Docs/Plans: Difference between revisions

Jump to navigation Jump to search
Removed completed plans and added new plans for server/infra upgrades
(add opnsense migration stuff)
Tags: Mobile edit Mobile web edit
(Removed completed plans and added new plans for server/infra upgrades)
 
#Formally acquire and install new servers (R640s)
# 10 Gb/s backbone for internal network
## Repair shipping damage on the 8-bay machines
## Install all Dell Daughterboards
### Put the bent metal back into shape so they can fit cleanly in the rack
## Program FiberStore SFP Sleds
### One of them has board damage and can only take a single X16 card, but it still works and shouldn't be an issue for our use case
# Rearrange servers
#### Maybe make sure the damaged traces don't short out?
## Mirrors/Leskinen on bottom of our space
## Buy CPUs for the 10-bay machine
## Maho right above
### Xeon Gold 6240s are cheap used
## Proxmox cluster
# Firewalls
## Shell
## Migrate firewall duty to Okabe and Kurisu
## Lasagna/Ravioli on very top (OPNSense servers)
## Decommission old firewall servers (lasagna and ravioli)
# Redo Proxmox
# Finish unlocking [[Locked HGST drives]]
## Change storage from local replication to either Ceph, or iSCSI/NFS via Leskinen
## Replace all laptop drives in the cluster
## Proxmox cluster
## Remove/decommission one of the R630s to make room
## Redistribute RAM and install new R640s, add them to the cluster
## 3D print needed 2.5" drive trays
## Ceph? (maybe)
### Change VM storage from NFS via Leskinen to Ceph on cluster
### Backup to Leskinen instead of cluster
## Figure out firewalling local network from VMs for VPS idea (able to give people an ""unmanaged VM"", it should not be able to access any other VMs on the local network)
### New subnet? (10.10.2.0/24)
### Reverse-NAT via OPNSense (and mandatory DHCP) so we don't have to trust people to statically assign themselves the right public IP?
# Mirrors
# Fix Mirrors LAN/WAN IP (currently only on WAN, via DHCP)
## Upgrade CPUs to the Xeon 2680 V4s from the decommissioned R630
# Pterodactyl
## Try to do it with as little downtime as possible..
# Pterodactyl (?)
# Faceplates for servers
## Stickerbomb idea!
## Can 3D print some of the faceplates instead of buying them
# Consider hosting authoritative DNS resolver for linuxusers.group on our infra
## Automated domains via dhcp hostnames in opnsense
# Finish OPNsense transition
##DNS for internal services
## Move Wireguard off of pfSense install
##1:1 NAT for public services (not mirrors)
### People will need to edit their configs to point at the new gateway
# #Consider hosting authoritative DNS resolver for linuxusers.group on our infra
## Migrate config from pfSense
### Automated domains via dhcp hostnames in opnsense (?)
### DHCP scary
##Network booting for servers/VMs (?)
### We should make any firewall/NAT/etc adjustments during this process
# LDAP (on Leskinen?cluster)
## Have OPNsense take over as main gateway
## Integrate logins for Shell, LUG VMs, and other servers
## Blow up pfSense and replace it with OPNsense
## Already set up:
## Set up gateway redundancy
### OPNSense, Proxmox, and iDRACs
### How will VPN work with this?
# LDAP (on Leskinen?)
## Tie into iDrac/Switches
## VM/Proxmox/OPNSense/Debian servers (Leskinen, Maho, Mirrors)
## Everything but Shell (and maybe Wiki) so alums can have access
# Document, document, document.
## Netbox?

Navigation menu