Host inventory¶
Descriptive inventory of shared runtime hosts for the Operate line.
Software Deploy picks from host.* options; this page is the live/legacy fact sheet.
Policy: Software decisions D2 — default host.konstant; host.vps-legacy migration-only.
Summary¶
| Host option | Machine | Role | Status |
|---|---|---|---|
host.konstant |
konstant-server |
Default self-host for Lab / Portfolio-org | Active (eval dual-run) |
host.vps-legacy |
ai-sandbox (Hetzner) |
Former default public edge | Warm / migration only — no new apps |
host.vercel |
Vercel | Alternate for suitable standalone apps | Allowed (Software pattern) |
host.gcp |
— | Future stub | Not filled |
konstant-server (host.konstant)¶
| Field | Value |
|---|---|
| Hostname | konstant-server |
| LAN | 192.168.2.188 (workstation LAN; may be unreachable off-site) |
| Tailscale | 100.80.164.32 (konstant-ts / konstant-deploy SSH aliases) |
| Public eval edge | *-konstant.hectorsanchez.eu via Cloudflare Tunnel / Funnel |
| Shape | Hetzner CPX22 — 2 vCPU, 4 GB RAM, 80 GB disk (when provisioned as such; confirm live) |
| OS | Ubuntu Server (eval lab) |
| SSH users | sdhector (admin), deploy (deploy + passwordless sudo for Conductor paths) |
| SSH keys | Workstation ed25519; never commit private keys |
| Mesh | Tailscale online |
Platform services (typical)¶
nginx, cloudflared, tailscaled, fail2ban, ufw, systemd socket-activated app units, Platform Control (when enabled), MCP stacks as installed per runbooks.
Conductor on konstant¶
| Component | URL | On-disk |
|---|---|---|
| Docs | https://conductor-docs.hectorsanchez.eu |
/srv/apps/conductor-docs/current/ |
| MCP | https://conductor-konstant.hectorsanchez.eu |
/srv/apps/conductor/current/ |
See Deploying and Konstant operations.
ai-sandbox (host.vps-legacy)¶
Former production public edge. Do not deploy new apps here.
| Field | Value (verified ~2026-07-19; re-verify before change) |
|---|---|
| Hostname | ai-sandbox |
| Tailscale | 100.83.223.20 (peer name may be ai-sandbox-1) |
| Public IP | 46.225.27.162 |
| Provider | Hetzner Cloud (historically CAX11 Arm64 / related SKUs — confirm in console) |
| OS | Ubuntu 24.04 LTS |
| SSH | deploy preferred; root via dedicated Hetzner key on operator machines only |
| Identity file (operators) | ~/.ssh/id_ed25519_hetzner — retrieve via secret-gate / Bitwarden, never commit |
Security posture (snapshot)¶
| Control | Setting |
|---|---|
| Tailscale | Installed, online |
| UFW | Active — default deny in; allow 22/80/443; allow all on tailscale0 |
| fail2ban | Active (sshd) |
| SSH password | Disabled |
| cloudflared | Running (production tunnel) |
Workloads historically on this host¶
nginx, cloudflared, Docker (e.g. Vikunja), Platform Control, mcp-ssh-manager, memory-gateway / writing-publisher MCP stack, OpenClaw gateway (~:18789 localhost).
Full retire path: Cutover and retire · detail: VPS legacy.
Access conventions¶
Alias (typical ~/.ssh/config) |
Target |
|---|---|
konstant |
LAN IP as sdhector |
konstant-ts |
Tailscale IP as sdhector |
konstant-deploy |
Tailscale as deploy |
ai-sandbox |
Tailscale as deploy + Hetzner key |
ai-sandbox-root |
Tailscale as root + Hetzner key (break-glass) |
Secrets and key material: Operate tooling — secret-gate · Secrets standard.
Related¶
- Konstant operations
- VPS legacy (ai-sandbox)
- Operate tooling
- Source harvest provenance:
docs/evidence/estate/operate-infra-harvest-2026-07-30.yml