From d75bd587921b4876dc8ec316e7d30418e65c32e0 Mon Sep 17 00:00:00 2001 From: jhodgkin Date: Sun, 12 Jul 2026 20:42:05 -0600 Subject: [PATCH] docs: update CLAUDE.md for SSH collector + Vaultwarden entry Co-Authored-By: Claude Sonnet 5 --- CLAUDE.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 409124b..c9c5d62 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -22,8 +22,12 @@ One login instead of logging into Proxmox, Zabbix, OMV, and every service separa in `apps/api/src/index.ts`. Adding a new data source = new collector + config entry, no other wiring. - `ProxmoxCollector` (done): one API call to `pve` returns CPU/mem/disk **and PSI pressure** (`pressurecpusome`, `pressurememoryfull`) for the host + every LXC. Covers ~22 of ~24 machines. - - Everything else (SSH collector for `.180`/`.171`, network discovery, Zabbix alerts) is filed as - backlog issues, not yet implemented. + - `SshHostCollector` (done): covers `.180` (omv) and `.171` (ripper), the bare-metal boxes Proxmox + can't see. Dedicated SSH key with a **forced `command=`** in the remote `authorized_keys` — the + server always runs a fixed read-only script regardless of what's exec'd, so a leaked key is still + contained. See `docs/ssh-collector-key-setup.md`, including the gotcha that `diskPaths` in + `hosts.yaml` must be kept in sync **by hand** with the remote script's `DISK_