Architecture

Capacity, Power, Thermal & Expansion Envelopes

Known compute, memory, storage, network, switch-port, and PoE limits, plus the electrical and thermal measurements required before expansion.

Capacity is constrained by assigned hardware, physical ports, storage topology, and the need to protect the edge firewalls from competing workloads. Inventory limits are known; whole-site electrical load, UPS runtime, cooling capacity, and measured thermal headroom are not yet recorded.

Electrical and Thermal Envelopes Are Unmeasured

No source records circuit ratings, PDU allocation, UPS capacity or runtime, idle and peak wattage, rack inlet temperature, sustained exhaust temperature, cooling capacity, or alarm thresholds. Hardware inventory is not evidence that the room or power path can support simultaneous peak load.

Known Resource Envelope

ResourceCurrent or target envelopeExpansion boundary
Multiport 10 Gb NICsSix total; five X710-T4 cards at Site B and one XL710/X710-class card in sa-stor-01All six are allocated; expansion requires procurement or an explicit reallocation
ThinkPad 10 Gb NICsTwo X550-T2 cards, one per Site A ThinkPadNo spare X550-T2 is recorded
Server RAM poolSeventeen 32 GB DDR4 ECC RDIMMs for Supermicro systemsEleven more 32 GB sticks are needed to bring every non-5049 Supermicro system to 128 GB
sa-stor-01 RAM96 GB installedSupported documented options are 192 GB, 288 GB, or 384 GB; do not mix RDIMM and LRDIMM
Site A ZFS8–12 Samsung SM863 1.92 TB SSDs in mirror vdevsExpansion stays in even-drive mirror pairs; usable capacity is half of raw mirror capacity
Site B CephFive nodes, 4–6 OSDs per node, 20–30 OSDs total, replication size 3Site-local only; reserve 2–4 enterprise SSDs as cold spares
Enterprise SSD pool20 SM863, 10 Micron 5200 MAX, 8 Micron 5300 Pro, all 1.92 TBAllocation must preserve the cold-spare target and workload endurance roles
Boot mediaSeven recorded 512 GB M.2/SATA M.2 devices plus the existing sa-stor-01 boot driveDo not consume 1.92 TB enterprise SSDs for boot unless forced
Site B core ports41 of 48 sb-sw-01 ports assignedSeven physical ports remain; VLAN and NIC design still governs whether they are usable

Site A Switching and PoE Envelope

Each USW-Pro-XG-10-PoE provides ten 10 GbE RJ45 ports and two 10 Gb SFP+ ports. The RSTP triangle consumes all six SFP+ endpoints.

SwitchAssigned RJ45 portsReserved expansion or recoverySFP+ state
sa-sw-01Ports 1–6Ports 7–9 disabled spares; port 10 disabled emergency adminPorts 11–12 used by fabric
sa-sw-02Ports 1–5Ports 6–9 disabled spares; port 10 disabled emergency adminPorts 11–12 used by fabric
sa-sw-03Ports 1–6Port 7 future AP; ports 8–9 disabled spares; port 10 disabled emergency adminPorts 11–12 used by fabric

PoE is disabled on every non-PoE endpoint. sa-ap-01 is the only enabled target PoE load: PoE++ 802.3bt at approximately 29 W on sa-sw-03 port 6. The future AP port remains disabled with PoE off until used.

PoE Budget Is Not the Site Power Budget

The AP's approximate draw is documented, but switch PoE capacity, aggregate switch draw, server load, UPS sizing, and circuit headroom are not. A second AP requires both a port-profile change and a verified power budget.

Workload Capacity Guardrails

System classSuitable workloadCapacity guardrail
E200 edge hostsOPNsense, OpenBao, UOS, DNS helper, small proxy, monitoring agentNo heavy databases, Ceph OSDs, storage-heavy VMs, or heavy Kubernetes workers
Site A ThinkPadsCI, development, GPU/AI/media, light VMs or workersNo IPMI; recovery from a failed network or thermal event may require physical access
sa-stor-01ZFS, PBS-A, DNS, monitoring, databases, core VMsAQC107 does not carry management or Corosync; protect storage and control services from NIC instability
Site B compute nodesCeph, Kubernetes/OpenShift, distributed computeCeph public and cluster traffic stay on separate directly attached networks

The E200 rule is a reliability envelope, not a utilization target. Spare CPU and I/O on the edge preserve routing responsiveness for the entire site.

Power and Thermal Evidence Gaps

MeasurementCurrent recordRequired before material expansion
Branch-circuit capacityNot recordedCircuit voltage, breaker rating, continuous-load allowance, and shared loads
PDU and outlet mappingNot recordedDevice-to-outlet map, PDU rating, and phase/bank balance where applicable
UPS capacity and runtimeNot recordedRated VA/W, battery health, load percentage, runtime at current and projected peak
Device idle and peak drawNot recordedMeasured watts per server, switch, storage chassis, AP, and WAN equipment
Rack thermal stateNot recordedInlet and exhaust temperatures at idle and sustained load
Cooling headroomNot recordedRoom/rack heat-removal capacity and acceptable operating range
Thermal alertingNot recordedSensor source, warning/critical thresholds, notification path, and response owner
Expansion reserveNot recordedMaximum additional watts and heat load without circuit, UPS, or cooling changes

Expansion Gates

  1. Confirm the target port, VLAN profile, NIC path, and failure-domain effect.
  2. Measure present electrical load and thermal state under sustained representative workload.
  3. Verify UPS runtime and circuit headroom with the proposed device included.
  4. Preserve edge-host CPU/I/O reserve, storage cold spares, and the no-spare NIC constraint.
  5. Add monitoring and recovery ownership before treating new capacity as production.

Hardware quantities and wiring detail remain in per-site inventory, NIC allocation, RAM & storage allocation, and the site port maps.