2.8 KiB
2.8 KiB
RULE — Acesso CT124 (big) → CT130 Spec Hub (BIG1)
Data: 2026-08-05
Para: Roger
Estado: ✅ testado (ssh CT130 → spec-hub)
Topologia (não misturar)
| CT/VM | Servidor Proxmox | IP LAN | Papel |
|---|---|---|---|
| CT124 | big (≠ BIG1) | 10.10.10.124 |
invest.myvexx.com |
| CT130 | BIG1 | 10.10.10.130 |
Spec Hub / Forgejo / Obsidian |
| big1 (host) | BIG1 | Tailscale 100.116.138.100:4422 |
jump host |
As LANs 10.10.10.0/24 de big e BIG1 não se roteiam entre si.
Acesso CT124 → CT130 = sempre via ProxyJump big1.
Chaves
| Ficheiro (na CT124) | Uso |
|---|---|
/root/.ssh/big_myvexx_id_rsa |
SSH ao host big1 (Tailscale). Fingerprint SHA256:M05N5Avg... |
/root/.ssh/ct124_to_ct130 |
SSH ao CT130 (pubkey no authorized_keys do 130) |
/root/.ssh/id_rsa |
NÃO usar para big1/CT130 (é outra chave Hetzner) |
No PC Windows: C:\Users\roger\.ssh\big_myvexx_id_rsa + config com ProxyJump / ProxyCommand.
SSH config canónico (CT124)
Ficheiro: /root/.ssh/config
Host big1
HostName 100.116.138.100
User root
Port 4422
IdentityFile /root/.ssh/big_myvexx_id_rsa
IdentitiesOnly yes
ServerAliveInterval 60
StrictHostKeyChecking accept-new
Host CT130 vm130 spec-hub
HostName 10.10.10.130
User root
IdentityFile /root/.ssh/ct124_to_ct130
IdentitiesOnly yes
ProxyJump big1
StrictHostKeyChecking accept-new
ServerAliveInterval 30
Comandos
# Da CT124 (ou máquina com o mesmo config + chaves)
ssh big1
ssh CT130
ssh vm130
ssh spec-hub
Teste rápido:
ssh CT130 'hostname; hostname -I'
# esperado: spec-hub / 10.10.10.130
Spec Hub — paths Invest
| Onde | Path |
|---|---|
| Repo | /opt/ligbox-spec-hub/repos/invest-myvexx/ |
| SPEC-051 | .../specs/051-invest-unified-dashboard-index-hub/SPEC-051-INVEST-UNIFIED-DASHBOARD-INDEX-HUB.md |
| Obsidian | /opt/ligbox-spec-hub/obsidian-vault/Invest-MyVexx/ |
| GitHub | https://github.com/itecnologys-tech/invest-myvexx |
Infra no BIG1 (nota)
- Rota
10.10.10.130→vmbr4000(serviçoroute-ct130.service) — persistente no big1. - Porta WAN 2530 ao CT130: OFF — não usar; sempre jump via big1.
- CT124 WAN SSH (referência):
51.171.219.218:2524(senha ambiente805353).
Copiar chaves para outra máquina (amanhã)
- Copiar
big_myvexx_id_rsa+ct124_to_ct130(+.pubopcional). - Colar o bloco SSH config acima (ajustar
IdentityFilese path diferente). - Tailscale ligado (para
100.116.138.100). - Testar
ssh big1depoisssh CT130.
Não sobrescrever id_rsa Hetzner/Proxmox com big_myvexx_id_rsa.