ops(esh-nas-pve): PVE 9 no-downtime prep (8.4.21, microcode, systemd-boot out, NIC pins)
This commit is contained in:
@@ -0,0 +1,88 @@
|
|||||||
|
# esh-nas-pve: no-downtime prep for the PVE 8 → 9 upgrade (Prime 2026-10-03: "prep now, i'm onsite").
|
||||||
|
# scripts/elway infra-ops@10.0.50.55 --playbook playbooks/esh-nas-pve-pve9-prep.yaml
|
||||||
|
# Plan + rationale: docs/runbooks/esh-pve-cluster-pve9-upgrade-plan.md (incl. "esh-nas-pve facts re-read 2026-10-03").
|
||||||
|
# Nothing here reboots or touches a guest. The new kernel, microcode and NIC pins all take effect at the NEXT boot,
|
||||||
|
# which is the planned reboot test on PVE 8, BEFORE any repo switch to trixie.
|
||||||
|
# - latest 8.4 packages (brings the newest 6.8 kernel; it is running 6.8.12-13, up since 2026-08-18);
|
||||||
|
# - non-free-firmware + intel-microcode (the pve8to9 FAIL nh3-pve hit);
|
||||||
|
# - remove the systemd-boot meta package (pve8to9 FAIL; this node boots GRUB from ZFS, so it is not the bootloader);
|
||||||
|
# - pin every NIC name by MAC (Debian 13's systemd may rename them; vmbr0's only port is enp5s0f0).
|
||||||
|
vars:
|
||||||
|
stage_dir: /root/pve9-prep-20261003
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: back up network config + apt sources
|
||||||
|
sudo: true
|
||||||
|
shell: |
|
||||||
|
mkdir -p {{ stage_dir }}
|
||||||
|
cp -p /etc/network/interfaces {{ stage_dir }}/interfaces.before
|
||||||
|
cp -p /etc/apt/sources.list {{ stage_dir }}/sources.list.before
|
||||||
|
creates: "{{ stage_dir }}/interfaces.before"
|
||||||
|
|
||||||
|
- name: add non-free-firmware to the Debian bookworm lines (for intel-microcode)
|
||||||
|
sudo: true
|
||||||
|
shell: sed -i -E '/^deb .*debian(-security)? bookworm/{/non-free-firmware/!s/$/ non-free-firmware/}' /etc/apt/sources.list
|
||||||
|
when: "grep -E '^deb .*debian(-security)? bookworm' /etc/apt/sources.list | grep -qv non-free-firmware"
|
||||||
|
|
||||||
|
- name: apt update (must be clean)
|
||||||
|
sudo: true
|
||||||
|
shell: |
|
||||||
|
! apt-get update -q 2>&1 | grep -E '^(E|Err):'
|
||||||
|
changed_when: "false"
|
||||||
|
|
||||||
|
- name: latest 8.4 packages + intel-microcode (keep local configs)
|
||||||
|
sudo: true
|
||||||
|
shell: |
|
||||||
|
set -o pipefail
|
||||||
|
DEBIAN_FRONTEND=noninteractive apt-get full-upgrade -y -q -o Dpkg::Options::=--force-confold 2>&1 | tail -6
|
||||||
|
DEBIAN_FRONTEND=noninteractive apt-get install -y -q intel-microcode 2>&1 | tail -3
|
||||||
|
|
||||||
|
- name: remove the systemd-boot meta package (GRUB is the bootloader here)
|
||||||
|
sudo: true
|
||||||
|
shell: DEBIAN_FRONTEND=noninteractive apt-get remove -y -q systemd-boot 2>&1 | tail -3
|
||||||
|
when: "dpkg -s systemd-boot >/dev/null 2>&1"
|
||||||
|
|
||||||
|
- name: pin every NIC name to its MAC (systemd .link; takes effect next boot)
|
||||||
|
sudo: true
|
||||||
|
shell: |
|
||||||
|
set -e
|
||||||
|
pin() { # name mac
|
||||||
|
cat > /etc/systemd/network/10-pin-$1.link <<EOF
|
||||||
|
# Pin $1 by MAC so the PVE 9 / Debian 13 udev cannot rename it.
|
||||||
|
# See eshpfi playbooks/esh-nas-pve-pve9-prep.yaml
|
||||||
|
[Match]
|
||||||
|
MACAddress=$2
|
||||||
|
Type=ether
|
||||||
|
[Link]
|
||||||
|
Name=$1
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
pin enp5s0f0 00:e0:c0:4f:c3:56
|
||||||
|
pin enp5s0f1 00:e0:c0:4f:c3:57
|
||||||
|
pin enp9s0 24:5e:be:85:ce:da
|
||||||
|
pin enp10s0 24:5e:be:85:ce:d9
|
||||||
|
pin enp11s0 24:5e:be:85:ce:dc
|
||||||
|
pin enp12s0 24:5e:be:85:ce:db
|
||||||
|
when: "! test -f /etc/systemd/network/10-pin-enp5s0f0.link"
|
||||||
|
|
||||||
|
- name: rebuild every initramfs so the .link files apply in early boot
|
||||||
|
sudo: true
|
||||||
|
shell: update-initramfs -u -k all 2>&1 | tail -4
|
||||||
|
when: "! lsinitramfs /boot/initrd.img-$(ls /boot/vmlinuz-* | sort -V | tail -1 | sed 's#/boot/vmlinuz-##') | grep -q 10-pin-enp5s0f0.link"
|
||||||
|
|
||||||
|
verify:
|
||||||
|
- name: interfaces file still parses (no live reload)
|
||||||
|
sudo: true
|
||||||
|
shell: ifreload -a -s
|
||||||
|
changed_when: "false"
|
||||||
|
- name: newest kernel's initramfs carries the uplink pin
|
||||||
|
sudo: true
|
||||||
|
shell: lsinitramfs /boot/initrd.img-$(ls /boot/vmlinuz-* | sort -V | tail -1 | sed 's#/boot/vmlinuz-##') | grep -q 10-pin-enp5s0f0.link
|
||||||
|
changed_when: "false"
|
||||||
|
- name: systemd-boot gone, intel-microcode in, GRUB still installed
|
||||||
|
sudo: true
|
||||||
|
# `apt remove` leaves systemd-boot in "deinstall ok config-files", where `dpkg -s` still exits 0, so read the status.
|
||||||
|
shell: |
|
||||||
|
! dpkg-query -W -f='${Status}' systemd-boot 2>/dev/null | grep -q 'install ok installed' && dpkg-query -W -f='${Status}' intel-microcode | grep -q 'install ok installed' && dpkg-query -W -f='${Status}' grub-efi-amd64 | grep -q 'install ok installed'
|
||||||
|
|
||||||
|
changed_when: "false"
|
||||||
Reference in New Issue
Block a user