Einstellungen & Credentials – Wo finde ich was?

Stand: 2026-05-26

Zweck: Schnell nachschlagen, wo Zugänge und Konfiguration liegen — ohne alles in einer Datei zu duplizieren.

Pfad dieser Datei: /Users/danieltoschke/EINSTELLUNGEN-UND-CREDENTIALS.md

Sicherheit: Viele verlinkte Dateien enthalten Klartext-Passwörter. Nicht committen, idealerweise chmod 600. Diese Übersicht enthält keine Passwörter, nur Verweise.

Inhaltsverzeichnis

  1. #schnell-nuclos-häufig-gesucht
  2. #1-passwort-manager
  3. #2-zentrale-projekt-credentials-homelab--toschkeorg
  4. #3-öffentlicher-server-srv01--mxcore-toschkede
  5. #4-monitoring-vm-vsrv01toschkede
  6. #5-homelab-netz-19216846023--46toszone
  7. #6-smarthome--homeassistant
  8. #7-mail-system-mailcow
  9. #8-wolke--nextcloud
  10. #9-sso--authentik--keycloak
  11. #10-dns-provider--api-tokens
  12. #11-hetzner-cloud--robot
  13. #12-fritzbox--netzwerk-hardware
  14. #13-synology-nas
  15. #14-proxmox-ve
  16. #15-coolify-alle-instanzen
  17. #16-semaphore--ansible
  18. #17-telegram-bot
  19. #18-vpn--wireguard
  20. #19-guacamole-remote-desktop-gateway
  21. #20-intel-amt--kvm-over-ip
  22. #21-cursor-agent--vnc-lxc
  23. #22-docker--colima-lokal
  24. #23-ssh--shell
  25. #24-ide--ki-tools
  26. #25-webseiten--wordpress
  27. #26-verein-toschkeorg-stack
  28. #27-safeincloud--infrastruktur-einträge-kurzübersicht
  29. #28-alle-mxcore-apps-schnellreferenz
  30. #29-suche-auf-dem-mac
  31. #30-checkliste-credential-fehlt

Schnell: Nuclos (häufig gesucht)

Es gibt zwei verschiedene „Nuclos"-Welten:

Hostname DNS IP Rolle Zugangsdaten
nuclos.toschke.de öffentlich 94.130.14.177 Nuclos ERP auf MXCore (Docker /opt/mxcore/nuclos/) Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Zeile Nuclos ERP
nuclos.46.tos.zone nur LAN 192.168.47.21 Coolify-Host im Heimnetz (Traefik, Semaphore, Guacamole) SafeInCloud → Eintrag nuclos.46.tos.zone (Login: nuclos)

Merksatz: nuclos.toschke.de = Internet / 177 · nuclos.46.tos.zone = LAN / 47.21


1. Passwort-Manager

Was Ort
SafeInCloud (Hauptquelle) App auf Mac / iOS — über 500 Einträge
XML-Exporte (Such-Backup) ~/Downloads/SafeInCloud.db_database_2026-05-13.xml
macOS Schlüsselbund „Schlüsselbundverwaltung" — WLAN, Zertifikate, App-Passwörter
Viele Dienste stehen nur in SafeInCloud, nicht in Projektdateien. Immer zuerst dort suchen.

2. Zentrale Projekt-Credentials (Homelab / toschke.org)

Hauptordner: Documents/Projekt/Credentials/

Datei Inhalt
Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md Sammelkopie: Semaphore (47.21 + Legacy 46.154), Telegram, toschke.org-Stack komplett (Coolify, Keycloak, Mailcow, Nextcloud, …), Hestia, DNS-Provider
Documents/Projekt/Credentials/Server/toschke_ev_server.env Kanonische .env — identische Daten wie in ZENTRALE, maschinenlesbar
Documents/Projekt/Credentials/SmartHome/project_credentials.json Coolify .22, Hetzner DNS, Technitium DNS, Proxmox API, HomeAssistant URLs
Documents/Projekt/Credentials/SmartHome/coolify_credentials.json Coolify .22 API-Token, User
Documents/Projekt/Credentials/SmartHome/proxmox_credentials.json Proxmox API-Token (root@pam!opencode)
Documents/Projekt/Credentials/README.md Regeln, Struktur, Schnellverweis
Documents/Projekt/Credentials/info.json Maschinenlesbare Metadaten

Duplikat (identischer Inhalt, älterer Pfad): Documents/Projekt/toschke_ev_server/credentials.env

Regel: Keine Passwörter in normalen Projektordnern — nur unter Credentials/ referenzieren.


3. Öffentlicher Server srv01 / mxcore (*.toschke.de)

Projekt: Documents/Projekte/srv01.toschke.de/cloudpanel/

Datei Inhalt
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md Vollinventar: alle ~30 MXCore-Apps (URLs + Login + Klartext-PW), Wolke-User, Mail, CloudPanel, API-Tokens, RP-SFTP-User
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/mxcore.env Lokale Kopie /opt/mxcore/.env
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/mxcore-docker-app-credentials.tsv TSV vom Server (/root/)
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env Cloudflare + Hetzner DNS API-Tokens
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/cp/authentik-mxcore.initial-credentials.txt Authentik-Bootstrap
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/cp/cloudpanel_reverse_proxy_sites.tsv RP-SFTP-User/Passwörter
Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/README.md scp-Befehle zum Synchronisieren vom Server

Auf dem Server (maßgeblich, per SSH root@94.130.14.177):

Server-Pfad Inhalt
/opt/mxcore/.env Master-Secrets aller Docker-Stacks
/root/mxcore-docker-app-credentials.tsv App-Logins
/root/authentik-mxcore.initial-credentials.txt IdP-Bootstrap
/root/cloudpanel_reverse_proxy_sites.tsv RP-Sites
/root/dns-api-tokens.env DNS-Provider-Tokens
/root/wolke-migrate-user-passwords.tsv Migrations-Passwörter Wolke
/root/mail-users-authentik-passwords.tsv Authentik-Sync Postfächer
/opt/mailcow-dockerized/mailcow.conf Mailcow DB/Redis/API

Übergreifende Doku (ohne Passwörter):

Datei Inhalt
Documents/Projekte/TOeV-Systeme/ANWENDUNGSREGISTER.md Master-App-Liste aller Dienste (mxcore + vsrv01 + srv01), Status, Compose-Pfade
Documents/Projekte/TOeV-Systeme/ANWENDUNGSSTAND.md Host-Architektur, Container-Übersicht, Mermaid-Diagramm

4. Monitoring-VM vsrv01.toschke.de

Aspekt Wert
IP 128.140.35.138
SSH ssh root@vsrv01.toschke.de (Key: ~/.ssh/id_ed25519)
Stack-Pfad /opt/toschke-modern
Hetzner-Konsole https://console.hetzner.com/projects/10005067/dashboard

Projekt: Documents/Projekte/vsrv01.toschke.de/

Datei Inhalt
Documents/Projekte/vsrv01.toschke.de/PROJECT_STATE.md Stand, DNS, TLS, offene Aufgaben
Documents/Projekte/vsrv01.toschke.de/zugangsdaten-zugangstoken.txt SSH-Keys, Hetzner API-Token (agents)
Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt Wolke CalDAV/CardDAV Sync, Authentik-Reset

Dienste auf vsrv01: Traefik, Uptime Kuma (up.vsrv01.toschke.de), Grafana (grafana.intern.toschke.org), Prometheus, PBS (pbs.vsrv01.toschke.de), Dockhand, Status-Seite


5. Homelab Netz 192.168.46.0/23 / *.46.tos.zone

Projekt: Documents/Projekte/homenet46/guacamole/

Datei Inhalt
Documents/Projekte/homenet46/guacamole/PROJECT_STATE.md IP-Inventar, Scan-Ergebnis, offene Aufgaben
Documents/Projekte/homenet46/guacamole/LAN-SCAN-192.168.46.0-23.md Nmap-Scan, 39 Hosts, 26 mit offenen Ports
Documents/Projekte/homenet46/guacamole/INVENTAR-FERNZUGRIFF-ZIELE.md SSH/RDP/VNC-Ziele

Wichtige LAN-IPs:

IP Rolle Credentials-Quelle
192.168.47.21 nuclos.46.tos.zone — Coolify, Traefik, Semaphore SafeInCloud
192.168.47.22 Zweiter Coolify-Host, VNC :5901, Technitium DNS :5380 SmartHome/project_credentials.json
192.168.47.72 Proxmox VE (:8006) SmartHome/proxmox_credentials.json
192.168.47.240 Windows AD / RDP :3389 (14WIN-APPS, Domain ev.toschke.de) SafeInCloud
192.168.47.131 LAVE (lave-toschke per SSH) ~/.ssh/config
192.168.46.70 Synology DISKSTATION1 SafeInCloud
192.168.46.50 Home Assistant (neu) SafeInCloud
192.168.46.31 Home Assistant (alt) SafeInCloud
192.168.46.10 FRITZ!Box 7690 SafeInCloud
192.168.46.19 Intel AMT (KVM-over-IP) zugang-intel-amt.txt
192.168.46.89 Raspberry Pi .homenet-guacamole-credentials.env
192.168.46.120 / .81 Macs (VNC :5900) .homenet-guacamole-credentials.env
192.168.46.61 Lantronix Spider Web-KVM .homenet-guacamole-credentials.env
192.168.46.125 NanoKVM (aktuell offline) .homenet-guacamole-credentials.env
192.168.46.91 Proxmox (lokal) SmartHome/proxmox_credentials.json

6. SmartHome / HomeAssistant

Projekt: Documents/Projekt/SmartHome/

Datei/Ordner Inhalt
Documents/Projekt/SmartHome/coolify_credentials.json = Kopie aus Credentials/SmartHome/
Documents/Projekt/SmartHome/project_credentials.json = Kopie, mit Coolify, DNS, Proxmox, HA-URLs
Documents/Projekt/SmartHome/proxmox_credentials.json = Kopie
Documents/Projekt/SmartHome/HomeAssistant/ REST-API-Skripte, Monitor
Documents/Projekt/SmartHome/Deconz/ ZigBee-Gateway
Documents/Projekt/SmartHome/Homematic/ CCU / HomeMatic IP
Documents/Projekt/SmartHome/dns-compose.yml Technitium DNS
Documents/Projekt/SmartHome/lxc_home-net.json LXC-Konfiguration

HomeAssistant: URLs http://192.168.46.50:8123 (neu), http://192.168.46.31:8123 (alt)

SafeInCloud: Eintrag Einstellungen – Home Assistant


7. Mail-System (Mailcow)

Aspekt Wert Credentials-Quelle
Admin-UI https://mail.toschke.de SafeInCloud; auf Server in /opt/mailcow-dockerized/mailcow.conf
Domains toschke.de, 4tn.de, toschke.email, … Mailcow-UI
App-Passwörter (Apple-Mail-Fix) SMTP für adhsautismus-vorstand@4tn.de, toschke@duese.ping.de Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt App-Passwörter
Authentik-Sync Postfach-PWs für SSO Server: /root/mail-users-authentik-passwords.tsv
SOGo Webmail webmail.toschke.de Postfach-Passwort oder SSO

8. Wolke / Nextcloud

Es gibt zwei getrennte Nextcloud-Instanzen:

Instanz URL Compose-Pfad Credentials
Wolke (Produktion) wolke.toschke.de /srv/wolke/ auf mxcore Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt Wolke (alle User + Passwörter)
Nextcloud (MXCore-Stack) nextcloud.toschke.de /opt/mxcore/nextcloud/ Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 4

CalDAV/CardDAV-Sync (Mac): Anleitung in Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt


9. SSO / Authentik / Keycloak

System URL Credentials
Authentik (MXCore-IdP) https://authentik.toschke.de Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md — akadmin
Authentik Passwort-Reset (daniel) — Documents/Projekte/vsrv01.toschke.de/wollke-mail-sync-sso.txt
Keycloak (toschke.org) https://auth.toschke.org Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Keycloak
OAuth-Secrets (OIDC) pro App in /opt/mxcore/.env Server / mxcore.env lokal

10. DNS-Provider & API-Tokens

Provider Domains Credentials
Hetzner Cloud DNS toschke.de, tos.zone, *.vsrv01.toschke.de Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env (HETZNER_DNS_API_TOKEN)
Cloudflare toschke.org, *.intern.toschke.org Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/dns-api-tokens.env (CLOUDFLARE_API_TOKEN); SafeInCloud: Cloudflare
Technitium DNS (intern, LAN) 46.tos.zone http://192.168.47.22:5380 — Documents/Projekt/Credentials/SmartHome/project_credentials.json; MXCore: dns.toschke.de — Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md

DNS-Skripte: operations/scripts/source-dns-tokens.sh, cloudflare-dns-migrate-ips.py, hetzner-cloud-dns-migrate.py


11. Hetzner Cloud & Robot

Konto Credentials
Hetzner Robot (Dedicated srv01) SafeInCloud: robot.your-server.de, FFOV Hetzner Robot, srv01 - Proxmox
Hetzner Cloud (vsrv01 VM, DNS) SafeInCloud: accounts.hetzner.com, Toschke e.V. accounts.hetzner.com
Hetzner Cloud API (vsrv01) Documents/Projekte/vsrv01.toschke.de/zugangsdaten-zugangstoken.txt
Hetzner Cloud API (Coolify) SafeInCloud: coolify-hetzner-token
Storage Box / Share SafeInCloud: Hetzner Share, FFOV Storage Box; .env auf vsrv01 (STORAGESHARE_*)

12. FRITZ!Box / Netzwerk-Hardware

Gerät IP Credentials
FRITZ!Box 7690 (Haupt-Gateway) 192.168.46.10 SafeInCloud: fritz.box mahlerbox, ha FRITZ!Box 7690
FRITZ!Box 5690 Pro (Praxis) — SafeInCloud: PRX BMT Gast WLAN FRITZ!Box 5690 Pro
MyFRITZ sso.myfritz.net SafeInCloud: www.myfritz.net, ffov sso www.myfritz.net
UniFi Network 192.168.46.123 / 46ubnt.toschke.eu SafeInCloud: UniFi Network
EAP (TP-Link Access Point) — SafeInCloud: EAP Cannockstr.

13. Synology NAS

Gerät IP Credentials
Diskstation1 (Haupt-NAS) 192.168.46.70 SafeInCloud: Diskstation1 - Synology DiskStation, diskstation1
PRX-Diskstation (Praxis-NAS) — SafeInCloud: PRX-Diskstation - Synology NAS
Synology-Konto account.synology.com SafeInCloud
QuickConnect toschke46.de8.quickconnect.to SafeInCloud

14. Proxmox VE

Instanz IP / URL Credentials
srv01 (Hetzner Dedicated) 94.130.14.172:8006 SafeInCloud: srv01 - Proxmox Virtual Environment, hetzn srv01
Homelab (hsrv02) 192.168.47.72:8006 SafeInCloud: hsrv02 - Proxmox Virtual Environment
Homelab alt 192.168.46.91:8006 Documents/Projekt/Credentials/SmartHome/proxmox_credentials.json — API-Token root@pam!opencode
Praxis — SafeInCloud: Praxis blech01 - Proxmox Virtual Environment
proxmox1.toschke.org (alt) — SafeInCloud

WireGuard auf srv01: SafeInCloud: vmbr1wireguard srv01


15. Coolify (alle Instanzen)

Instanz URL Credentials
Homelab .21 http://192.168.47.21:8000/, https://coolify.46.tos.zone SafeInCloud: Coolify 47.179
Homelab .22 http://192.168.47.22:8000/ Documents/Projekt/Credentials/SmartHome/project_credentials.json, SafeInCloud
toschke.org (.84) http://192.168.46.84:8000/ Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Coolify
ADHS Autismus — SafeInCloud: [Coolify ADHS Autismus] Coolify

Coolify-Anleitungen: Documents/Projekt/toschke_ev_server/coolify_anleitung.log


16. Semaphore / Ansible

Instanz URL Credentials
Aktuell (Coolify .21) http://192.168.47.21:3000, https://ansible.46.tos.zone Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 1
Legacy (LXC .154) http://192.168.46.154:3000 Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 2; auch Documents/Projekt/ansible-semaphore/CREDENTIALS.md

Compose lokale Orchestration: Documents/Projekt/orchestration-coolify/docker/.env

Playbooks/Stacks: Documents/Projekt/toschke_ev_server/compose/ (mailcow, keycloak, nextcloud, joplin, …)


17. Telegram Bot

Feld Wert Quelle
Bot @toschke_bot Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Abschnitt 3
Token in ZENTRALE auch Documents/Projekt/bot-projekte/telegram_chats.md
Monitoring-Gruppe -1002166598578 telegram_chats.md
Semaphore-Thread 13526 telegram_chats.md

18. VPN / WireGuard

System Credentials
WireGuard (srv01 vmbr1) SafeInCloud: vmbr1wireguard srv01, Wireguard Clients
VPN Marcel SafeInCloud: vpn Marcel
OpenVPN / IPsec (geplant auf mxcore) Documents/Projekte/TOeV-Systeme/ANWENDUNGSREGISTER.md → vpn-hub (geplant)
Vivaldi VPN SafeInCloud: vivaldi vpn

19. Guacamole (Remote-Desktop-Gateway)

Aspekt Wert
URL https://nuclos.46.tos.zone/guacamole/, direkt http://192.168.47.21:8088/guacamole/
Credentials-Datei ~/.homenet-guacamole-credentials.env — Web-Login, Postgres-DB, alle Zielsystem-IPs und Ports
Projektordner Documents/Projekte/homenet46/guacamole/

Enthält auch: RDP-Ziel 192.168.47.240, SSH zu Proxmox/Synology/Pi, VNC zu Macs/Coolify2, Intel AMT, NanoKVM


20. Intel AMT / KVM-over-IP

Gerät IP Credentials
Intel AMT (KVM) 192.168.46.19:5900 (VNC), :16992 (Web) Documents/Projekte/vsrv01.toschke.de/zugang-intel-amt.txt — AMT-Web + VNC-Passwort
Lantronix Spider 192.168.46.61 (HTTPS) ~/.homenet-guacamole-credentials.env

21. Cursor Agent / VNC LXC

Projekt: cursor-hsrv02-lxc4722-docker/

Was Wert
VNC 192.168.47.22:5901 (PW in .env → VNC_PASSWORD)
noVNC (Browser) http://192.168.47.22:6080/vnc.html
Worker-Metriken http://192.168.47.22:18080/metrics
.env cursor-hsrv02-lxc4722-docker/.env — CURSOR_API_KEY, VNC_PASSWORD
SSH-Config cursor-hsrv02-lxc4722-docker/ssh/config

22. Docker / Colima (lokal)

Was Pfad
Docker-Config ~/.docker/config.json (Context: colima, Creds-Store: desktop)
Colima-VM ~/.colima/
Colima SSH-Config ~/.colima/ssh_config (Include in ~/.ssh/config)

23. SSH & Shell

Was Pfad
SSH-Config ~/.ssh/config — Hosts: lave-toschke (.131), xpipe_bridge, Colima-Include
SSH-Keys ~/.ssh/id_ed25519 / .pub
XPipe Bridge ~/.xpipe/ssh_bridge/
Zsh ~/.zshrc (PATH für opencode, pipx), ~/.zprofile
Ansible ~/.ansible/ (Galaxy-Cache, tmp)
Git ~/.gitconfig, ~/.gitignore (nur Documents/Projekt/ getrackt)

24. IDE / KI-Tools

Tool Konfiguration
Cursor CLI ~/.cursor/cli-config.json (Permissions, Model)
Cursor Projekte / Chats ~/.cursor/projects/
Cursor Rules / Skills ~/.cursor/skills-cursor/
OpenCode ~/.opencode/, ~/.opencode/bin, Backup ~/Backup_OpenCode/opencode.global.dat
Codex / Agent-Skills ~/.codex/skills/
Ollama ~/.ollama/
Claude ~/.claude/, ~/.claude.json

25. Webseiten & WordPress

Projekt Credentials
WordPress toschke.de (MXCore-Stack) Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → WordPress
WordPress gruene-datteln.de SafeInCloud: neu gruene-datteln.de; Verdigado GCMS
Hestia Control Panel (web.toschke.de:8083) Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md → Hestia, plus SafeInCloud: USER - web.toschke.de
CloudPanel-Site-User (SFTP) Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md → Abschnitt CloudPanel-Websites
WordPress.com SafeInCloud: wordpress.com
Selbsthilfegruppen (web.toschke.de) SafeInCloud: web.toschke.de

26. Verein toschke.org Stack

Alle in Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md bzw. Documents/Projekt/Credentials/Server/toschke_ev_server.env:

Dienst URL
Coolify http://192.168.46.84:8000
Keycloak (SSO) https://auth.toschke.org
Nextcloud https://cloud.toschke.org
Mailman 3 https://lists.toschke.org
MailPiler https://archive.toschke.org
Mailcow https://mail.toschke.org

27. SafeInCloud – Infrastruktur-Einträge (Kurzübersicht)

Alle folgenden Einträge sind nur in SafeInCloud und in keiner Projektdatei:

Bereich SafeInCloud-Titel (Auswahl)
Proxmox srv01 - Proxmox, hsrv02 - Proxmox, ffov Proxmox, TOeV Proxmox, Praxis blech01 - Proxmox
FRITZ!Box fritz.box mahlerbox, ha FRITZ!Box 7690, PRX BMT Gast WLAN FRITZ!Box 5690 Pro
Synology Diskstation1, diskstation1, PRX-Diskstation, account.synology.com
Home Assistant Einstellungen – Home Assistant, Home Assistant Synology
Homematic 35488.meine-homematic.de
Hetzner accounts.hetzner.com, Toschke e.V. accounts.hetzner.com, coolify-hetzner-token, hetzner dns home api, Hetzner Share
Coolify Coolify 47.179, [Coolify ADHS Autismus] Coolify
UniFi UniFi Network, account.ui.com
Mail admin mailcow UI, daniel@toschke.de mail.toschke.email, webmail.toschke.de, bernd@toschke.de Mailkonto
VPN vmbr1wireguard srv01, Wireguard Clients, vpn Marcel, vivaldi vpn
Easybell Cannock login.easybell.de, Eichen login.easybell.de, TN login.easybell.de, Trunking www.easybell.de
Domains Cloudflare, ccp.netcup.net, Domains - Toschke e.V.
Monitoring Uptime Kuma - Login, Checkmk Local site cmk, uptimerobot.com
Sonstige Infra Portainer, Portainer eu, Portainer Syno, akt. Login – Nginx Proxy Manager, CPS-Datensysteme

28. Alle MXCore-Apps (Schnellreferenz)

Alle Details + Klartext-Passwörter: Documents/Projekte/srv01.toschke.de/cloudpanel/operations/credentials/SICHERHEIT-ZUGAENGE-UND-INITIALPASSWOERTER.md

Dienst URL Status
Authentik authentik.toschke.de produktiv
Paperless paperless.toschke.de produktiv
Tandoor tandoor.toschke.de produktiv
Joplin joplin.toschke.de produktiv
OpenVSCode openvcode.toschke.de teilweise
Obsidian LiveSync obsidian.toschke.de teilweise
Dockhand dockhand.toschke.de teilweise
Wekan wekan.toschke.de produktiv
Vikunja vikunja.toschke.de produktiv
HedgeDoc hedgedoc.toschke.de produktiv
Rallly rallly.toschke.de produktiv
WordPress wordpress.toschke.de produktiv
Nextcloud (Stack) nextcloud.toschke.de produktiv
OnlyOffice onlyoffice.toschke.de produktiv
Collabora collabora.toschke.de produktiv
Matrix Synapse matrix.toschke.de produktiv
Element messenger.toschke.de teilweise
Synapse-Admin admin.matrix.toschke.de produktiv
Mailman 3 mailman.toschke.de produktiv
mailpiler mailpiler.toschke.de teilweise
Nuclos nuclos.toschke.de teilweise
Zammad support.toschke.de produktiv
OpenProject projekt.toschke.de produktiv
XWiki wiki.toschke.de produktiv
RustDesk rustdesk.toschke.de teilweise
Jitsi bbb.toschke.de teilweise
Overleaf tex.toschke.de teilweise
Technitium DNS dns.toschke.de teilweise
Wolke (NC) wolke.toschke.de produktiv
Mailcow mail.toschke.de produktiv
CloudPanel mxcore.toschke.de produktiv

29. Suche auf dem Mac


# Hostname in Projekt-Dokumentation
rg -i 'SUCHBEGRIFF' ~/Documents/Projekt ~/Documents/Projekte 2>/dev/null

# SafeInCloud-Export durchsuchen (nur Titel, keine Passwörter)
rg -o 'title="[^"]*SUCHBEGRIFF[^"]*"' ~/Downloads/SafeInCloud*.xml

# In ~/.homenet-guacamole-credentials.env nachsehen (Homelab-Geräte)
grep -i 'SUCHBEGRIFF' ~/.homenet-guacamole-credentials.env

# DNS klären
dig +short HOSTNAME A

# Auf dem Server suchen
ssh root@94.130.14.177 "grep -ri 'SUCHBEGRIFF' /opt/mxcore/.env /root/*credentials* 2>/dev/null"

30. Checkliste „Credential fehlt"

  1. SafeInCloud durchsuchen (Hostname, IP, Dienstname)
  2. Documents/Projekt/Credentials/ZENTRALE_CREDENTIALS.md (toschke.org / Homelab)
  3. ~/.homenet-guacamole-credentials.env (LAN-Geräte, Guacamole-Ziele)
  4. Bei *.toschke.de → srv01…/SICHERHEIT-ZUGAENGE-…md
  5. Bei *.46.tos.zone → SafeInCloud + homenet-guacamole/PROJECT_STATE.md
  6. Bei SmartHome → Credentials/SmartHome/project_credentials.json
  7. Bei DNS → dns-api-tokens.env (lokal oder Server)
  8. Auf dem Server: /opt/mxcore/.env, /root/credentials, Coolify-UI → Service-Env
  9. In Cursor-Chat-Verläufen: manchmal stehen Passwörter nur in früheren Agent-Transcripts

Netzwerk-Dokumentation (ohne Passwörter)

Projekt Pfad Inhalt
Netzwerk-Konfigurationen Documents/Projekt/Netzwerk-Konfigurationen/ Inventar-Skripte, Rechenzentren
Proxmox-Inventur srv01 proxmox-inventory/srv01/ Netzwerk, Gäste, Storage, Backup-Zuordnung
DNS-ZONES App Documents/Projekte/DNS-ZONES/ DNS-Zonen-Verwaltungstool
TOeV-Systeme (Master-Doku) Documents/Projekte/TOeV-Systeme/ ANWENDUNGSREGISTER, ANWENDUNGSSTAND

Änderungshistorie

Datum Änderung
2026-05-24 Erste Version; Nuclos-Zweiteilung dokumentiert
2026-05-26 Massive Erweiterung: 30 Abschnitte, alle Server/Dienste/LAN-Geräte, SmartHome, Mail, SSO, DNS, VPN, Guacamole, SafeInCloud-Übersicht, MXCore-App-Liste, Suchbefehle