs in as root) |
| Proxmox VM name ↔ Tailscale hostname | 5 mismatches (appliance-driven, see below) |
Expected-user model audited: root on Proxmox hosts + PBS + sectestbed-PVE, subodev on Pis/Jetson, localuser everywhere else.
SSH failures (19 + 1 offline)
| Host | DNS name | Reason (from sshd) | Notes / proposed fix |
|---|---|---|---|
| pfv-jetson-nano-1 | pfv-jetson-nano-1.knel.net | Permission denied (publickey,password) as subodev | Deploy workstation SSH key to subodev (needs console/physical — Saturday candidate) |
| pfvsvrpi | pfvsvrpi.knel.net | Permission denied (publickey) as subodev | Same — key deploy needed; host is up (banner answers) |
| stlpc-artroom | stlpc-artroom.knel.net | Permission denied (publickey,password) | No localuser key; #341 needs this host for TEMPer deploy |
| stlpc-garage | stlpc-garage.knel.net | Permission denied (publickey,password) | Same |
| ultixfield | ultix-field.knel.net | Permission denied (publickey,password) | Field device; note DNS/TS name spelling differs |
| tsys-cloudron-new | tsys-cloudron.knel.net | Permission denied (publickey,password,keyboard-interactive) | Production Cloudron VPS (Reston) — decide intended access user; do not experiment on prod |
| tsys-ucs-01 | tsys-ucs-01.knel.net | Permission denied (publickey,gssapi,keyboard-interactive) | UCS appliance: no localuser; likely needs localuser created or documented admin path |
| tsys-ucs-02 | tsys-ucs-02.knel.net | Permission denied (publickey,gssapi,keyboard-interactive) | Same |
| tsys-proxmox-datacenter | tsys-proxmox-datacenter.knel.net | Permission denied (publickey,password) | PDM appliance VM; try root-key or create localuser |
| tsys-proxmox-mailgw-01 | tsys-proxmox-mailgw-01.knel.net | Permission denied (publickey,password) | PMG appliance: root@pmg shell is the norm; key not installed |
| tsys-proxmox-mailgw-02 | tsys-proxmox-mailgw-02.knel.net | Permission denied (publickey,password) | Same |
| preprod-proxmox-datacenter | preprod-proxmox-datacenter.knel.net | Permission denied (publickey,password) | Same class as prod PDM |
| preprod-proxmox-mailgw | preprod-proxmox-mailgw.knel.net | Permission denied (publickey,password) | Same class as prod PMG |
| sectestbed-proxmox-datacenter | sectestbed-proxmox-datacenter.knel.net | Permission denied (publickey,password) | Same |
| sectestbed-proxmox-mailgw | sectestbed-proxmox-mailgw.knel.net | Permission denied (publickey,password) | Same |
| sectestbed-proxmox-pbs | sectestbed-proxmox-pbs.knel.net | Permission denied (publickey,password) | PBS appliance: root is the norm (prod PBS works as root) |
| sectestbed-sandbox | sectestbed-sandbox.knel.net | Permission denied (keyboard-interactive) | localuser exists but no pubkey installed; remote-dns.sh sandbox mode depends on it |
| homeassistant (pfv-bms) | pfv-bms.knel.net | Connection refused (port 22) | Home Assistant OS — known/accepted: no SSH by design |
| umbrel (tsys-umbrel) | tsys-umbrel.knel.net | Permission denied (publickey,password) | Umbrel OS — known/accepted: no SSH planned |
| stlp-3dscanner | stlp-3dscanner.knel.net | OFFLINE since 2026-02-03 | Power/network check when onsite |
Pattern: 10 of 19 failures are Proxmox/UCS appliance VMs (PDM, PMG, PBS, UCS) that only know root, not localuser. Decision needed: standardize appliance access (root key) vs create localuser with sudo.
Name mismatches (Tailscale hostname vs VM/DNS name)
| Tailscale hostname | VM name | DNS name | IP | Suggested owner action |
|---|---|---|---|---|
| homeassistant | pfv-bms | pfv-bms.knel.net | 100.67.108.125 | Accepted (HA OS); keep alias documented |
| umbrel | tsys-umbrel | tsys-umbrel.knel.net | 100.66.182.14 | Accepted (Umbrel OS); keep alias documented |
| ultixfield | (physical) | ultix-field.knel.net | 100.115.233.124 | Rename TS node or DNS to match spelling |
| sectestbed-hfnoc | sectestbed-hfnoc-uisp | sectestbed-hfnoc-uisp.knel.net | 100.101.168.80 | Rename one side |
| tsys-cloudron-new | (none — Reston VPS) | tsys-cloudron.knel.net | 100.107.35.78 | Align TS hostname with DNS or vice versa |
| ultix-streaming (workstation) | ultix-streaming@tsys5 | resolves 127.0.1.1, not TS IP | 100.101.187.119 | Fix knel.net record for the workstation |
Other findings
tailscale-router.knel.net(andpfv-netboot.knel.net,pfv-tsys2,knelai-*) now return NXDOMAIN — the stale records listed in the Aug-6 inventory were cleaned. Butnetinfra/dns-cluster-setup/remote-dns.shstill defaults itstsrouteralias totailscale-router.knel.net, so that mode is dead until repointed.netbird(100.123.45.23) is a physical box, not a Proxmox VM; DNS + localuser + sudo all pass.- VMs with no Tailscale presence (out of scope but noteworthy):
DellOpenManageEnterprise(712), plus the three templates. - Full raw results:
scripts/audit-fleet.shre-run emits the TSV; per-host ssh stderr lands in the error-log argument.
Verified clean (54)
All 7 Proxmox hosts (root), pfv-proxmox-backup-server (root), sectestbed-proxmox-pve (root), all 8 k8s nodes, pfv-netinfra-01/02, tsys-awx/ca/librenms/siem/voip, devbox-cloudron, hfnoc-uisp, kali-rd, kali-tsys, pfv-rr-middleware-01/02, subopi3, subopi-dev-3, subopi-dev-4 (subodev+sudo), netbird, and the full sectestbed/preprod suite minus the appliance VMs listed above.