memory: ESH WAN static 128.177.138.182/30 LIVE (CGNAT over), crowdsec esh allowlist updated, open follow-ups (FG trusthost3, esh-ana rebind, mesh direct path)

This commit is contained in:
2026-09-08 13:29:42 -07:00
parent 304baddfc1
commit 7d5de53565
+12 -5
View File
@@ -255,11 +255,17 @@ below is a live commitment or a known-open risk._
ran copper through a drilled floor 2x4 himself; recommendation was a 10Gtek
SR 2-pack + OM4 3 m LC-LC (~$4065) because cable-vs-pull-damage was never resolved.
- **Cityside fiber `/30` is NOT provisioned.** `128.177.138.182/30`, gw `.181`.
Static passes no traffic and DHCP still hands CGNAT `100.104.3.250`; operator
power-cycled both ends and opened a ticket. Cutover payloads stay staged:
`wan1-REVERT.json`, and the `esh-ana` IPsec fix (`ipsec_local_ip 100.104.3.250 →
128.177.138.182`) **which will otherwise silently break ESH→Anaheim restic backups.**
- ✅ **ESH WAN is now a STATIC PUBLIC IPv4: `128.177.138.182/30`, gw `128.177.138.181` (Cityside Fiber),
LIVE** — operator confirmed 2026-09-08; UDM WAN1 (`eth8`) reads `wan_type: static`, uplink up since
~2026-09-05, egress verified from esh-docker-vm = `128.177.138.182` (a real public address — CGNAT at
ESH is HISTORY; `100.104.0.1` still shows as the ISP's first hop, that is their access network, not
NAT). IPv6 unchanged (`2607:73c0:402:1d00::/56`, hosts still egress as their own v6). Done 2026-09-08:
`128.177.138.182` added to the crowdsec `esh` allowlist on ana-docker (the false-ban class is closed
for ESH). Still stale and OPEN: (a) FortiGate infra-ops `trusthost3` = old CGNAT `23.164.40.160`
should be `128.177.138.182` or the WAN-SSH safety net does not work from ESH; (b) dormant `esh-ana`
IPsec object is bound to **wan2** (`192.168.200.111`) — rebind to wan1/`128.177.138.182` if it is ever
to serve as mesh failover; (c) esh-scale still reaches peers via DERP(lax) — a UDP/41641 port-forward
on the ESH UDM would let the mesh go direct now that the IP is static. `wan1-REVERT.json` is obsolete.
-**esh-nas is effectively open to the whole ESH LAN** — twelve NFS exports rw to
`10.0.0.0/8` with `sec=sys`, and every SMB share but `backup` guest-writable.
@@ -586,6 +592,7 @@ below is a live commitment or a known-open risk._
- `[2026-09-08]` **ERP run 5 = RESCUED (landmark R49.5)** — first capability-gate pass in the ERP-seat line; the 3.46%-loss dependency-forcing slot (GovReport+QMSum) broke the coupling runs 3c/4 couldn't. Seat `erp-tune-v5` served on gx10:8098, `trial` alias repointed 3c→v5. → `persistent-memory.d/2026-09-08-run5-rescued.md`
- `[2026-09-08]` **R47 base settled from bytes = STOCK `google/gemma-4-26B-A4B-it`** — three-way sha match (local == HF etag == stock LFS oid; commit `4d7ae498` == stock HEAD); the `-heretic` label is a naming error, all runs trained from stock. Accept-vs-swap now evidenced. → `persistent-memory.d/2026-09-08-base-provenance-stock.md`
- `[2026-09-08]` **ESH WAN static `128.177.138.182/30` (gw .181) is LIVE** — the Cityside /30 that was 'not provisioned' on 09-04 now carries traffic; egress verified from esh-docker-vm. CGNAT at ESH is over. Added to the crowdsec `esh` allowlist. Open follow-ups: FortiGate trusthost3, dormant esh-ana IPsec rebind wan2→wan1, tailscale direct-path port-forward.
- `[2026-09-08]` **ERP run 6 LAUNCHED on pfi-gx10 on the jenerallee78 ARA-abliterated base** (index `33c59654…`, 32/32 shards byte-verified vs brokkr pins, stock tokenizer set installed over the repo's 256-token-truncating one, run-5 recipe byte-held, free check exact). Operator's direct grant `operator-2026-09-08-rnd-run6`; run-5 seat unloaded (`trial` dark). Gate names: `erp-seat-base-ara` / `erp-tune-v6`. → `docs/runbooks/gx10-run-06.md`, commit `3fec668`.
- `[2026-09-08]` **Miranda = operator's chief of staff, may relay his directives** — added to user-level `~/.claude/CLAUDE.md` (dotfiles `7134a22`) as the named exception to the no-relayed-auth rule (unidentified peer relays still excluded); material-consequence calls she relays stay the operator's own.
- `[2026-09-08]` **Fleet fixes shipped** — WhereTF Homepage card + DNS (`4506ef6`); ext-tts LiteLLM alias → `irv-ml1.nh3.internal` (DB `/model/update` + `extra_hosts`, `957c8f1`); the 09-06 irv-ml1 stale-IP trail repointed across 25 composes + services.yaml + ssh-target → DNS name (`e0d1c44`); Homepage `/api/services` outage fixed — ana-ml2 discovery via a socat proxy on ana-docker (`stacks/ana-ml2-proxy`, `913d2d2`, reversible).