[P2606] WebServer NGINX: plan actualizado, ficha nodo, HTTPS operativo
- P2606: Plan v1.1 EN EJECUCIÓN. Fases 1-3 completadas. - Ficha nodo srvv-nginx-rm.md. P2606 en adn/07_proyectos.md. - Incluye cambios acumulados de sesiones anteriores.
This commit is contained in:
@@ -1,12 +1,13 @@
|
||||
# Nodo: dasu-pc-0
|
||||
# Nodo: dasu-pc
|
||||
|
||||
## Información General
|
||||
- **Hostname**: `dasu-pc-0` (Prev: `pc-dasu0`)
|
||||
- **Hostname**: `dasu-pc` (Prev: `dasu-pc-0`, `pc-dasu0`)
|
||||
- **Patrimonio**: `32120`
|
||||
- **Ubicación**: Oficina DASUTEN (Externa a Facultad)
|
||||
- **Tipo**: PC Física
|
||||
- **Rol**: Estación de Trabajo Remota (Usuarios: Andrea/Romina)
|
||||
- **Sistema Operativo**: Windows 10
|
||||
- **Dominio**: `dasuten.utnlr` (Unido 18/03/2026 - P2601.07.01)
|
||||
- **Conectividad**: Tailscale (`100.100.145.51`) - ✅ ONLINE (Unattended Mode)
|
||||
- **SSH**: `UTNLR@100.100.145.51:7022` (Plan A, Passphrase RSA, Bóveda: `rsa`)
|
||||
- **Acceso Respaldo (Plan B)**: W-ZOMBI v2.0 C2 (Vía Powershell: `iwr 100.111.195.4:8000/zombi.ps1 -useb | iex`)
|
||||
@@ -14,7 +15,7 @@
|
||||
## Credenciales de Gestión (Tailscale Admin)
|
||||
- **Cuenta Maestra**: `pcdasu0@frlr.utn.edu.ar`
|
||||
- **Pass (Ref)**: `UTN$larioja00`
|
||||
- **Propósito**: Esta cuenta gestiona la red Tailscale que une a `dasu-pc-0` con `pcv-dasu1`.
|
||||
- **Propósito**: Esta cuenta gestiona la red Tailscale que une a `dasu-pc` con `dasu-pcv`.
|
||||
|
||||
## Servicios
|
||||
- **RustDesk**: ID `398 699 016` (Acceso Remoto Principal por GUI). Password: `UTNlarioja00`
|
||||
@@ -1,9 +1,8 @@
|
||||
# Nodo: dasu-pcv-0
|
||||
# Nodo: dasu-pcv
|
||||
|
||||
## Identidad
|
||||
- **Hostname**: `dasu-pcv-0`
|
||||
- **Nombre anterior**: `pcv-dasu0` (renombrado 16/03/2026)
|
||||
- **Rol**: VM de Pruebas — Emulación de cliente `pc-dasu0`
|
||||
- **Hostname**: `dasu-pcv` (Prev: `dasu-pcv-0`, `pcv-dasu0`, renombrado 16/03/2026)
|
||||
- **Rol**: VM de Pruebas — Emulación de cliente `dasu-pc`
|
||||
- **Estado**: ✅ Operativo (Unida al dominio `dasuten.utnlr`)
|
||||
- **Padre/Host**: `srv-dasu`
|
||||
- **VMID**: `102`
|
||||
@@ -21,17 +20,23 @@
|
||||
## Sistema Operativo
|
||||
- **OS**: Windows 10 Enterprise LTSC 2021 (es-ES, 64-bit)
|
||||
- **Evaluación**: 90 días
|
||||
- **Propósito**: Pruebas de unión a dominio y validación del sistema DASUTeN antes de configurar el nodo físico `pc-dasu0`.
|
||||
- **Propósito**: Pruebas de unión a dominio y validación del sistema DASUTeN antes de configurar el nodo físico `dasu-pc`.
|
||||
|
||||
## Red y Conectividad
|
||||
- **Subred**: `10.0.100.0/24`
|
||||
- **IP**: `10.0.100.12/24` (Estática)
|
||||
- **Gateway**: `10.0.100.1`
|
||||
- **DNS Primario**: `10.0.100.10` (dasu-srvv-dc)
|
||||
- **DNS Secundario**: `8.8.8.8`
|
||||
|
||||
## Relación con pc-dasu0
|
||||
Esta VM replica la configuración prevista para la PC física [`pc-dasu0`](pc-dasu0.md) (Ryzen 5, Win 10) que operará en la oficina DASUTeN. Las configuraciones validadas aquí (dominio, sistema, políticas de grupo) se replicarán al nodo físico final.
|
||||
### Configuración Actual (2026-03-25)
|
||||
- **Subred**: `10.0.100.0/24`
|
||||
- **IP Local**: `10.0.100.12/24`
|
||||
- **Gateway**: `10.0.100.1` (srv-dasu vmbr0)
|
||||
- **DNS**: `10.0.100.10` (dasu-srvv-dc), `8.8.8.8` (backup)
|
||||
|
||||
### Tailscale
|
||||
- **IP**: `100.118.129.44`
|
||||
- **Estado**: ⚠️ Offline (última vista hace 7d)
|
||||
- **Cuenta**: `pcdasu0@frlr.utn.edu.ar`
|
||||
|
||||
## Relación con dasu-pc
|
||||
Esta VM replica la configuración prevista para la PC física [`dasu-pc`](dasu-pc.md) (Ryzen 5, Win 10) que operará en la oficina DASUTeN. Las configuraciones validadas aquí (dominio, sistema, políticas de grupo) se replicarán al nodo físico final.
|
||||
|
||||
## Dominio
|
||||
- **Bosque**: `dasuten.utnlr`
|
||||
@@ -0,0 +1,51 @@
|
||||
# Nodo: dasu-sql2
|
||||
|
||||
## Identidad
|
||||
- **Hostname**: `dasu-sql2`
|
||||
- **Rol**: SQL Server 2019 (DASUTEN) — Modo Workgroup
|
||||
- **OS**: Windows Server 2022 Core (Evaluation)
|
||||
- **Estado**: 🚧 En configuración
|
||||
- **Última Actualización**: 2026-03-27 (Evento 1318)
|
||||
- **Plan**: [P2601.09_DASUTEN-sin-DC.md](../docs/proy/P2601_Dasuten/P2601.09_DASUTEN-sin-DC.md)
|
||||
|
||||
## Virtualización
|
||||
- **Hipervisor**: [srv-dasu](srv-dasu.md)
|
||||
- **VMID**: 103
|
||||
- **Tipo**: QEMU/KVM
|
||||
- **BIOS**: SeaBIOS
|
||||
- **Machine**: pc-i440fx-10.1
|
||||
- **CPU**: 2 vCPU (host passthrough)
|
||||
- **RAM**: 4 GB
|
||||
- **Disco**: 60 GB SATA (local-lvm, thin provisioned, discard=on)
|
||||
- **Red**: VirtIO (bridge vmbr0)
|
||||
|
||||
## Red
|
||||
- **Configuración**: DHCP del ISP
|
||||
- **IP**: `192.168.1.19/24`
|
||||
- **Gateway**: 192.168.1.1 (router ISP)
|
||||
|
||||
### Tailscale
|
||||
- **IP**: `100.126.182.123`
|
||||
- **Estado**: ✅ ONLINE
|
||||
- **Cuenta**: `pcdasu0@frlr.utn.edu.ar`
|
||||
|
||||
### Acceso Remoto
|
||||
- **SSH**: `Administrator@100.126.182.123:7022` (Password, Bóveda: `dasu-sql2:Administrator`)
|
||||
- **OpenSSH Server**: ✅ Operativo (Puerto 7022)
|
||||
|
||||
## Credenciales
|
||||
- **Usuario**: Administrator
|
||||
- **Bóveda**: `dasu-sql2:Administrator`
|
||||
- **Auth**: password
|
||||
|
||||
## Servicios Planificados
|
||||
- **SQL Server 2019**: Enterprise (Evaluation) — Autenticación Mixta (SQL + Windows)
|
||||
- **OpenSSH Server**: Puerto 7022
|
||||
|
||||
## Backups
|
||||
- **2026-03-27 19:07**: vzdump modo stop + zstd (post-install WS2022 Core + VirtIO)
|
||||
|
||||
## Bitácora de Referencia
|
||||
- **Evento 1316**: Creación VM y instalación OS
|
||||
- **Evento 1317**: Backup post-instalación
|
||||
- **Evento 1318**: Configuración hostname, SSH, Tailscale
|
||||
+14
-7
@@ -18,15 +18,22 @@
|
||||
- **Red VirtIO**: `vmbr0` (NAT mode)
|
||||
|
||||
## Red y Conectividad
|
||||
|
||||
### Configuración Actual (2026-03-25)
|
||||
- **Subred Aislada**: `10.0.100.0/24`
|
||||
- **IP**: `10.0.100.10/24` (Estática oculta tras NAT de Proxmox)
|
||||
- **Gateway**: `10.0.100.1` (IP de ruteo del host Proxmox)
|
||||
- **Servidores DNS**: `10.0.100.10` (local), `8.8.8.8` (backup)
|
||||
- **Acceso Remoto**:
|
||||
- RDP Habilitado (TCP 3389)
|
||||
- **IP Local**: `10.0.100.10/24`
|
||||
- **Gateway**: `10.0.100.1` (srv-dasu vmbr0)
|
||||
- **DNS**: `10.0.100.10` (loopback), `8.8.8.8` (backup)
|
||||
|
||||
### Tailscale
|
||||
- **IP**: `100.85.117.101`
|
||||
- **Estado**: ✅ ONLINE
|
||||
- **Cuenta**: `pcdasu0@frlr.utn.edu.ar`
|
||||
|
||||
### Acceso Remoto
|
||||
- **SSH**: `admindasu@100.85.117.101:7022` (Passphrase RSA, Bóveda: `rsa`)
|
||||
- Habilitado OpenSSH Server (Puerto 7022). ✅ Operativo.
|
||||
- Tailscale: Activo
|
||||
- **RDP**: Habilitado (TCP 3389)
|
||||
- **OpenSSH Server**: ✅ Operativo (Puerto 7022)
|
||||
|
||||
## Servicios y Roles
|
||||
1. **Active Directory Domain Services (AD DS)**
|
||||
|
||||
+16
-10
@@ -14,17 +14,23 @@
|
||||
- **Red VirtIO**: `vmbr0` (NAT mode)
|
||||
|
||||
## Red y Conectividad
|
||||
|
||||
### Configuración Actual (2026-03-25)
|
||||
- **Subred Aislada**: `10.0.100.0/24`
|
||||
- **IP**: `10.0.100.11/24` (Estática oculta tras NAT de srv-dasu)
|
||||
- **Gateway**: `10.0.100.1` (IP de ruteo del host Proxmox)
|
||||
- **Servidores DNS**: `10.0.100.10` (dasu-srvv-dc) / `8.8.8.8`
|
||||
- **Acceso Remoto**:
|
||||
- **SSH**: `DASUTEN\admindasu@10.0.100.11:7022` (Bóveda: `admindasu`)
|
||||
- **SSH (Tailscale)**: `100.107.24.124:7022`
|
||||
- **Tailscale**: `100.107.24.124` (Direct Access)
|
||||
- ✅ **OpenSSH Server** (Puerto 7022) - Configurado y Operativo
|
||||
- **SQL Browser**: UDP 1434 (Visible en LAN interna)
|
||||
- **SQL Instance**: TCP 1433 (Visible en LAN interna)
|
||||
- **IP Local**: `10.0.100.11/24`
|
||||
- **Gateway**: `10.0.100.1` (srv-dasu vmbr0)
|
||||
- **DNS**: `10.0.100.10` (dasu-srvv-dc), `8.8.8.8` (backup)
|
||||
|
||||
### Tailscale
|
||||
- **IP**: `100.107.24.124`
|
||||
- **Estado**: ✅ ONLINE
|
||||
|
||||
### Acceso Remoto
|
||||
- **SSH Local**: `DASUTEN\admindasu@10.0.100.11:7022`
|
||||
- **SSH Tailscale**: `DASUTEN\admindasu@100.107.24.124:7022`
|
||||
- **OpenSSH Server**: ✅ Operativo (Puerto 7022)
|
||||
- **SQL Browser**: UDP 1434 (LAN interna)
|
||||
- **SQL Instance**: TCP 1433 (LAN interna)
|
||||
|
||||
## Servicios y Roles
|
||||
1. **Microsoft SQL Server 2019 Standard (Core)**
|
||||
|
||||
+79
-10
@@ -4,7 +4,8 @@
|
||||
- **Hostname**: `srv-dasu.utnlarioja`
|
||||
- **Rol Inicial**: Hypervisor Proxmox VE (Standalone - DASUTEN)
|
||||
- **OS**: Debian / Proxmox VE
|
||||
- **Estado**: ⏳ Instalación Base
|
||||
- **Estado**: ✅ Operativo (Red Configurada - Capa 2 + Tailscale)
|
||||
- **Última Actualización**: 2026-03-25 (Evento 1275)
|
||||
|
||||
## Hardware (Físico)
|
||||
- **Placa Madre**: ASUS PRIME A320M-K (BIOS Ver. 0217 UEFI)
|
||||
@@ -14,12 +15,55 @@
|
||||
- **CPU**: AMD A10-9700 Radeon R7 (4 Cores / 3.5GHz)
|
||||
- **RAM**: 16 GB (2x 8GB DDR4 2666MHz Crucial/Undefined - 15Gi usable)
|
||||
- **Almacenamiento**: 1x 480GB SSD ADATA SU630 (`sda` - LVM-Thin Proxmox Base)
|
||||
- **Red Física**:
|
||||
- **enp33s0**: Conexión ISP (router DHCP) + link directo srv-ns8 (10.0.100.2)
|
||||
- **nic0**: Bridge a vmbr0 para red local VMs
|
||||
|
||||
## Red
|
||||
- **IP**: `100.112.46.104` (Tailscale VPN)
|
||||
- **IP Física (Bridge vmbr0)**: DHCP (WAN) + `10.0.100.1` (Alias LAN DASUTEN)
|
||||
- **SSH**: `rmonla@100.112.46.104:22` (Passphrase RSA, Bóveda: `rsa`)
|
||||
- **Acceso**: SSH Key + Sudo (Usuario `rmonla` - Credenciales en bóveda: `srv-dasu:rmonla`)
|
||||
|
||||
### Configuración Física (2026-03-25)
|
||||
| Interfaz | Configuración | IP | Propósito |
|
||||
|----------|---------------|-----|-----------|
|
||||
| **enp33s0** | DHCP | `192.168.200.42/23` | ISP (router externo) |
|
||||
| **vmbr0** (bridge nic0) | Estática | `10.0.100.1/24` | Red local VMs + pc-dasu0 |
|
||||
| **enp33s0** (alias) | Estática | `10.0.100.2/24` | Link directo srv-ns8 |
|
||||
|
||||
### Tailscale
|
||||
- **IP**: `100.112.46.104`
|
||||
- **Estado**: ✅ ONLINE (active; direct `192.168.200.42:41641`)
|
||||
- **Subnet Router**: `10.0.100.0/24` (anunciado)
|
||||
- **Cuenta**: `pcdasu0@frlr.utn.edu.ar`
|
||||
|
||||
### SSH
|
||||
- **Acceso directo**: `rmonla@100.112.46.104:22` (Passphrase RSA)
|
||||
- **Acceso VMs**: `rmonla@10.0.100.x:7022` (Windows Server Core - OpenSSH)
|
||||
- **Credenciales**: Bóveda `srv-dasu:rmonla`
|
||||
|
||||
### Topología Implementada
|
||||
```
|
||||
INTERNET (ISP Router DHCP)
|
||||
│
|
||||
↓ (enp33s0 - DHCP 192.168.200.42)
|
||||
┌─────────────────────────────────────┐
|
||||
│ srv-dasu (Proxmox VE) │
|
||||
│ ┌─────────────────────────────┐ │
|
||||
│ │ vmbr0: 10.0.100.1/24 │ │
|
||||
│ │ NAT/Masquerade → enp33s0 │ │
|
||||
│ │ DNS: 10.0.100.10 + 8.8.8.8 │ │
|
||||
│ └─────────────────────────────┘ │
|
||||
│ │ │ │ │
|
||||
│ ↓ ↓ ↓ │
|
||||
│ VM 100 VM 101 VM 102 │
|
||||
│ DC .10 SQL .11 PCV .12 │
|
||||
└─────────────────────────────────────┘
|
||||
│
|
||||
↓ (link directo 10.0.100.2)
|
||||
┌──────────────────┐
|
||||
│ srv-ns8 │
|
||||
│ enp37s0 │
|
||||
│ 10.0.100.8 │
|
||||
└──────────────────┘
|
||||
```
|
||||
|
||||
### Tailscale
|
||||
- **Cuenta**: `pcdasu0@frlr.utn.edu.ar`
|
||||
@@ -27,14 +71,39 @@
|
||||
- **Gestión**: `./adn/tools/run tailscale switch dasuten`
|
||||
|
||||
## Servicios Críticos
|
||||
1. **Virtualización**
|
||||
- **Motor**: Proxmox VE
|
||||
- **Estado**: ✅ Operativo (Híbrido)
|
||||
|
||||
### 1. Virtualización
|
||||
- **Motor**: Proxmox VE 9.1
|
||||
- **Estado**: ✅ Operativo
|
||||
- **Propósito**: Hospedar servidores virtuales exclusivos para la oficina de DASUTEN.
|
||||
- **Subnet Router**: Expone `10.0.100.0/24` vía Tailscale.
|
||||
|
||||
### Huéspedes (VMs)
|
||||
- **[VM 100: dasu-srvv-dc](dasu-srvv-dc.md)** (Controlador de Dominio / Windows Server Core)
|
||||
### 2. Red y Conectividad
|
||||
- **NAT/Masquerade**: ✅ Configurado (`iptables -t nat -A POSTROUTING -s 10.0.100.0/24 -o enp33s0 -j MASQUERADE`)
|
||||
- **DNS Forwarding**: VMs usan `10.0.100.10` (DC) + `8.8.8.8` (Google)
|
||||
- **Proxy Docker**: `tinyproxy` en `:3129` (Alpine container)
|
||||
|
||||
### 3. Tailscale
|
||||
- **Estado**: ✅ ONLINE
|
||||
- **IP Pública**: `100.112.46.104`
|
||||
- **Conexión**: Directa (`192.168.200.42:41641`)
|
||||
- **Función**: Subnet router para `10.0.100.0/24`
|
||||
|
||||
### Huéspedes (VMs) - Red 10.0.100.0/24
|
||||
| VM | Hostname | IP | Rol | Estado |
|
||||
|----|----------|-----|-----|--------|
|
||||
| **100** | [dasu-srvv-dc](dasu-srvv-dc.md) | `10.0.100.10` | AD DS + DNS | ✅ ONLINE (Tailscale: 100.85.117.101) |
|
||||
| **101** | [dasu-srvv-sql](dasu-srvv-sql.md) | `10.0.100.11` | SQL Server 2019 | ✅ ONLINE (Tailscale: 100.107.24.124) |
|
||||
| **102** | dasu-pcv | `10.0.100.12` | VM de pruebas (Win 10 LTSC) | ✅ ONLINE (Tailscale: 100.118.129.44) |
|
||||
|
||||
## Dependencias / Sincronización
|
||||
- **Cluster**: Ninguna (Servidor Standalone externo al cluster de la Facultad).
|
||||
- **Red Local**: `10.0.100.0/24` (VMs + srv-ns8 vía link directo)
|
||||
- **Internet**: ISP vía DHCP (enp33s0 → router 192.168.200.1)
|
||||
- **Tailscale**: VPN mesh con subnet routing activo
|
||||
|
||||
## Bitácora de Referencia
|
||||
- **Evento 1272** (10:52-11:41): Configuración Capa 2
|
||||
- **Evento 1273** (11:42-11:43): Documentación topología
|
||||
- **Evento 1274** (12:17-13:02): Traslado srv-dasu
|
||||
- **Evento 1275** (13:03-13:30): Ecosistema completo ONLINE
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
# Ficha de Nodo: srvv-nginx-rm
|
||||
|
||||
| Atributo | Valor |
|
||||
| :--- | :--- |
|
||||
| **Hostname** | `srvv-nginx-rm` |
|
||||
| **IP Pública** | `190.114.205.17` |
|
||||
| **IP LAN** | `10.0.10.117` |
|
||||
| **DNS** | `rmonla.duckdns.org` |
|
||||
| **Sistema Operativo** | Debian 12 (Bookworm) |
|
||||
| **Tipo** | Contenedor LXC (VMID 116, unprivileged) |
|
||||
| **Rol** | Servidor Web NGINX |
|
||||
| **Host** | `srv-pmox3` (10.0.10.203) |
|
||||
| **SSH** | Puerto `7022`, usuario `root`, auth `password` |
|
||||
| **Bóveda** | `srvv-nginx-rm:root` |
|
||||
|
||||
## Especificaciones de Hardware
|
||||
- **CPU**: 2 cores (compartido LXC)
|
||||
- **RAM**: 2 GB
|
||||
- **Swap**: 512 MB
|
||||
- **Disco**: 20 GB (local-lvm:vm-116-disk-0)
|
||||
|
||||
## Servicios y Responsabilidades
|
||||
1. **NGINX 1.22.1** — Servidor web, puertos 80 (HTTP) y 443 (HTTPS)
|
||||
2. **PHP 8.2-FPM** — Procesamiento de aplicaciones PHP
|
||||
3. **Certbot 2.1.0** — Certificados Let's Encrypt, renovación automática
|
||||
4. **OpenSSH** — Acceso remoto, puerto 7022
|
||||
|
||||
## Aplicaciones Desplegadas
|
||||
| App | Ruta | Repo GitHub | Método Deploy |
|
||||
| :--- | :--- | :--- | :--- |
|
||||
| ViaCrucis | `/vcby` → `/var/www/vcby` | `ricardomonla/assjdm-ViaCrusis` | Deploy key SSH |
|
||||
|
||||
## Red
|
||||
- **eth0**: `190.114.205.17/24` — Red pública, gw `190.114.205.1`
|
||||
- **eth1**: `10.0.10.117/23` — Red interna, gw `10.0.10.1`
|
||||
- **DNS**: `8.8.8.8`
|
||||
- **Bridge**: `vmbr0` (capa 2 compartida público/privado)
|
||||
- **DuckDNS**: `rmonla.duckdns.org` → `190.114.205.17`
|
||||
|
||||
## HTTPS / Certificado SSL
|
||||
- **Certificado**: Let's Encrypt para `rmonla.duckdns.org`
|
||||
- **Expiración**: 2026-06-26
|
||||
- **Renovación**: Automática (certbot timer)
|
||||
- **Redirect**: HTTP → HTTPS (301) activo
|
||||
|
||||
## Acceso y Mantenimiento
|
||||
- **SSH**: `ssh -p 7022 root@10.0.10.117` o `root@190.114.205.17`
|
||||
- **Candados**: `./adn/tools/run candados run srvv-nginx-rm:root SSHPASS 'sshpass -e ssh -p 7022 root@10.0.10.117'`
|
||||
- **Proxmox**: `pct exec 116 -- bash` desde srv-pmox3
|
||||
- **Web pública**: `https://rmonla.duckdns.org/vcby/`
|
||||
- **Backup**: Pendiente configurar vzdump
|
||||
- **Monitorización**: Pendiente integrar
|
||||
|
||||
## Dependencias
|
||||
- `srv-pmox3` — Host Proxmox
|
||||
- Proyecto `P2606_WebServer-NGINX`
|
||||
|
||||
## Historial de Cambios Relevantes
|
||||
- 2026-03-28: LXC creado. NGINX instalado. IP pública verificada (HTTP 200).
|
||||
- 2026-03-28: DNS DuckDNS configurado. Repo vcby clonado con deploy key. PHP 8.2-FPM instalado.
|
||||
- 2026-03-28: HTTPS configurado con certbot/Let's Encrypt. Redirect HTTP→HTTPS activo.
|
||||
- 2026-03-28: Clave root guardada en candados (`srvv-nginx-rm:root`).
|
||||
Reference in New Issue
Block a user