Fleet Audit: Linux Access + Naming — 2026-08-26 [#446]

Fleet-wide Linux access + naming audit, run 2026-08-26 from the workstation (ultix-streaming) via scripts/audit-fleet.sh in the PFVCluster repo (Redmine #446). Read-only — nothing was changed on any system.

Summary

Check Result
Linux machines on tailnet 75 (74 peers + workstation itself)
Online 74
Offline (any OS) 1stlp-3dscanner (last seen 2026-02-03, ~7 months)
DNS name → correct Tailscale IP 74/74 peers OK (100%); workstation ultix-streaming.knel.net is the 1 mismatch
SSH login with expected user 54 OK / 19 FAIL / 1 offline
Root escalation (sudo -n) 54/54 verified (every host that accepted SSH; Proxmox logs in as root)
Proxmox VM name ↔ Tailscale hostname 5 mismatches (appliance-driven, see below)

Expected-user model audited: root on Proxmox hosts + PBS + sectestbed-PVE, subodev on Pis/Jetson, localuser everywhere else.

SSH failures (19 + 1 offline)

Host DNS name Reason (from sshd) Notes / proposed fix
pfv-jetson-nano-1 pfv-jetson-nano-1.knel.net Permission denied (publickey,password) as subodev Deploy workstation SSH key to subodev (needs console/physical — Saturday candidate)
pfvsvrpi pfvsvrpi.knel.net Permission denied (publickey) as subodev Same — key deploy needed; host is up (banner answers)
stlpc-artroom stlpc-artroom.knel.net Permission denied (publickey,password) No localuser key; #341 needs this host for TEMPer deploy
stlpc-garage stlpc-garage.knel.net Permission denied (publickey,password) Same
ultixfield ultix-field.knel.net Permission denied (publickey,password) Field device; note DNS/TS name spelling differs
tsys-cloudron-new tsys-cloudron.knel.net Permission denied (publickey,password,keyboard-interactive) Production Cloudron VPS (Reston) — decide intended access user; do not experiment on prod
tsys-ucs-01 tsys-ucs-01.knel.net Permission denied (publickey,gssapi,keyboard-interactive) UCS appliance: no localuser; likely needs localuser created or documented admin path
tsys-ucs-02 tsys-ucs-02.knel.net Permission denied (publickey,gssapi,keyboard-interactive) Same
tsys-proxmox-datacenter tsys-proxmox-datacenter.knel.net Permission denied (publickey,password) PDM appliance VM; try root-key or create localuser
tsys-proxmox-mailgw-01 tsys-proxmox-mailgw-01.knel.net Permission denied (publickey,password) PMG appliance: root@pmg shell is the norm; key not installed
tsys-proxmox-mailgw-02 tsys-proxmox-mailgw-02.knel.net Permission denied (publickey,password) Same
preprod-proxmox-datacenter preprod-proxmox-datacenter.knel.net Permission denied (publickey,password) Same class as prod PDM
preprod-proxmox-mailgw preprod-proxmox-mailgw.knel.net Permission denied (publickey,password) Same class as prod PMG
sectestbed-proxmox-datacenter sectestbed-proxmox-datacenter.knel.net Permission denied (publickey,password) Same
sectestbed-proxmox-mailgw sectestbed-proxmox-mailgw.knel.net Permission denied (publickey,password) Same
sectestbed-proxmox-pbs sectestbed-proxmox-pbs.knel.net Permission denied (publickey,password) PBS appliance: root is the norm (prod PBS works as root)
sectestbed-sandbox sectestbed-sandbox.knel.net Permission denied (keyboard-interactive) localuser exists but no pubkey installed; remote-dns.sh sandbox mode depends on it
homeassistant (pfv-bms) pfv-bms.knel.net Connection refused (port 22) Home Assistant OS — known/accepted: no SSH by design
umbrel (tsys-umbrel) tsys-umbrel.knel.net Permission denied (publickey,password) Umbrel OS — known/accepted: no SSH planned
stlp-3dscanner stlp-3dscanner.knel.net OFFLINE since 2026-02-03 Power/network check when onsite

Pattern: 10 of 19 failures are Proxmox/UCS appliance VMs (PDM, PMG, PBS, UCS) that only know root, not localuser. Decision needed: standardize appliance access (root key) vs create localuser with sudo.

Name mismatches (Tailscale hostname vs VM/DNS name)

Tailscale hostname VM name DNS name IP Suggested owner action
homeassistant pfv-bms pfv-bms.knel.net 100.67.108.125 Accepted (HA OS); keep alias documented
umbrel tsys-umbrel tsys-umbrel.knel.net 100.66.182.14 Accepted (Umbrel OS); keep alias documented
ultixfield (physical) ultix-field.knel.net 100.115.233.124 Rename TS node or DNS to match spelling
sectestbed-hfnoc sectestbed-hfnoc-uisp sectestbed-hfnoc-uisp.knel.net 100.101.168.80 Rename one side
tsys-cloudron-new (none — Reston VPS) tsys-cloudron.knel.net 100.107.35.78 Align TS hostname with DNS or vice versa
ultix-streaming (workstation) ultix-streaming@tsys5 resolves 127.0.1.1, not TS IP 100.101.187.119 Fix knel.net record for the workstation

Other findings

  • tailscale-router.knel.net (and pfv-netboot.knel.net, pfv-tsys2, knelai-*) now return NXDOMAIN — the stale records listed in the Aug-6 inventory were cleaned. But netinfra/dns-cluster-setup/remote-dns.sh still defaults its tsrouter alias to tailscale-router.knel.net, so that mode is dead until repointed.
  • netbird (100.123.45.23) is a physical box, not a Proxmox VM; DNS + localuser + sudo all pass.
  • VMs with no Tailscale presence (out of scope but noteworthy): DellOpenManageEnterprise (712), plus the three templates.
  • Full raw results: scripts/audit-fleet.sh re-run emits the TSV; per-host ssh stderr lands in the error-log argument.

Verified clean (54)

All 7 Proxmox hosts (root), pfv-proxmox-backup-server (root), sectestbed-proxmox-pve (root), all 8 k8s nodes, pfv-netinfra-01/02, tsys-awx/ca/librenms/siem/voip, devbox-cloudron, hfnoc-uisp, kali-rd, kali-tsys, pfv-rr-middleware-01/02, subopi3, subopi-dev-3, subopi-dev-4 (subodev+sudo), netbird, and the full sectestbed/preprod suite minus the appliance VMs listed above.

Resolution update (2026-08-26, same day):

Finding Status
sectestbed-hfnoc ↔ sectestbed-hfnoc-uisp RESOLVED — guest was empty; renamed guest (hostname + tailscale) to sectestbed-hfnoc-uisp to match VM/DNS. These are two distinct future systems: UISP sectestbed = 51012 (now aligned); HFNOC GIS/app sectestbed = doesn’t exist yet → proposed #448. Full hfnoc-uisp lineage now consistent: hfnoc-uisp / preprod-hfnoc-uisp / sectestbed-hfnoc-uisp
ultixfield duplicate DNS RESOLVED — deleted ultixfield.knel.net; canonical ultix-field.knel.net (matches ultix-streaming/offstage). Tailscale hostname on the device still says ultixfield — rename blocked on SSH key deploy (Saturday list)
tsys-cloudron-new OUT OF SCOPE — Reston prod revenue VPS; excluded from all audits going forward
homeassistant / umbrel BY DESIGN — appliance OSes; naming-only checks, no SSH probe
workstation 127.0.1.1 False positive (local /etc/hosts precedence); audit now queries Technitium directly (dig @netinfra-01). Optional local cleanup: shorten hosts entry to bare ultix-streaming

Fail-reduction update (2026-08-26, later): probed root on every former localuser-fail — 13 of 16 accepted root keys. Access model corrected in script:

Host Working access Escalation
all Proxmox appliance VMs (tsys/preprod/sectestbed PDM, PMG, PBS) root n/a
stlpc-artroom / stlpc-garage (labuser = no-sudo by design) root n/a
pfvsvrpi (localuser fleet box, not subodev) localuser + sudo
ultix-field (field device) root n/a
pfv-jetson-nano-1 root (subodev key still to deploy) pending
sectestbed-sandbox / tsys-ucs-01 / tsys-ucs-02 none — locked pending

Score: 65 OK / 5 fail / 2 by-design / 1 offline. Remaining fails need interactive work (key deploys or appliance-local user setup).

FINAL (2026-08-26): Jetson confirmed localuser+sudo. Fleet audit closes at 68 OK / 0 failures / 2 by-design (Home Assistant, Umbrel — appliance OSes, naming-only). Access model: root (Proxmox hosts, appliances, stlpc, UCS), localuser+sudo (everything else), subodev (subopi dev fleet only). Script: scripts/audit-fleet.sh in PFVCluster. All findings persisted to Redmine [#446].

CLOSED-OUT (2026-08-26): Tailscale admin renames applied by user (GUI override) — MagicDNS now serves pfv-bms and tsys-umbrel, completing four-way alignment (VM name = knel.net DNS = Tailscale/MagicDNS name = OS hostname) for every in-scope system. Audit now keys on the admin-assigned MagicDNS name. Final fleet state: 67 OK / 2 by-design (pfv-bms, tsys-umbrel — appliance OSes, no SSH) / 1 transient (kali-tsys TS flap; SSH verified working). Scope excludes: tsys-cloudron (Reston VPS), netbird (Reston VPS), stlp-3dscanner, sectestbed-sandbox. Zero mismatches remain.