104 lines
2.8 KiB
Markdown
104 lines
2.8 KiB
Markdown
# RULE — Acesso CT124 (big) → CT130 Spec Hub (BIG1)
|
|
|
|
**Data:** 2026-08-05
|
|
**Para:** Roger
|
|
**Estado:** ✅ testado (`ssh CT130` → `spec-hub`)
|
|
|
|
---
|
|
|
|
## Topologia (não misturar)
|
|
|
|
| CT/VM | Servidor Proxmox | IP LAN | Papel |
|
|
|-------|------------------|--------|-------|
|
|
| **CT124** | **big** (≠ BIG1) | `10.10.10.124` | invest.myvexx.com |
|
|
| **CT130** | **BIG1** | `10.10.10.130` | Spec Hub / Forgejo / Obsidian |
|
|
| **big1** (host) | BIG1 | Tailscale `100.116.138.100:4422` | jump host |
|
|
|
|
As LANs `10.10.10.0/24` de **big** e **BIG1** **não** se roteiam entre si.
|
|
Acesso CT124 → CT130 = **sempre via ProxyJump big1**.
|
|
|
|
---
|
|
|
|
## Chaves
|
|
|
|
| Ficheiro (na CT124) | Uso |
|
|
|---------------------|-----|
|
|
| `/root/.ssh/big_myvexx_id_rsa` | SSH ao host **big1** (Tailscale). Fingerprint `SHA256:M05N5Avg...` |
|
|
| `/root/.ssh/ct124_to_ct130` | SSH ao **CT130** (pubkey no `authorized_keys` do 130) |
|
|
| `/root/.ssh/id_rsa` | **NÃO** usar para big1/CT130 (é outra chave Hetzner) |
|
|
|
|
No PC Windows: `C:\Users\roger\.ssh\big_myvexx_id_rsa` + config com `ProxyJump` / `ProxyCommand`.
|
|
|
|
---
|
|
|
|
## SSH config canónico (CT124)
|
|
|
|
Ficheiro: `/root/.ssh/config`
|
|
|
|
```
|
|
Host big1
|
|
HostName 100.116.138.100
|
|
User root
|
|
Port 4422
|
|
IdentityFile /root/.ssh/big_myvexx_id_rsa
|
|
IdentitiesOnly yes
|
|
ServerAliveInterval 60
|
|
StrictHostKeyChecking accept-new
|
|
|
|
Host CT130 vm130 spec-hub
|
|
HostName 10.10.10.130
|
|
User root
|
|
IdentityFile /root/.ssh/ct124_to_ct130
|
|
IdentitiesOnly yes
|
|
ProxyJump big1
|
|
StrictHostKeyChecking accept-new
|
|
ServerAliveInterval 30
|
|
```
|
|
|
|
---
|
|
|
|
## Comandos
|
|
|
|
```bash
|
|
# Da CT124 (ou máquina com o mesmo config + chaves)
|
|
ssh big1
|
|
ssh CT130
|
|
ssh vm130
|
|
ssh spec-hub
|
|
```
|
|
|
|
Teste rápido:
|
|
```bash
|
|
ssh CT130 'hostname; hostname -I'
|
|
# esperado: spec-hub / 10.10.10.130
|
|
```
|
|
|
|
---
|
|
|
|
## Spec Hub — paths Invest
|
|
|
|
| Onde | Path |
|
|
|------|------|
|
|
| Repo | `/opt/ligbox-spec-hub/repos/invest-myvexx/` |
|
|
| SPEC-051 | `.../specs/051-invest-unified-dashboard-index-hub/SPEC-051-INVEST-UNIFIED-DASHBOARD-INDEX-HUB.md` |
|
|
| Obsidian | `/opt/ligbox-spec-hub/obsidian-vault/Invest-MyVexx/` |
|
|
| GitHub | https://github.com/itecnologys-tech/invest-myvexx |
|
|
|
|
---
|
|
|
|
## Infra no BIG1 (nota)
|
|
|
|
- Rota `10.10.10.130` → `vmbr4000` (serviço `route-ct130.service`) — persistente no **big1**.
|
|
- Porta WAN **2530** ao CT130: **OFF** — não usar; sempre jump via big1.
|
|
- CT124 WAN SSH (referência): `51.171.219.218:2524` (senha ambiente `805353`).
|
|
|
|
---
|
|
|
|
## Copiar chaves para outra máquina (amanhã)
|
|
|
|
1. Copiar `big_myvexx_id_rsa` + `ct124_to_ct130` (+ `.pub` opcional).
|
|
2. Colar o bloco SSH config acima (ajustar `IdentityFile` se path diferente).
|
|
3. Tailscale ligado (para `100.116.138.100`).
|
|
4. Testar `ssh big1` depois `ssh CT130`.
|
|
|
|
**Não** sobrescrever `id_rsa` Hetzner/Proxmox com `big_myvexx_id_rsa`.
|