- Merge Infrastructure + Secure + Systems → SNS Networking (Business #1) - Merge Web + Software + Cloud → SNS Digital (planned) - SNS Support unchanged (planned) - Add infra/ folder with 16 FOSS-first buildable designs - Update all agent knowledge, division briefs, legal structure - Restructure businesses/ from 7 to 3 operating folders
3.8 KiB
3.8 KiB
Proxmox Base Cluster — SNS Networking
Entity: SNS Networking · Status: Buildable now
What it is
A single-node (expandable to cluster) Proxmox VE hypervisor that hosts all on-prem
VMs and LXC containers. This is the foundation — everything else in infra/ runs
on top of this or connects to it.
Stack
| Component | Software | FOSS | Notes |
|---|---|---|---|
| Hypervisor | Proxmox VE 8.x | Yes | Debian-based, KVM + LXC |
| Storage | ZFS (local) | Yes | Mirror or RAIDZ1 depending on disk count |
| Networking | Linux bridge + VLANs | Yes | vmbr0 = management, vmbr1 = services |
| Backup | Proxmox Backup Server (PBS) | Yes | Separate VM or separate box |
| Templates | Cloud-init images (Debian 12, Rocky 9, Ubuntu 24.04) | Yes | Pulled and prepped with virt-customize |
| Automation | Ansible + Proxmox API | Yes | community.general.proxmox* modules |
Topology
┌─────────────────────────────────────────────┐
│ Proxmox VE Host (bare metal) │
│ │
│ vmbr0 (mgmt, VLAN 1) vmbr1 (services, VLAN 10+) │
│ ├── LXC: dns (Pi-hole/AdGuard) │
│ ├── LXC: nginx-proxy (reverse proxy) │
│ ├── VM: gitea (code hosting) │
│ ├── VM: monitoring (Prometheus+Grafana) │
│ ├── VM: app-01 (general workloads) │
│ └── VM: pbs (Proxmox Backup Server) │
│ │
│ ZFS pool: rpool (OS) + datapool (VMs) │
└─────────────────────────────────────────────┘
│
├── WireGuard tunnel → Linode (bastion)
└── Tailscale mesh (management access)
Build Steps
- Install Proxmox VE on bare metal (Debian netinstall + Proxmox repo, or ISO).
- Configure ZFS — mirror for 2 disks, RAIDZ1 for 3+. Separate
rpool(OS) fromdatapool(VM storage). - Networking — create
vmbr0(management) andvmbr1(service VLAN). Tag VLANs at the switch if physical segregation exists. - Disable enterprise repo, enable no-subscription repo — remove nag popup.
- Cloud-init templates — download base images, convert to templates:
wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-generic-amd64.qcow2 qm create 9000 --memory 2048 --net0 virtio,bridge=vmbr1 --name debian12-template qm importdisk 9000 debian-12-generic-amd64.qcow2 datapool qm set 9000 --scsihw virtio-scsi-pci --scsi0 datapool:vm-9000-disk-0 qm set 9000 --ide2 datapool:cloudinit --boot c --bootdisk scsi0 qm template 9000 - PBS — install Proxmox Backup Server (separate VM or LXC). Point PVE's storage config at it. Schedule nightly backups.
- Ansible bootstrap — run base hardening playbook against all new VMs (SSH keys, UFW, fail2ban, unattended-upgrades).
Security Posture
- Management access: Tailscale or WireGuard only. Proxmox web UI not exposed to WAN.
- SSH: key-only, no password auth, port 22 behind Tailscale/WireGuard.
- Firewall: Proxmox host firewall enabled. Default deny inbound. Allow only Tailscale/WireGuard + VLAN inter-traffic as needed.
- Updates:
aptauto-security-updates on host. Manual kernel updates (reboot required). - Backups: PBS with encryption at rest. Retention: 7 daily, 4 weekly, 3 monthly.
Upgrade Path
- Multi-node cluster: Add a second Proxmox host, enable HA with Ceph or shared ZFS-over-iSCSI.
- Ceph storage: When local ZFS capacity or redundancy isn't enough.
- SDN: Proxmox SDN module for VXLAN overlays if VLAN count gets unmanageable.