Skip to content

Host inventory

Descriptive inventory of shared runtime hosts for the Operate line. Software Deploy picks from host.* options; this page is the live/legacy fact sheet.

Policy: Software decisions D2 — default host.konstant; host.vps-legacy migration-only.


Summary

Host option Machine Role Status
host.konstant konstant-server Default self-host for Lab / Portfolio-org Active (eval dual-run)
host.vps-legacy ai-sandbox (Hetzner) Former default public edge Warm / migration only — no new apps
host.vercel Vercel Alternate for suitable standalone apps Allowed (Software pattern)
host.gcp Future stub Not filled

konstant-server (host.konstant)

Field Value
Hostname konstant-server
LAN 192.168.2.188 (workstation LAN; may be unreachable off-site)
Tailscale 100.80.164.32 (konstant-ts / konstant-deploy SSH aliases)
Public eval edge *-konstant.hectorsanchez.eu via Cloudflare Tunnel / Funnel
Shape Hetzner CPX22 — 2 vCPU, 4 GB RAM, 80 GB disk (when provisioned as such; confirm live)
OS Ubuntu Server (eval lab)
SSH users sdhector (admin), deploy (deploy + passwordless sudo for Conductor paths)
SSH keys Workstation ed25519; never commit private keys
Mesh Tailscale online

Platform services (typical)

nginx, cloudflared, tailscaled, fail2ban, ufw, systemd socket-activated app units, Platform Control (when enabled), MCP stacks as installed per runbooks.

Conductor on konstant

Component URL On-disk
Docs https://conductor-docs.hectorsanchez.eu /srv/apps/conductor-docs/current/
MCP https://conductor-konstant.hectorsanchez.eu /srv/apps/conductor/current/

See Deploying and Konstant operations.


ai-sandbox (host.vps-legacy)

Former production public edge. Do not deploy new apps here.

Field Value (verified ~2026-07-19; re-verify before change)
Hostname ai-sandbox
Tailscale 100.83.223.20 (peer name may be ai-sandbox-1)
Public IP 46.225.27.162
Provider Hetzner Cloud (historically CAX11 Arm64 / related SKUs — confirm in console)
OS Ubuntu 24.04 LTS
SSH deploy preferred; root via dedicated Hetzner key on operator machines only
Identity file (operators) ~/.ssh/id_ed25519_hetzner — retrieve via secret-gate / Bitwarden, never commit

Security posture (snapshot)

Control Setting
Tailscale Installed, online
UFW Active — default deny in; allow 22/80/443; allow all on tailscale0
fail2ban Active (sshd)
SSH password Disabled
cloudflared Running (production tunnel)

Workloads historically on this host

nginx, cloudflared, Docker (e.g. Vikunja), Platform Control, mcp-ssh-manager, memory-gateway / writing-publisher MCP stack, OpenClaw gateway (~:18789 localhost).

Full retire path: Cutover and retire · detail: VPS legacy.


Access conventions

Alias (typical ~/.ssh/config) Target
konstant LAN IP as sdhector
konstant-ts Tailscale IP as sdhector
konstant-deploy Tailscale as deploy
ai-sandbox Tailscale as deploy + Hetzner key
ai-sandbox-root Tailscale as root + Hetzner key (break-glass)

Secrets and key material: Operate tooling — secret-gate · Secrets standard.