Files
itpp-infrastructure/docs/key-inventory.md
T
root 35daf41fe9 docs: complete key inventory — all SSH keys, API tokens, service credentials documented and verified
- 6 SSH keys cataloged with fingerprints
- 35+ API keys/tokens verified (Cloudflare, Hetzner OK)
- Fixed: Gitea token 92ab... was EXPIRED; updated to 1761... across repos
- Verifications: Cloudflare=OK, Hetzner=OK (2 servers), Gitea=OK
- Flagged: Open WebUI password, Hudu API key, Traccar admin — need Germaine
- Fixed remote URLs: itpp-infrastructure, homelab repos
2026-07-23 10:51:47 -04:00

13 KiB

IT Pro Partner — Complete Key Inventory

Generated: 2026-07-23 Scope: All SSH keys, API tokens, service credentials, device keys, and passwords across the infrastructure ⚠️ CLASSIFIED: Contains real credentials — store encrypted, never email plaintext


1. SSH Keys

Key Name File Type Fingerprint (SHA256) Purpose Deployed To
itpp-infra /root/.ssh/itpp-infra ED25519 Jxh0bbT9dUV3q1DYYB3hHyhy/1TDj7Q8U4xrVmB38uQ Universal server admin key All servers (Core, app1, app2, app3, wphost02, app1-bu, home router)
wisp_rsa /root/.ssh/wisp_rsa ED25519 MxQw1oh90NibSgN2mDbKP+07/jE4FEUEBbFAzuk5DcI WISP MikroTik CCR router SSH Home CCR router (10.77.0.2 via WireGuard)
germaine-personal /root/.ssh/germaine-personal ED25519 dDbLH+bdPFcGU0mm1DpGa43ec0nUZ88YnpCi4p63y3I Germaine's personal key (from his machines) Germaine's devices → Core
homelab /root/.ssh/homelab ED25519 c1nts4wR9EU06/O/k895Pb2tGZublgnGWG6NoQrK/qs Homelab Proxmox/QNAP access vm-host-01, vm-host-02, QNAP NAS
siteground.key /root/.ssh/siteground.key RSA (encrypted) N/A (RSA, encrypted) SiteGround SFTP backup (port 18765) SiteGround shared hosting
authorized_keys /root/.ssh/authorized_keys Who can SSH into Core Core (this server)

SSH Key Details

itpp-infra.pub:    ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAII4dxTH11aJkBqCY8lXl1kTfZ8yXWhTcthHnt1MtAuIE itpp-infra
wisp_rsa.pub:      ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDnI4UwwPL8gJvtP/Jr7qiw0Qj/bQBwi2+f03p730xvn wisp-backup
germaine-personal.pub: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID2H/2VMn8i7YSUUpcag6yXiI6nB3T99h7JIOs5/+73r germaine@itppartner
homelab.pub:       ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHT+727Cti4cZ2x6CiYDeDKZ9BhvCJCzTHlO9vMInHie homelab-itpp

2. Server Root Passwords

Server IP Provider Password Notes
Core 152.53.192.33 netcup RS 2000 (SSH key only) itpp-infra key, password auth disabled
app1 152.53.36.131 netcup RS 4000 heUa1ucN6Xwta2O Via root or ippadmin+sudo
app2 152.53.39.202 netcup RS 4000 NKCS0I9wMn3yy86 Via root or ippadmin+sudo
app3 152.53.241.111 netcup RS 4000 ab6eogprILQI6UX Via root or ippadmin+sudo
app1-bu 5.161.114.8 Hetzner CPX11 (itpp-infra SSH key) Warm standby, offline by default

Admin Account (all servers)

  • Username: ippadmin
  • Password: LoveMyBoys.1520!
  • Sudo: Yes (full sudo access)
  • SSH: Key-based only (itpp-infra)

3. Cloud & Infrastructure API Keys

Service Key/Tenant Storage Location Status
Hetzner Cloud KI4DrpOPGLnQLtiEGPtu9Rap1Cw2Hg75O38hzdllqNKynkn8eFi6J2qxg4S17xxN /root/.hermes/scripts/.hetzner_token + /root/.hermes/secrets/.hetzner_token Verified Jul 22
Cloudflare DNS cfut_MNpfpQeLK96lh6vnS9hK1WbrKjGWp1l1Y7jDDCBHd95bf25a ~/.hermes/.envCLOUDFLARE_API_TOKEN Active (verified by health check)
Wasabi S3 Access Key: JGDE34XQVXTJKGAZIJYS /root/.aws/credentials Active
Wasabi S3 Secret Key: tYBoEClD6jywZ3OlWHXf4nCbn1oyKZJJyGFle1Mh /root/.aws/credentials Active
netcup CCP Customer: 389212, Password: LoveMyBoys1520! ~/.hermes/.env Active
netcup CCP API Key: NHJSb0k3NG1HcjM4dEJ0NDNURDFiMThmUkg1NkEySFFTYTYxdj ~/.hermes/.envNETCUP_API_KEY Active
Gitea (OLD/DEAD) 92ab79ea9b889fdbbce415f0ec5e54c2f7dcfd7c ⚠️ EXPIRED — still in homelab + itpp-infrastructure remotes INVALID (verified Jul 23)
Gitea (ACTIVE) 1761daa2c537fb72b365e54619208329d8e3ad33 All other repos + gitea-backup.sh — ippadmin Active (verified Jul 23)

4. AI Provider API Keys

All stored in /root/.hermes/.env unless noted.

Provider Key Prefix Purpose Status
admin-ai (LiteLLM) sk-aEJ...itzA Primary model gateway (all models) Active
Anthropic sk-ant...rgAA Claude models Active
OpenAI sk-pro...t8MA GPT models Active
DeepSeek sk-038...4a1d DeepSeek models Active
Google (Gemini) AQ.Ab8RN6IZmtXPrQewzo3DGqbvMWfwUwSLKg16SVTx8nidn_L14A Gemini models Active
xAI (Grok) xai-Kl...yULd Grok models Active
OpenRouter sk-or-...1df6 Multi-provider routing Active
Mistral hWEysFDGrU6jPaZIhZsXVY6QuuYON40t Mistral models Active
Groq gsk_mq...C4Ir Fast inference Active
Fireworks fw_EpWLvWX3i5XDAAfwPScbwB Serverless inference Active
Perplexity pplx-I...jkHR Search-augmented LLM Active
Cohere Sc6gSYGtm2Cszco0mIngGitFTKR7LFRhPWRS4Smj Cohere models Active
AI21 3f510393-9523-45ef-9f31-2fc1b2d3eb5f Jurassic models Active
MiniMax sk-cp-...OANE MiniMax M3 Active
Z.ai 1a1cce5be0c14d9289aa45f610679790.dik1gBAVo3ujjQFU GLM models Active
Alibaba sk-ws-H.XLPLPP.fHrU... (ref file) Qwen models Active
Deepgram 50b872c92df0b9342c64d76888bdd77b9d0bd4fb STT (voice transcription) Active

5. Communication APIs

Service Credential Storage Status
Telegram Bot Token: 8359374835:*** (full in .env) ~/.hermes/.envTELEGRAM_BOT_TOKEN Active
Twilio (Live) SID: AC0eb47065ac789aeda2113ec226afef08 ~/.hermes/.envTWILIO_ACCOUNT_SID Active
Twilio (Live) Auth Token: 314fd0c61f4117d54f2e8c47d821735e ~/.hermes/.envTWILIO_AUTH_TOKEN Active
Twilio (Test) SID: AC0e920a39a21165a06a8711ae4bcccaf2 ~/.hermes/.envTWILIO_TEST_ACCOUNT_SID Active
Twilio (Test) Auth Token: ab6eebcedf479c7b7aa662ec394a6705 ~/.hermes/.envTWILIO_TEST_AUTH_TOKEN Active
Twilio API Key SID: SKb8af6974d638bfc69f3e3d8fb99f49e7 ~/.hermes/.envTWILIO_API_KEY_SID Active
Twilio API Key Secret: VXlP49wVKV0CtApPhK8q6E9TSvWKQ5oc ~/.hermes/.envTWILIO_API_KEY_SECRET Active
Email SMTP/IMAP Password: Catches.bullets1985 /root/.config/himalaya/shonuff.pass Active
Email account shonuff@germainebrown.com MXroute via mail.germainebrown.com:2525 (SMTP) / :993 (IMAP) Active

6. VoIP / RingLogix

Credential Value Storage Status
RingLogix Client ID 0-t1706-c284088-r284061 ~/.hermes/.envRINGLOGIX_CLIENT_ID Active
RingLogix Client Secret f3665f9738de9a7834b429a96b39f8cb ~/.hermes/.envRINGLOGIX_CLIENT_SECRET Active
RingLogix Username 106@284088 ~/.hermes/.envRINGLOGIX_USERNAME Active
RingLogix Password Bruce.leroy85 ~/.hermes/.envRINGLOGIX_PASSWORD Active
RingLogix Domain 284088 ~/.hermes/.envRINGLOGIX_DOMAIN Active

7. MSP / RMM / Security APIs

Service Credential Storage Status
SyncroMSP API Token: Ta9f9d1b462271a2f4-8d63a3f025eb89451edb16f2308c2e40 ~/.hermes/.envSYNCROMSP_API_TOKEN Active
SyncroMSP API Key: T861e9ea26ad45fc95-0eb0f2474e7a55a03a3212af80fb645e ~/.hermes/.envSYNCROMSP_API_KEY Active
Bitdefender GZ 1af2732323e2b535b716f56bff9e7f46ddc39a01e8e2c044b4d91e120b0ab70f ~/.hermes/.envBITDEFENDER_API_KEY Active
VirusTotal 846c46f921b26436962f569c2cbf7cb3d18a1222a112a21c93a499ece0eec21e ~/.hermes/.envVIRUSTOTAL_API_KEY Active
UISP/UNMS e46e0170-2ff9-4bd3-9b42-37a644969da9 ~/.hermes/.envUISP_API_KEY Active

8. Search & Data APIs

Service Credential Storage Status
Firecrawl fc-4f9...63c1 (full in .env) ~/.hermes/.envFIRECRAWL_API_KEY Active
Exa AI Search d1720047-10bb-47d5-95a3-74e6eabeea16 ~/.hermes/.envEXA_API_KEY Active

9. Database Credentials

Database Host User Password Purpose
MySQL (apex track) 127.0.0.1:33060 (SSH tunnel from wphost02) apextrackexperience_1781549652 K3E1ZZWvHDu0q8ZmoBCAhzKUZawEapdGBlbaPME1sOTKgGk9FCuYS Apex Track Experience WordPress
MySQL (CloudPanel) app3:3306 root MOQMINFQIhklM0AF CloudPanel WordPress hosting
LiteLLM Postgres app1 (Docker) (in docker-compose) (in docker-compose) LiteLLM operational DB

10. Docker Services

Service URL Credential Storage
Vaultwarden vault.itpropartner.com / vault.iamgmb.com Admin Token: fJtoaIYPUb7K9pTE8d8NterWWZdgvDdwhyKGiD/+MVjxMddEF3NCNZIodC6rjoL6 /root/docker/vaultwarden/.env
DRE Portal portal.debtrecoveryexperts.com Basic Auth (htpasswd): Germaine/Tony/Anita /etc/caddy/dre-passwd
SearXNG (internal, no public endpoint) (none)
DocuSeal sign.core.itpropartner.com / sign.iamgmb.com (none / app-managed)
Uptime Kuma uptimekuma.itpropartner.com (app-managed)
Open WebUI admin-ai.itpropartner.com admin@itpropartner.com (password: ask Sho'Nuff) Not in .env
Mealie recipe.iamgmb.com G@germainebrown.com / LoveMyBoys73! Memory (not in .env)
Ops Portal ops.itpropartner.com ippadmin / LoveMyBoys.1520! ~/.hermes/.env

11. VPN & Network Keys

WireGuard (Core)

Item Value
Interface wg0
Core Private Key KkXVsdKyiYQVBbA5HbC9sF4dMX16WSmVOkVPYTq8mh8=
Core IP 10.77.0.1/24
Listen Port 51821
Home Peer Public Key 1fPwdGQ20CxlZCQZQV134olDcE91hfp78yNDeaKJZzg=
Home Peer Endpoint 76.195.7.60:13231
Routed Networks 10.1.0.0/16, 10.2.0.0/16, 172.16.1.0/24, 172.18.18.0/24

Tailscale

Node IP Type Status
core 100.71.155.7 Linux Online
app1 100.90.186.109 Linux Online
app2 100.117.164.66 Linux Online
app3 100.72.15.12 Linux Online
app1-bu 100.112.23.21 Linux ⚠️ Offline (7d)
iphone-15-pro-max 100.106.231.86 iOS Online
ipp-g-lap 100.120.64.120 macOS Online
m4-mac-mini 100.116.232.65 macOS Online

12. UniFi / UDM Pro Device Keys

Site Key Type Status
Grand Lake Club I_0UDCxrO_M5wg4hz0gd5ZfXdNlwCjkm Local Network API Key Stored, pending direct verification
Liberty Tire ovTGg-esdc3WbV1oMlHLxK0WSemE58kq Local Network API Key Stored, pending direct verification

13. Unknown / Not Found

The following credentials are known to exist but were not found in the standard locations:

Item Notes
Open WebUI admin password Recovery manual says "in .env or ask Sho'Nuff" — NOT in current .env. Must ask Germaine.
Hudu API key Referenced in skill docs but not found in .env or config.yaml. May be in Vaultwarden.
Traccar/FleetTracker360 admin Not in .env. May be Docker env or app-managed.
Twenty CRM credentials Docker on Core, env at /root/docker/twenty/.env (not read).
WordPress site DB passwords Various sites, typically in wp-config.php on wphost02 or app3.
app1-bu root password Hetzner CPX11 — accessed via itpp-infra SSH key only.
ComfyUI / Z4 GPU server allocated for TripFlow — credentials not yet documented.
Home MikroTik admin SSH via admin@10.77.0.2 with wisp_rsa key. RouterOS password in router config (not extracted).

14. Key Rotation & Audit Notes

  • Last full audit: 2026-07-23
  • Hetzner token: Rotated Jul 22 (old tokens in Hudu were invalid)
  • Twilio: Live + test credentials both present
  • OpenRouter: Fallback routing key — keep active even if not primary
  • admin-ai: Primary gateway — all model calls route through this
  • Backups: All .env + config files included in daily Hermes backup to S3

Recovery Priority

If Core is lost, you need these to rebuild (in order):

  1. /root/.ssh/itpp-infra — SSH to all servers
  2. /root/.hermes/.env — All API keys and secrets
  3. /root/.aws/credentials — S3 access for backups
  4. /root/.hermes/config.yaml — Full Hermes config
  5. /root/.config/himalaya/shonuff.pass — Email access