VPS legacy — ai-sandbox (host.vps-legacy)¶
Inventory and retire guidance for the Hetzner VPS historically named ai-sandbox.
Do not choose this host for new work (Software D2).
Harvested from hector-sanchez-eu/hetzner-vps, hetzner-vps-management, konstant-server inventory notes, and incubator infrastructure-management (non-secret facts only).
Status¶
| Aspect | State |
|---|---|
| Software inventory option | host.vps-legacy — migration / history only |
| Production public edge | Still warm until cutover sign-off (cutover) |
| New app deploys | Forbidden |
| GitHub source repos | hetzner-vps / hetzner-vps-management archived 2026-07-30 |
Identity¶
| Field | Value |
|---|---|
| Hostname | ai-sandbox |
| Public IP | 46.225.27.162 |
| Tailscale | 100.83.223.20 |
| Domain apex (historical) | hectorsanchez.eu edge via this host |
| Labels (historical) | env=development, purpose=ai-sandbox-and-prototyping |
Operator access¶
- Prefer
ssh ai-sandboxasdeploywith key from Bitwarden (id_ed25519_hetzneror equivalent secret name — resolve via secret-gate). - Break-glass root only when required; do not store plaintext keys in Conductor.
- Before any production mutation, verify live state over SSH — markdown in archived repos may be stale.
What ran here (descriptive)¶
Historically: Moltbot / OpenClaw-style agents, Telegram bots, Bitwarden-backed secret injection on the VPS, nginx + cloudflared, Vikunja + MCP services, Platform Control, mcp-ssh-manager (ssh-mcp.hectorsanchez.eu), writing/memory MCP stack.
Repos that documented this era (recovery only after archive):
| Repo | Notes |
|---|---|
hector-sanchez-eu/hetzner-vps |
Moltbot deploy scripts, Bitwarden integration docs, firewall notes — archived 2026-07-30 |
hector-sanchez-eu/hetzner-vps-management |
Stub cleaned workspace (AGENTS.md only) — archived 2026-07-30 |
Incubator infrastructure/vps-management-ui |
Admin UI targeting this VPS (vps.hectorsanchez.eu, Tailscale-only) |
Konstant-Ventures/vps-deployment-toolkit |
Archived 2026-07-30 — superseded for new work by konstant patterns |
Secrets¶
All secret values stay in Bitwarden Secrets Manager (EU), project workspaces.
Unlock and export with secret-gate only. Names commonly associated with this host (non-exhaustive):
| Name | Purpose |
|---|---|
VPS_HOST |
Deploy host address (prefer Tailscale IP) |
VPS_SSH_KEY |
Deploy SSH private key |
HETZNER_DNS_TOKEN |
Hetzner Cloud DNS API |
CLOUDFLARE_API_TOKEN / tunnel connector tokens |
Edge — do not confuse API vs connector |
| App-specific bot/API keys | Per-app; reuse generic names when possible |
Never commit keys from quarantined incubator paths (e.g. DigitalOcean id_ed25519 copies).
Migration expectation¶
- App healthy on konstant (
host.konstant) or Vercel (host.vercel) - Smoke on eval hostname
- Flip DNS/tunnel per cutover
- Keep VPS powered ≥ 7 days for rollback
- Decommission only when checklist complete
Related¶
- Hosts · Cutover · Heritage infrastructure · Tooling
- Provenance:
docs/evidence/estate/operate-infra-harvest-2026-07-30.yml - Archive instructions:
archive/operate-harvest/README.md·scripts/archive-legacy-infra-repos.sh