Einstellungen & Credentials – Wo finde ich was?
Stand: 2026-05-26
Zweck: Schnell nachschlagen, wo Zugänge und Konfiguration liegen — ohne alles in einer Datei zu duplizieren.
Pfad dieser Datei: /Users/danieltoschke/EINSTELLUNGEN-UND-CREDENTIALS.md
Sicherheit: Viele verlinkte Dateien enthalten Klartext-Passwörter. Nicht committen, idealerweise chmod 600. Diese Übersicht enthält keine Passwörter, nur Verweise.
Inhaltsverzeichnis
#schnell-nuclos-häufig-gesucht
#1-passwort-manager
#2-zentrale-projekt-credentials-homelab--toschkeorg
#3-öffentlicher-server-srv01--mxcore-toschkede
#4-monitoring-vm-vsrv01toschkede
#5-homelab-netz-19216846023--46toszone
#6-smarthome--homeassistant
#7-mail-system-mailcow
#8-wolke--nextcloud
#9-sso--authentik--keycloak
#10-dns-provider--api-tokens
#11-hetzner-cloud--robot
#12-fritzbox--netzwerk-hardware
#13-synology-nas
#14-proxmox-ve
#15-coolify-alle-instanzen
#16-semaphore--ansible
#17-telegram-bot
#18-vpn--wireguard
#19-guacamole-remote-desktop-gateway
#20-intel-amt--kvm-over-ip
#21-cursor-agent--vnc-lxc
#22-docker--colima-lokal
#23-ssh--shell
#24-ide--ki-tools
#25-webseiten--wordpress
#26-verein-toschkeorg-stack
#27-safeincloud--infrastruktur-einträge-kurzübersicht
#28-alle-mxcore-apps-schnellreferenz
#29-suche-auf-dem-mac
#30-checkliste-credential-fehlt
Schnell: Nuclos (häufig gesucht)
Es gibt zwei verschiedene „Nuclos"-Welten:
| Hostname |
DNS |
IP |
Rolle |
Zugangsdaten |
nuclos.toschke.de |
öffentlich |
94.130.14.177 |
Nuclos ERP auf MXCore (Docker /opt/mxcore/nuclos/) |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Zeile Nuclos ERP |
nuclos.46.tos.zone |
nur LAN |
192.168.47.21 |
Coolify-Host im Heimnetz (Traefik, Semaphore, Guacamole) |
SafeInCloud → Eintrag nuclos.46.tos.zone (Login: nuclos) |
Merksatz: nuclos.toschke.de = Internet / 177 · nuclos.46.tos.zone = LAN / 47.21
1. Passwort-Manager
| Was |
Ort |
| SafeInCloud (Hauptquelle) |
App auf Mac / iOS — über 500 Einträge |
| XML-Exporte (Such-Backup) |
~/Downloads/SafeInCloud.db_database_2026-05-13.xml |
| macOS Schlüsselbund |
„Schlüsselbundverwaltung" — WLAN, Zertifikate, App-Passwörter |
Viele Dienste stehen nur in SafeInCloud, nicht in Projektdateien. Immer zuerst dort suchen.
2. Zentrale Projekt-Credentials (Homelab / toschke.org)
Hauptordner: Documents/Projekt/Credentials/
| Datei |
Inhalt |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md |
Sammelkopie: Semaphore (47.21 + Legacy 46.154), Telegram, toschke.org-Stack komplett (Coolify, Keycloak, Mailcow, Nextcloud, …), Hestia, DNS-Provider |
Documents/Projekt/Credentials/Server/toschke_ev_server.env |
Kanonische .env — identische Daten wie in ZENTRALE, maschinenlesbar |
Documents/Projekt/Credentials/SmartHome/project_credentials.json |
Coolify .22, Hetzner DNS, Technitium DNS, Proxmox API, HomeAssistant URLs |
Documents/Projekt/Credentials/SmartHome/coolify_credentials.json |
Coolify .22 API-Token, User |
Documents/Projekt/Credentials/SmartHome/proxmox_credentials.json |
Proxmox API-Token (root@pam!opencode) |
Documents/Projekt/Credentials/README.md |
Regeln, Struktur, Schnellverweis |
Documents/Projekt/Credentials/info.json |
Maschinenlesbare Metadaten |
Duplikat (identischer Inhalt, älterer Pfad): Documents/Projekt/toschke_ev_server/credentials.env
Regel: Keine Passwörter in normalen Projektordnern — nur unter Credentials/ referenzieren.
3. Öffentlicher Server srv01 / mxcore (*.toschke.de)
Projekt: Documents/Projekte/srv01.toschke.de/cloudpanel/
| Datei |
Inhalt |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md |
Vollinventar: alle ~30 MXCore-Apps (URLs + Login + Klartext-PW), Wolke-User, Mail, CloudPanel, API-Tokens, RP-SFTP-User |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/mxcore.env |
Lokale Kopie /opt/mxcore/.env |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/mxcore-docker-app-credentials.tsv |
TSV vom Server (/root/) |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env |
Cloudflare + Hetzner DNS API-Tokens |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/cp/authentik-mxcore.initial-credentials.txt |
Authentik-Bootstrap |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/cp/cloudpanel_reverse_proxy_sites.tsv |
RP-SFTP-User/Passwörter |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/README.md |
scp-Befehle zum Synchronisieren vom Server |
Auf dem Server (maßgeblich, per SSH root@94.130.14.177):
| Server-Pfad |
Inhalt |
/opt/mxcore/.env |
Master-Secrets aller Docker-Stacks |
/root/mxcore-docker-app-credentials.tsv |
App-Logins |
/root/authentik-mxcore.initial-credentials.txt |
IdP-Bootstrap |
/root/cloudpanel_reverse_proxy_sites.tsv |
RP-Sites |
/root/dns-api-tokens.env |
DNS-Provider-Tokens |
/root/wolke-migrate-user-passwords.tsv |
Migrations-Passwörter Wolke |
/root/mail-users-authentik-passwords.tsv |
Authentik-Sync Postfächer |
/opt/mailcow-dockerized/mailcow.conf |
Mailcow DB/Redis/API |
Übergreifende Doku (ohne Passwörter):
| Datei |
Inhalt |
Documents/Projekte/TOeV-Systeme/ANWENDUNGSREGISTER.md |
Master-App-Liste aller Dienste (mxcore + vsrv01 + srv01), Status, Compose-Pfade |
Documents/Projekte/TOeV-Systeme/ANWENDUNGSSTAND.md |
Host-Architektur, Container-Übersicht, Mermaid-Diagramm |
4. Monitoring-VM vsrv01.toschke.de
| Aspekt |
Wert |
| IP |
128.140.35.138 |
| SSH |
ssh root@vsrv01.toschke.de (Key: ~/.ssh/id_ed25519) |
| Stack-Pfad |
/opt/toschke-modern |
| Hetzner-Konsole |
https://console.hetzner.com/projects/10005067/dashboard |
Projekt: Documents/Projekte/vsrv01.toschke.de/
| Datei |
Inhalt |
Documents/Projekte/vsrv01.toschke.de/PROJECT_STATE.md |
Stand, DNS, TLS, offene Aufgaben |
Documents/Projekte/vsrv01.toschke.de/zugangsdaten-zugangstoken.txt |
SSH-Keys, Hetzner API-Token (agents) |
Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt |
Wolke CalDAV/CardDAV Sync, Authentik-Reset |
Dienste auf vsrv01: Traefik, Uptime Kuma (up.vsrv01.toschke.de), Grafana (grafana.intern.toschke.org), Prometheus, PBS (pbs.vsrv01.toschke.de), Dockhand, Status-Seite
5. Homelab Netz 192.168.46.0/23 / *.46.tos.zone
Projekt: Documents/Projekte/homenet46/guacamole/
| Datei |
Inhalt |
Documents/Projekte/homenet46/guacamole/PROJECT_STATE.md |
IP-Inventar, Scan-Ergebnis, offene Aufgaben |
Documents/Projekte/homenet46/guacamole/LAN-SCAN-192.168.46.0-23.md |
Nmap-Scan, 39 Hosts, 26 mit offenen Ports |
Documents/Projekte/homenet46/guacamole/INVENTAR-FERNZUGRIFF-ZIELE.md |
SSH/RDP/VNC-Ziele |
Wichtige LAN-IPs:
| IP |
Rolle |
Credentials-Quelle |
192.168.47.21 |
nuclos.46.tos.zone — Coolify, Traefik, Semaphore |
SafeInCloud |
192.168.47.22 |
Zweiter Coolify-Host, VNC :5901, Technitium DNS :5380 |
SmartHome/project_credentials.json |
192.168.47.72 |
Proxmox VE (:8006) |
SmartHome/proxmox_credentials.json |
192.168.47.240 |
Windows AD / RDP :3389 (14WIN-APPS, Domain ev.toschke.de) |
SafeInCloud |
192.168.47.131 |
LAVE (lave-toschke per SSH) |
~/.ssh/config |
192.168.46.70 |
Synology DISKSTATION1 |
SafeInCloud |
192.168.46.50 |
Home Assistant (neu) |
SafeInCloud |
192.168.46.31 |
Home Assistant (alt) |
SafeInCloud |
192.168.46.10 |
FRITZ!Box 7690 |
SafeInCloud |
192.168.46.19 |
Intel AMT (KVM-over-IP) |
zugang-intel-amt.txt |
192.168.46.89 |
Raspberry Pi |
.homenet-guacamole-credentials.env |
192.168.46.120 / .81 |
Macs (VNC :5900) |
.homenet-guacamole-credentials.env |
192.168.46.61 |
Lantronix Spider Web-KVM |
.homenet-guacamole-credentials.env |
192.168.46.125 |
NanoKVM (aktuell offline) |
.homenet-guacamole-credentials.env |
192.168.46.91 |
Proxmox (lokal) |
SmartHome/proxmox_credentials.json |
6. SmartHome / HomeAssistant
Projekt: Documents/Projekt/SmartHome/
| Datei/Ordner |
Inhalt |
Documents/Projekt/SmartHome/coolify_credentials.json |
= Kopie aus Credentials/SmartHome/ |
Documents/Projekt/SmartHome/project_credentials.json |
= Kopie, mit Coolify, DNS, Proxmox, HA-URLs |
Documents/Projekt/SmartHome/proxmox_credentials.json |
= Kopie |
Documents/Projekt/SmartHome/HomeAssistant/ |
REST-API-Skripte, Monitor |
Documents/Projekt/SmartHome/Deconz/ |
ZigBee-Gateway |
Documents/Projekt/SmartHome/Homematic/ |
CCU / HomeMatic IP |
Documents/Projekt/SmartHome/dns-compose.yml |
Technitium DNS |
Documents/Projekt/SmartHome/lxc_home-net.json |
LXC-Konfiguration |
HomeAssistant: URLs http://192.168.46.50:8123 (neu), http://192.168.46.31:8123 (alt)
SafeInCloud: Eintrag Einstellungen – Home Assistant
7. Mail-System (Mailcow)
| Aspekt |
Wert |
Credentials-Quelle |
| Admin-UI |
https://mail.toschke.de |
SafeInCloud; auf Server in /opt/mailcow-dockerized/mailcow.conf |
| Domains |
toschke.de, 4tn.de, toschke.email, … |
Mailcow-UI |
| App-Passwörter (Apple-Mail-Fix) |
SMTP für adhsautismus-vorstand@4tn.de, toschke@duese.ping.de |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt App-Passwörter |
| Authentik-Sync |
Postfach-PWs für SSO |
Server: /root/mail-users-authentik-passwords.tsv |
| SOGo Webmail |
webmail.toschke.de |
Postfach-Passwort oder SSO |
8. Wolke / Nextcloud
Es gibt zwei getrennte Nextcloud-Instanzen:
| Instanz |
URL |
Compose-Pfad |
Credentials |
| Wolke (Produktion) |
wolke.toschke.de |
/srv/wolke/ auf mxcore |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt Wolke (alle User + Passwörter) |
| Nextcloud (MXCore-Stack) |
nextcloud.toschke.de |
/opt/mxcore/nextcloud/ |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 4 |
CalDAV/CardDAV-Sync (Mac): Anleitung in Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt
9. SSO / Authentik / Keycloak
| System |
URL |
Credentials |
| Authentik (MXCore-IdP) |
https://authentik.toschke.de |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md — akadmin |
| Authentik Passwort-Reset (daniel) |
— |
Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt |
| Keycloak (toschke.org) |
https://auth.toschke.org |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Keycloak |
| OAuth-Secrets (OIDC) |
pro App in /opt/mxcore/.env |
Server / mxcore.env lokal |
10. DNS-Provider & API-Tokens
| Provider |
Domains |
Credentials |
| Hetzner Cloud DNS |
toschke.de, tos.zone, *.vsrv01.toschke.de |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env (HETZNER_DNS_API_TOKEN) |
| Cloudflare |
toschke.org, *.intern.toschke.org |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env (CLOUDFLARE_API_TOKEN); SafeInCloud: Cloudflare |
| Technitium DNS (intern, LAN) |
46.tos.zone |
http://192.168.47.22:5380 — Documents/Projekt/Credentials/SmartHome/project_credentials.json; MXCore: dns.toschke.de — Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md |
DNS-Skripte: operations/scripts/source-dns-tokens.sh, cloudflare-dns-migrate-ips.py, hetzner-cloud-dns-migrate.py
11. Hetzner Cloud & Robot
| Konto |
Credentials |
| Hetzner Robot (Dedicated srv01) |
SafeInCloud: robot.your-server.de, FFOV Hetzner Robot, srv01 - Proxmox |
| Hetzner Cloud (vsrv01 VM, DNS) |
SafeInCloud: accounts.hetzner.com, Toschke e.V. accounts.hetzner.com |
| Hetzner Cloud API (vsrv01) |
Documents/Projekte/vsrv01.toschke.de/zugangsdaten-zugangstoken.txt |
| Hetzner Cloud API (Coolify) |
SafeInCloud: coolify-hetzner-token |
| Storage Box / Share |
SafeInCloud: Hetzner Share, FFOV Storage Box; .env auf vsrv01 (STORAGESHARE_*) |
12. FRITZ!Box / Netzwerk-Hardware
| Gerät |
IP |
Credentials |
| FRITZ!Box 7690 (Haupt-Gateway) |
192.168.46.10 |
SafeInCloud: fritz.box mahlerbox, ha FRITZ!Box 7690 |
| FRITZ!Box 5690 Pro (Praxis) |
— |
SafeInCloud: PRX BMT Gast WLAN FRITZ!Box 5690 Pro |
| MyFRITZ |
sso.myfritz.net |
SafeInCloud: www.myfritz.net, ffov sso www.myfritz.net |
| UniFi Network |
192.168.46.123 / 46ubnt.toschke.eu |
SafeInCloud: UniFi Network |
| EAP (TP-Link Access Point) |
— |
SafeInCloud: EAP Cannockstr. |
13. Synology NAS
| Gerät |
IP |
Credentials |
| Diskstation1 (Haupt-NAS) |
192.168.46.70 |
SafeInCloud: Diskstation1 - Synology DiskStation, diskstation1 |
| PRX-Diskstation (Praxis-NAS) |
— |
SafeInCloud: PRX-Diskstation - Synology NAS |
| Synology-Konto |
account.synology.com |
SafeInCloud |
| QuickConnect |
toschke46.de8.quickconnect.to |
SafeInCloud |
14. Proxmox VE
| Instanz |
IP / URL |
Credentials |
| srv01 (Hetzner Dedicated) |
94.130.14.172:8006 |
SafeInCloud: srv01 - Proxmox Virtual Environment, hetzn srv01 |
Homelab (hsrv02) |
192.168.47.72:8006 |
SafeInCloud: hsrv02 - Proxmox Virtual Environment |
| Homelab alt |
192.168.46.91:8006 |
Documents/Projekt/Credentials/SmartHome/proxmox_credentials.json — API-Token root@pam!opencode |
| Praxis |
— |
SafeInCloud: Praxis blech01 - Proxmox Virtual Environment |
| proxmox1.toschke.org (alt) |
— |
SafeInCloud |
WireGuard auf srv01: SafeInCloud: vmbr1wireguard srv01
15. Coolify (alle Instanzen)
| Instanz |
URL |
Credentials |
Homelab .21 |
http://192.168.47.21:8000/, https://coolify.46.tos.zone |
SafeInCloud: Coolify 47.179 |
Homelab .22 |
http://192.168.47.22:8000/ |
Documents/Projekt/Credentials/SmartHome/project_credentials.json, SafeInCloud |
toschke.org (.84) |
http://192.168.46.84:8000/ |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Coolify |
| ADHS Autismus |
— |
SafeInCloud: [Coolify ADHS Autismus] Coolify |
Coolify-Anleitungen: Documents/Projekt/toschke_ev_server/coolify_anleitung.log
16. Semaphore / Ansible
| Instanz |
URL |
Credentials |
Aktuell (Coolify .21) |
http://192.168.47.21:3000, https://ansible.46.tos.zone |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 1 |
Legacy (LXC .154) |
http://192.168.46.154:3000 |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 2; auch Documents/Projekt/ansible-semaphore/CREDENTIALS.md |
Compose lokale Orchestration: Documents/Projekt/orchestration-coolify/docker/.env
Playbooks/Stacks: Documents/Projekt/toschke_ev_server/compose/ (mailcow, keycloak, nextcloud, joplin, …)
17. Telegram Bot
| Feld |
Wert |
Quelle |
| Bot |
@toschke_bot |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 3 |
| Token |
in ZENTRALE |
auch Documents/Projekt/bot-projekte/telegram_chats.md |
| Monitoring-Gruppe |
-1002166598578 |
telegram_chats.md |
| Semaphore-Thread |
13526 |
telegram_chats.md |
18. VPN / WireGuard
| System |
Credentials |
WireGuard (srv01 vmbr1) |
SafeInCloud: vmbr1wireguard srv01, Wireguard Clients |
| VPN Marcel |
SafeInCloud: vpn Marcel |
| OpenVPN / IPsec (geplant auf mxcore) |
Documents/Projekte/TOeV-Systeme/ANWENDUNGSREGISTER.md → vpn-hub (geplant) |
| Vivaldi VPN |
SafeInCloud: vivaldi vpn |
19. Guacamole (Remote-Desktop-Gateway)
| Aspekt |
Wert |
| URL |
https://nuclos.46.tos.zone/guacamole/, direkt http://192.168.47.21:8088/guacamole/ |
| Credentials-Datei |
~/.homenet-guacamole-credentials.env — Web-Login, Postgres-DB, alle Zielsystem-IPs und Ports |
| Projektordner |
Documents/Projekte/homenet46/guacamole/ |
Enthält auch: RDP-Ziel 192.168.47.240, SSH zu Proxmox/Synology/Pi, VNC zu Macs/Coolify2, Intel AMT, NanoKVM
20. Intel AMT / KVM-over-IP
| Gerät |
IP |
Credentials |
| Intel AMT (KVM) |
192.168.46.19:5900 (VNC), :16992 (Web) |
Documents/Projekte/vsrv01.toschke.de/zugang-intel-amt.txt — AMT-Web + VNC-Passwort |
| Lantronix Spider |
192.168.46.61 (HTTPS) |
~/.homenet-guacamole-credentials.env |
21. Cursor Agent / VNC LXC
Projekt: cursor-hsrv02-lxc4722-docker/
| Was |
Wert |
| VNC |
192.168.47.22:5901 (PW in .env → VNC_PASSWORD) |
| noVNC (Browser) |
http://192.168.47.22:6080/vnc.html |
| Worker-Metriken |
http://192.168.47.22:18080/metrics |
.env |
cursor-hsrv02-lxc4722-docker/.env — CURSOR_API_KEY, VNC_PASSWORD |
| SSH-Config |
cursor-hsrv02-lxc4722-docker/ssh/config |
22. Docker / Colima (lokal)
| Was |
Pfad |
| Docker-Config |
~/.docker/config.json (Context: colima, Creds-Store: desktop) |
| Colima-VM |
~/.colima/ |
| Colima SSH-Config |
~/.colima/ssh_config (Include in ~/.ssh/config) |
23. SSH & Shell
| Was |
Pfad |
| SSH-Config |
~/.ssh/config — Hosts: lave-toschke (.131), xpipe_bridge, Colima-Include |
| SSH-Keys |
~/.ssh/id_ed25519 / .pub |
| XPipe Bridge |
~/.xpipe/ssh_bridge/ |
| Zsh |
~/.zshrc (PATH für opencode, pipx), ~/.zprofile |
| Ansible |
~/.ansible/ (Galaxy-Cache, tmp) |
| Git |
~/.gitconfig, ~/.gitignore (nur Documents/Projekt/ getrackt) |
| Tool |
Konfiguration |
| Cursor CLI |
~/.cursor/cli-config.json (Permissions, Model) |
| Cursor Projekte / Chats |
~/.cursor/projects/ |
| Cursor Rules / Skills |
~/.cursor/skills-cursor/ |
| OpenCode |
~/.opencode/, ~/.opencode/bin, Backup ~/Backup_OpenCode/opencode.global.dat |
| Codex / Agent-Skills |
~/.codex/skills/ |
| Ollama |
~/.ollama/ |
| Claude |
~/.claude/, ~/.claude.json |
25. Webseiten & WordPress
| Projekt |
Credentials |
| WordPress toschke.de (MXCore-Stack) |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → WordPress |
| WordPress gruene-datteln.de |
SafeInCloud: neu gruene-datteln.de; Verdigado GCMS |
Hestia Control Panel (web.toschke.de:8083) |
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Hestia, plus SafeInCloud: USER - web.toschke.de |
| CloudPanel-Site-User (SFTP) |
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt CloudPanel-Websites |
| WordPress.com |
SafeInCloud: wordpress.com |
Selbsthilfegruppen (web.toschke.de) |
SafeInCloud: web.toschke.de |
26. Verein toschke.org Stack
Alle in Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md bzw. Documents/Projekt/Credentials/Server/toschke_ev_server.env:
| Dienst |
URL |
| Coolify |
http://192.168.46.84:8000 |
| Keycloak (SSO) |
https://auth.toschke.org |
| Nextcloud |
https://cloud.toschke.org |
| Mailman 3 |
https://lists.toschke.org |
| MailPiler |
https://archive.toschke.org |
| Mailcow |
https://mail.toschke.org |
27. SafeInCloud – Infrastruktur-Einträge (Kurzübersicht)
Alle folgenden Einträge sind nur in SafeInCloud und in keiner Projektdatei:
| Bereich |
SafeInCloud-Titel (Auswahl) |
| Proxmox |
srv01 - Proxmox, hsrv02 - Proxmox, ffov Proxmox, TOeV Proxmox, Praxis blech01 - Proxmox |
| FRITZ!Box |
fritz.box mahlerbox, ha FRITZ!Box 7690, PRX BMT Gast WLAN FRITZ!Box 5690 Pro |
| Synology |
Diskstation1, diskstation1, PRX-Diskstation, account.synology.com |
| Home Assistant |
Einstellungen – Home Assistant, Home Assistant Synology |
| Homematic |
35488.meine-homematic.de |
| Hetzner |
accounts.hetzner.com, Toschke e.V. accounts.hetzner.com, coolify-hetzner-token, hetzner dns home api, Hetzner Share |
| Coolify |
Coolify 47.179, [Coolify ADHS Autismus] Coolify |
| UniFi |
UniFi Network, account.ui.com |
| Mail |
admin mailcow UI, daniel@toschke.de mail.toschke.email, webmail.toschke.de, bernd@toschke.de Mailkonto |
| VPN |
vmbr1wireguard srv01, Wireguard Clients, vpn Marcel, vivaldi vpn |
| Easybell |
Cannock login.easybell.de, Eichen login.easybell.de, TN login.easybell.de, Trunking www.easybell.de |
| Domains |
Cloudflare, ccp.netcup.net, Domains - Toschke e.V. |
| Monitoring |
Uptime Kuma - Login, Checkmk Local site cmk, uptimerobot.com |
| Sonstige Infra |
Portainer, Portainer eu, Portainer Syno, akt. Login – Nginx Proxy Manager, CPS-Datensysteme |
28. Alle MXCore-Apps (Schnellreferenz)
Alle Details + Klartext-Passwörter: Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md
| Dienst |
URL |
Status |
| Authentik |
authentik.toschke.de |
produktiv |
| Paperless |
paperless.toschke.de |
produktiv |
| Tandoor |
tandoor.toschke.de |
produktiv |
| Joplin |
joplin.toschke.de |
produktiv |
| OpenVSCode |
openvcode.toschke.de |
teilweise |
| Obsidian LiveSync |
obsidian.toschke.de |
teilweise |
| Dockhand |
dockhand.toschke.de |
teilweise |
| Wekan |
wekan.toschke.de |
produktiv |
| Vikunja |
vikunja.toschke.de |
produktiv |
| HedgeDoc |
hedgedoc.toschke.de |
produktiv |
| Rallly |
rallly.toschke.de |
produktiv |
| WordPress |
wordpress.toschke.de |
produktiv |
| Nextcloud (Stack) |
nextcloud.toschke.de |
produktiv |
| OnlyOffice |
onlyoffice.toschke.de |
produktiv |
| Collabora |
collabora.toschke.de |
produktiv |
| Matrix Synapse |
matrix.toschke.de |
produktiv |
| Element |
messenger.toschke.de |
teilweise |
| Synapse-Admin |
admin.matrix.toschke.de |
produktiv |
| Mailman 3 |
mailman.toschke.de |
produktiv |
| mailpiler |
mailpiler.toschke.de |
teilweise |
| Nuclos |
nuclos.toschke.de |
teilweise |
| Zammad |
support.toschke.de |
produktiv |
| OpenProject |
projekt.toschke.de |
produktiv |
| XWiki |
wiki.toschke.de |
produktiv |
| RustDesk |
rustdesk.toschke.de |
teilweise |
| Jitsi |
bbb.toschke.de |
teilweise |
| Overleaf |
tex.toschke.de |
teilweise |
| Technitium DNS |
dns.toschke.de |
teilweise |
| Wolke (NC) |
wolke.toschke.de |
produktiv |
| Mailcow |
mail.toschke.de |
produktiv |
| CloudPanel |
mxcore.toschke.de |
produktiv |
29. Suche auf dem Mac
# Hostname in Projekt-Dokumentation
rg -i 'SUCHBEGRIFF' ~/Documents/Projekt ~/Documents/Projekte 2>/dev/null
# SafeInCloud-Export durchsuchen (nur Titel, keine Passwörter)
rg -o 'title="[^"]*SUCHBEGRIFF[^"]*"' ~/Downloads/SafeInCloud*.xml
# In ~/.homenet-guacamole-credentials.env nachsehen (Homelab-Geräte)
grep -i 'SUCHBEGRIFF' ~/.homenet-guacamole-credentials.env
# DNS klären
dig +short HOSTNAME A
# Auf dem Server suchen
ssh root@94.130.14.177 "grep -ri 'SUCHBEGRIFF' /opt/mxcore/.env /root/*credentials* 2>/dev/null"
30. Checkliste „Credential fehlt"
- SafeInCloud durchsuchen (Hostname, IP, Dienstname)
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md (toschke.org / Homelab)
~/.homenet-guacamole-credentials.env (LAN-Geräte, Guacamole-Ziele)
- Bei
*.toschke.de → srv01…/SICHERHEIT-ZUGAENGE-…md
- Bei
*.46.tos.zone → SafeInCloud + homenet-guacamole/PROJECT_STATE.md
- Bei SmartHome →
Credentials/SmartHome/project_credentials.json
- Bei DNS →
dns-api-tokens.env (lokal oder Server)
- Auf dem Server:
/opt/mxcore/.env, /root/credentials, Coolify-UI → Service-Env
- In Cursor-Chat-Verläufen: manchmal stehen Passwörter nur in früheren Agent-Transcripts
Netzwerk-Dokumentation (ohne Passwörter)
| Projekt |
Pfad |
Inhalt |
| Netzwerk-Konfigurationen |
Documents/Projekt/Netzwerk-Konfigurationen/ |
Inventar-Skripte, Rechenzentren |
| Proxmox-Inventur srv01 |
proxmox-inventory/srv01/ |
Netzwerk, Gäste, Storage, Backup-Zuordnung |
| DNS-ZONES App |
Documents/Projekte/DNS-ZONES/ |
DNS-Zonen-Verwaltungstool |
| TOeV-Systeme (Master-Doku) |
Documents/Projekte/TOeV-Systeme/ |
ANWENDUNGSREGISTER, ANWENDUNGSSTAND |
Änderungshistorie
| Datum |
Änderung |
| 2026-05-24 |
Erste Version; Nuclos-Zweiteilung dokumentiert |
| 2026-05-26 |
Massive Erweiterung: 30 Abschnitte, alle Server/Dienste/LAN-Geräte, SmartHome, Mail, SSO, DNS, VPN, Guacamole, SafeInCloud-Übersicht, MXCore-App-Liste, Suchbefehle |