Donation build
Firewheel STEM Institute · Chandler, AZ · donated by CVS Health

Firewheel Server

A decommissioned Dell PowerEdge R640, reinstalled with Ubuntu Server 26.04.1 LTS and set up as a shared AI workspace for Firewheel's mentors and students. Chad installs it on site.

Pre-install: hardware not yet released Install rehearsed twice on a VM Target: October 2026
HardwareDell PowerEdge R6401U, 14th generation, dual-socket Intel Xeon Scalable, iDRAC9
Operating systemUbuntu Server 26.04.1 LTS"Resolute Raccoon". Free security updates to April 2031, no account or token
Who uses itMentors, with students alongsideEach mentor has their own Claude Code and account (18+). Students hold no accounts
UpkeepNone scheduledPatches itself and reboots at 04:00. A failed disk shows as an amber light
The rule every choice follows No license, no subscription, no prolonged maintenance.

Firewheel has no sysadmin. Install once, walk away, still working in three years. If an option needs someone to tend it, it is the wrong option here, even when it is technically better.

What runs on the box

The stack, from metal to people

Each layer runs on the one below it. Solid boxes ran end to end in the rehearsal on a real Ubuntu 26.04.1 install. Dashed boxes are designed but not fully built; they are covered in the AI brain section below.

Peoplewho touches it, and how
MentorsSSH in with a key. Own Linux user, own Claude account
StudentsWork alongside a mentor. No accounts, under 18
Firewheel staffCheck health in a browser through Cockpit
Agentper mentor
Claude CodeAnthropic's native installer in each mentor's home, so every copy updates itself. Added with add-mentor.sh
MCP tools wired inCrawl4AI (read a page) and Firecrawl (search the web), both connected per mentor
Servicesall bound to 127.0.0.1
Firecrawl :3002Self-hosted search. 5 containers from pinned images
Crawl4AIPage reader in a Python venv, one shared Chromium in /opt/ms-playwright
Qdrant :6333Vector store, running and empty until ingest exists
BRAIN dashboard :8787Stack and access lights, graph rebuilt nightly at 03:30
Access probesystemd timer every 15 min. Watches disk, reboots, updates, SSH, firewall
Runtimesno third-party repos except Docker
Docker Engine 29.8From Docker's own resolute repo, Compose v5.5
Node.js 22.22In Ubuntu main. Runs the Firecrawl MCP through npx
Python 3.14Ships with 26.04. Crawl4AI, probe, dashboard
Operating systemUbuntu Server 26.04.1 LTS
ext4 on LVMRoot volume grown to the full disk at install
Auto-patchingunattended-upgrades, reboot at 04:00
OpenSSH :22Keys only, passwords off
ufwDefault deny. LAN may reach 22 and 9090
Cockpit :9090Health page for staff
HardwareDell PowerEdge R640
PERC hardware RAIDRAID 1 (2 drives) or RAID 10 (4+)
iDRAC9Hardware page and drive health. Express is fine
Dual PSURedundant if both are present
BIOSAC Power Recovery = On. No setup password
Rehearsed and workingDesigned, not fully built
Source: install/stack.json, rehearsal run 2
How it is reached

Network and access

Only two doors face the LAN. Everything else listens on the box itself. Nothing faces the internet: no port forwarding, no dynamic DNS.

Network diagram: LAN devices reach SSH and Cockpit through ufw; services are localhost only; outbound internet only Internet · outbound only Anthropic (Claude) · web pages for search and scrape · Ubuntu and Docker updates Firewheel LAN DHCP reservation keeps the address fixed Mentor laptop SSH key, Claude login Staff browser Cockpit, Linux password Anyone on the Wi-Fi reaches nothing else ufw firewheel · R640 · Ubuntu 26.04.1 OpenSSH :22 keys only Cockpit :9090 health page Claude Code one per mentor, runs in their SSH session 127.0.0.1 only Firecrawl :3002 search API, 5 Docker containers Crawl4AI stdio MCP page reader, shared Chromium Qdrant :6333 vector store for the data layer BRAIN dashboard :8787 no login, so reached by SSH tunnel Any other port: no path HTTPS out iDRAC9 port own cable, own address
Docker-published ports go around ufw. The rehearsal proved it: Qdrant answered from the LAN with no firewall rule. So every container binds to 127.0.0.1, and the only LAN-facing services are SSH and Cockpit. The iDRAC hardware page has its own network port and ideally its own wall drop.
The machine

Dell PowerEdge R640

Launched in 2017. Dell's 14th-generation 1U server: dual-socket Intel Xeon Scalable (Skylake or Cascade Lake), up to 24 DIMMs, iDRAC9. For this workload it is comfortably overqualified. Claude's compute runs at Anthropic, so the box needs a shell, RAM for editors and containers, and a network.

Front, schematic
Front view of the R640: control panels at each end and up to ten drive bays STATUS 0 1 2 3 4 5 6 7 8 9 POWER · USB · VGA Status LEDs, pull-out service tag Drive bays: 4 × 3.5″, 8 × 2.5″ or 10 × 2.5″, set by the backplane Example: amber = disk failed Power button, USB, VGA, iDRAC direct port
Rear, schematic
Rear view of the R640: PCIe slots, management ports, network daughter card and two power supplies PCIe SLOT 1 NETWORK DAUGHTER CARD PCIe SLOT 2 / 3 PSU 1 PSU 2 iDRAC port, USB, VGA, serial One of four cards. Two have no RJ45 port and cannot plug into an ordinary switch Keep empty: third-party cards force the fans to a loud fixed speed Two supplies for redundancy. 750 W Titanium needs 200-240 V
Schematic. Positions are approximate, not a port map. The real layout gets confirmed from the machine on install day.
Verified factValue
Form factor1U, 42.8 mm high, 482 mm wide at the rack ears
Depth769.66 mm body · 808.51 mm to PSU handles
CPU sockets2 × Intel Xeon Scalable
Memory slots24 DIMMs
ManagementiDRAC9, Express or Enterprise
DriversAll in the Linux kernel: megaraid_sas, igb / bnx2x, ast
Dell's Ubuntu matrixValidated up to 22.04. Dell stopped testing 14G there, which applies to 24.04 and 26.04 alike
GPUUp to 3 single-width cards (T4 class). Not used: no local AI models
End of lifeNo Dell date published. Firmware stays free without a contract
Power supplyInput voltage
495 W Platinum100-240 V, autoranging
750 W Platinum100-240 V, autoranging
750 W Titanium200-240 V only. Will not run on a standard 120 V outlet
1100 W Platinum100-240 V, autoranging
1600 W Platinum100-240 V, autoranging
Running cost, estimated
Real draw, 24/7150-350 W
Electricity per yearabout $250-450
Replace with the real number from the iDRAC power readout once it is running.
Noise, by configurationCPUIdleWorkingScale 0-50 dBA
Minimum1 × Bronze 3104, 85 W35 dBA37 dBA
Typical2 × Gold 5120, 105 W36 dBA39 dBA
Feature rich2 × Gold 6142, 150 W39 dBA46 dBA
Dell, 14G Acoustical Performance, 2018. Blue bar idle, amber bar working. Every power-on runs the fans at 100% for about 30 seconds. Dell calls the minimum build "quiet enough for typical office environment."

Confirm on install day

The exact configuration of this unit is not known yet. These get read off the machine itself. The first three can each stop the install if they go the wrong way.

Power supply model can block

Read the PSU label. 750 W Titanium needs a 208/240 V circuit. Also check that both supplies are present.

Drives and caddies can block

Are drives included, with caddies? Empty bays need blanks, or airflow suffers and the fans get louder.

Network daughter card can block

4 × 10 GbE SFP+ and 2 × 25 GbE have no RJ45. Fix is a ~$30 PCIe gigabit card.

CPU and RAM

Model, socket count, DIMM count. CPU sets power, heat and noise.

PERC controller

H730P / H740P is ideal. H330 has no cache and weak RAID 5/6, but RAID 1 or 10 is fine on it.

BOSS card

If present, the OS goes on its M.2 pair and every front bay holds data. Reinstalls never touch the data.

Lockdown and passwords

No BIOS setup password and no iDRAC System Lockdown. Lockdown plus lost iDRAC credentials is the one true brick.

Rails, bezel, cords

Rails and C13/C14 power cords, included or not.

The room at Firewheel

Space

A rack needs about a metre of depth. Without one, a shelf that carries the full depth, not two corners.

Cooling

Air-conditioned. A sealed closet in a Chandler summer will shut it down.

Power

A 120 V circuit that can carry it. A UPS is worth considering.

Network

A wired drop, ideally two so iDRAC gets its own.

How it gets built

Install day, in order

Everything after the Ubuntu installer is two scripts, both safe to re-run. Rehearsed from a blank disk to a clean unattended reboot.

  1. Before the day

    • Download ubuntu-26.04.1-live-server-amd64.iso and check it against SHA256SUMS
    • Write the stick with Rufus: GPT, UEFI (non-CSM)
    • Make 8 git bundles: the 6 Firewheel repos plus claude-toolkit and ai-os-brain. Bundles, never folder copies: Windows line endings make every file look modified on Linux
  2. BIOS and firmware

    • F2 → System BIOS → System Security → AC Power Recovery = On, so it powers back up after an outage
    • One pass of every BIOS, iDRAC, PERC and NIC update for the service tag. Then stop
    • Create the PERC virtual disk (RAID 1 or 10). Without it the Ubuntu installer shows zero disks
  3. Ubuntu installer

    • F11 → boot the USB under UEFI. Choose Ubuntu Server (not minimized)
    • Storage: use the whole disk with LVM, then grow ubuntu-lv to the max. The default gives root half the disk, capped at 100 GB. Delete the old size before typing the new one
    • Name firewheel, user fwadmin. Skip Ubuntu Pro. Tick "Install OpenSSH server", which is off by default. No snaps
  4. First boot

    ssh-copy-id fwadmin@<box-ip>
    git clone /media/usb/firewheel-server.bundle /srv/firewheel/firewheel-server
  5. Run firewheel-install.sh inside tmux

    It downloads several GB and refuses to start outside tmux, because a dropped SSH session killed a build in the rehearsal.

    1Ubuntu packages
    204:00 auto-patch reboot
    3SSH keys only
    4Firewall: 22 and 9090
    5Docker Engine
    6Repos from the bundles
    7Qdrant
    8Crawl4AI, shared browser
    9Firecrawl, pinned images
    10Probe and dashboard services
  6. Add each mentor

    sudo bash install/add-mentor.sh <username> <their-key.pub>

    Makes a key-only account, installs their own Claude Code and connects Crawl4AI and Firecrawl. They sign in to Claude the first time they run claude.

  7. Reboot and walk away

    Reboot once without touching anything, then confirm everything came back on its own with sudo python3 install/access-probe.py --print. Fill in and tape up the card on the closet door.

Proof it works

Rehearsal on a VM, 30 September 2026

Two full installs in VirtualBox from the exact ISO, before the hardware arrives. Anything Dell-specific (PERC, iDRAC, BIOS, PSU, NIC) waits for the real box.

33findings, all fixed and re-verified
13 / 0probe checks green / red after an unattended reboot
8 of 8services back on their own after reboot
2.9 minFirecrawl from pinned images, vs 19.5 min building from source

The 9 yellow checks are the wiki brains and repos waiting for a Firewheel GitHub org. Two test mentors were added, each with a self-updating Claude Code and both web tools connected.

Why it is built this way

Decisions that keep it maintenance-free

Ubuntu 26.04.1, not 24.04

Tested: Docker publishes for it, and Node 22 is in Ubuntu's own repos. Four more years of free updates than 24.04's window started with.

No Ubuntu Pro or Livepatch

Both attach a token to the machine that can quietly lapse.

Reboot at 04:00 for patches

Kernel fixes need a reboot without Livepatch. Nobody is logged in at 4 AM. This one setting is most of the no-maintenance story.

Hardware RAID, ext4

The PERC handles disks with no software to understand. Boring is the point.

Amber light, not email alerts

Email alerting needs an SMTP relay and a mailbox someone maintains. The drive light and a phone number on the wall will still work in three years.

SSH keys only

Nothing expires, nothing to reset. The script skips this step if your key is not on the box yet, so you cannot lock yourself out.

Everything on 127.0.0.1

Docker ports ignore the firewall. Binding to localhost keeps the vector store and search off the Wi-Fi.

Claude Code per mentor

A global npm install is owned by root and never updates. Per-user copies update themselves, and no API key sits in a shared file.

Pinned Firecrawl images

A re-run in two years rebuilds the exact set that was tested, not whatever upstream shipped that week.

Not installed on purpose

Kubernetes, Proxmox, VMware, Swarm, a monitoring stack, configuration management. Each one is something a person has to understand later.

Still open

What is not settled yet

Blocker

Firewheel GitHub organisation. The six repos have no remote on purpose: brains on a personal account would be a loan, not a donation. Fredi or Glen creates the org with Chad as admin. Until then there is no off-box backup and no cross-brain querying.

Decide

What the four project brains are for. They are numbered, not named, until the server's use is discussed with Firewheel.

Decide

How mentors see the BRAIN dashboard. Today it is an SSH tunnel. Opening it to the LAN needs a firewall rule, and the page has no login.

Decide

Claude seats. Firewheel qualifies for Anthropic's nonprofit rate. The form needs a Firewheel staff email and title, so Firewheel submits it.

Untested

The 04:00 reboot actually firing, a staff member logging in to Cockpit, and RAG ingest, which is not built yet.

Memory · designed, partly built

AI brain and data layer

Two kinds of memory, for two kinds of question. The AI brain is a small set of pages Claude writes and keeps up to date, so it can answer "where are we and why" in seconds. The data layer holds every manual, rulebook and web page in full, so Claude can find the exact passage. Claude checks the brain first and the data layer second.

How material flows in, and how a question gets answered
Sources feed two lanes: the AI brain, curated by Claude, and the data layer, a searchable vector store. Claude Code reads the brain first, then searches the data layer. Sources Manuals, rulebooks PDFs, game manuals Datasheets, specs parts, sensors, boards Web pages via Crawl4AI, Firecrawl Team notes, code decisions, build logs AI brain · curated pages raw/ sources as added, never edited Claude the librarian: ingest and lint wiki/ index, topic pages, sources, log Plain markdown in git: every change has a history. Opens in Obsidian or any editor. Data layer · full-text search Chunk split into passages Embed on CPU local model, no key Qdrant one set per project catalog.db (SQLite) one row per document: what we have, what is missing Ask Mentor + students in a project folder Claude Code 1 · reads the brain index 2 · searches Qdrant 3 · answers, citing the source Purple arrow runs both ways: a reusable answer is saved back as a brain page.
Qdrant and catalog.db are rebuilt from the raw files at any time, so they never need a backup. Only raw/ and wiki/ hold anything irreplaceable, and both are plain files in git.
AI brainData layer
Answers"Where is this project, what did we decide, and why?""What exactly does the manual say about X?"
HoldsA few dozen to a few hundred short pages per projectEvery source document in full, thousands of passages
Who writes itClaude, from what people put in raw/The ingest script, with no judgement involved
How it finds thingsReads the index, follows links between pagesSearches by meaning, not exact words
Where it lives/srv/firewheel/firewheel-*-wikiQdrant in Docker on 127.0.0.1:6333, plus catalog.db
If it is lostRestore from git. Pushed off the box once the Firewheel org existsRe-run ingest over raw/. Nothing is lost
The five brains
One master brain lists four project brains. Each brain is sealed and cannot read the others. A proposed local tool would let Claude search across all of them. Master brain · firewheel-wiki directory of projects, server how-to, shared conventions built, committed, no remote yet lists them, cannot read them Project 1 brain firewheel-project-1-wiki raw/ · wiki/ · outputs/ subject not assigned yet Project 2 brain firewheel-project-2-wiki raw/ · wiki/ · outputs/ subject not assigned yet Project 3 brain firewheel-project-3-wiki raw/ · wiki/ · outputs/ subject not assigned yet Project 4 brain firewheel-project-4-wiki raw/ · wiki/ · outputs/ subject not assigned yet Cross-brain search, proposed: a small tool on the box that reads every brain folder directly, so Claude can answer "how are all four projects doing?"
Each brain is sealed on purpose: it has its own folder, its own history and its own sources, so every claim traces back to a file that brain holds. When two projects need the same manual, it is copied into both. Four is a starting guess, not a limit; a new brain takes one command.

Ingest

Someone drops a file in a brain's raw/ folder. Claude reads it, says what it learned, writes a source page, updates every topic page it touches, then updates the index and log. The same file also goes through the data layer's chunk-and-embed step.

Ask

Claude opens the brain's index first and follows only the pages it points to. For detail it searches Qdrant. Every answer names the source file behind it. A good answer can be saved as a new page.

Lint

On request, Claude reports broken links, orphan pages, claims with no source and contradictions between sources. It reports and does not auto-fix, so a person sees each change.

Embeddings run on the box

A small local model (all-MiniLM-L6-v2 on ONNX Runtime) turns text into vectors on the CPU. It needs no API key or account, so there is nothing to renew. The same setup answers searches in about 0.1 s on Chad's own video-transcript corpus. A hosted embedding service would mean a key and a bill.

Qdrant is a cache, not the record

The record is the files in raw/. If the vector store breaks, delete it and run ingest again. Nobody has to back it up or repair it.

catalog.db for "what do we have"

Inventory questions get an exact answer from one SQLite query, not a guess from a folder listing.

Brains are plain files in git

No database to administer. Students can read the pages in any editor. Git history shows who changed what.

Off-box backup waits on the org

Once Firewheel's GitHub org exists, each brain pushes to it nightly with no one involved. Until then, the brains live only on the server.

PieceState
Master brain and four project brainsBuilt Scaffolded and committed, local git, no remote
Qdrant vector storeBuilt Installed by the script, running on 127.0.0.1, empty
Chunk-and-embed ingest scriptTo build Same pattern as Chad's ICT corpus, with the local CPU model
catalog.dbTo build Same pattern as the ICT corpus catalog
Search tool for Claude Code (Qdrant)To build An MCP server per mentor, like Crawl4AI is wired in today
Cross-brain searchProposed Local tool reading the brain folders. Chad's own version reads GitHub and only lets Chad in, so it does not carry over
Nightly push of the brainsBlocked Needs the Firewheel GitHub org