feat(mesh): fold irv-ml1 in additively (node 100.64.0.6), wg0 lifeline preserved; wg0 retirement deferred to on-site
This commit is contained in:
@@ -323,3 +323,33 @@ during upload sampled ~32% (single reading) → not clearly the cap; upload like
|
|||||||
userspace-WireGuard single-flow, the CT vNIC, or the WAN. Operator: the ANA AT&T line is
|
userspace-WireGuard single-flow, the CT vNIC, or the WAN. Operator: the ANA AT&T line is
|
||||||
SHARED fiber, so the upload figure may be the line, not the routers — left as-is (no CT core
|
SHARED fiber, so the upload figure may be the line, not the routers — left as-is (no CT core
|
||||||
bump). Baseline for future comparison, not a hardware limit.
|
bump). Baseline for future comparison, not a hardware limit.
|
||||||
|
|
||||||
|
## 2026-09-06 — irv-ml1 folded in ADDITIVELY (operator inaccessible 5 days — lifeline preserved)
|
||||||
|
|
||||||
|
Constraint: operator has NO physical access to the Irvine building for 5 days; irv-ml1 must
|
||||||
|
not go dark unrecoverably. Its ONLY remote path is the bespoke WireGuard tunnel `wg0`
|
||||||
|
(10.100.79.3 → nh3-dev, AllowedIPs 10.0/16+10.100/16+10.250/16); its LAN 10.6.110.50 is not
|
||||||
|
reachable from the fleet.
|
||||||
|
|
||||||
|
Enrolled irv-ml1 as headscale node **100.64.0.6** (`infra-ops@10.100.79.3` has NOPASSWD root;
|
||||||
|
`tailscaled` was already running but logged out with STALE prefs → **public** Tailscale
|
||||||
|
`controlplane.tailscale.com` + `RouteAll:true`). Used `tailscale up --reset --login-server
|
||||||
|
https://headscale.phasefinal.com --authkey … --accept-routes=false --accept-dns=false
|
||||||
|
--hostname irv-ml1`. ⚠ **accept-routes MUST stay OFF**: wg0's AllowedIPs are the exact /16s the
|
||||||
|
mesh routers advertise, so accepting them would fight the lifeline over the prefix my SSH
|
||||||
|
returns on = 5-day lockout. Armed an auto-revert dead-man switch (`tailscale down` in 10m
|
||||||
|
unless disarmed) before the change; disarmed via sentinel after verifying.
|
||||||
|
|
||||||
|
Result: **DUAL PATH** — wg0 (10.100.79.3, untouched, fleet routes still via it) AND mesh
|
||||||
|
(100.64.0.6). Both verified from nh3-dev. Reboot-safe: `wg-quick@wg0` + `tailscaled` both
|
||||||
|
enabled, prefs now headscale + accept-routes=false + WantRunning=true. Mesh peering currently
|
||||||
|
rides over wg0 as transport (11ms).
|
||||||
|
|
||||||
|
⚠ **DEFERRED to the on-site window (do NOT do remotely):** retire wg0; enable accept-routes /
|
||||||
|
subnet-routing over the mesh; migrate yt-voice-clipper egress off the dante SOCKS proxy. Each
|
||||||
|
touches the exact routing that is the lifeline. When on-site (physical console as fallback):
|
||||||
|
flip accept-routes on, confirm fleet reachability over the mesh, THEN down wg0.
|
||||||
|
|
||||||
|
⚠ **Lesson (repeat):** `pkill -f` / `pgrep -f <pattern>` over SSH self-matches when the pattern
|
||||||
|
is in your own ssh argv — killed my session twice disarming the switch. Kill by explicit PID,
|
||||||
|
or make the switch sentinel-based (which saved it here).
|
||||||
|
|||||||
Reference in New Issue
Block a user