diff --git a/persistent-memory.md b/persistent-memory.md index fd503c5..5a83ad5 100644 --- a/persistent-memory.md +++ b/persistent-memory.md @@ -206,7 +206,8 @@ COMPLETE and gated RESCUED (02:13 PDT). Live open items:_ restart, so left for the operator's word. ⚠ NOT gate-parity (gated artifact = bf16 arm on the GX10; this seat has a smoke test + 3-run decode probe only) — **operator ruled "no gate"**; the config block states it as unrated on every safety axis. - ⚠ **ana-ml2 mesh return routes are NON-PERSISTENT** (`ip route replace 10.100/16, 10.0/16, 10.6.110/24, 100.64/10 + ✅ **ana-ml2 mesh return routes PERSISTED 23:49 PT** (operator ruling) as `/etc/network/if-up.d/mesh-routes` via + `playbooks/ana-ml2-mesh-routes.yaml` (elway); verify after the next ana-ml2 reboot. (was: non-persistent (`ip route replace 10.100/16, 10.0/16, 10.6.110/24, 100.64/10 via 10.250.50.45` on `enp97s0f0np0.50`, 2026-09-08) — before that nh3-dev→ana-ml2 timed out (two DHCP defaults, reply left the wrong NIC). Lost on reboot; make durable (netplan/networkd) or expect the timeout to return. - **📮 althing reachability on THIS bg seat = the cc-channel route, NOT the waiter.** `althing-listen` diff --git a/playbooks/ana-ml2-mesh-routes.yaml b/playbooks/ana-ml2-mesh-routes.yaml new file mode 100644 index 0000000..5cdca8d --- /dev/null +++ b/playbooks/ana-ml2-mesh-routes.yaml @@ -0,0 +1,28 @@ +# ana-ml2: persist the mesh return routes (via ana-scale 10.250.50.45) as an ifupdown if-up.d +# hook on the VLAN-50 interface. Rerunnable; `ip route replace` is idempotent. +# scripts/elway infra-ops@10.250.50.54 --playbook playbooks/ana-ml2-mesh-routes.yaml +steps: + - name: Install the if-up.d hook + upload: + src: playbooks/files/ana-ml2-mesh-routes.sh + dest: /etc/network/if-up.d/mesh-routes + mode: "0755" + sudo: true + + - name: Apply the routes now (same command the hook runs at ifup) + shell: IFACE=enp97s0f0np0.50 /etc/network/if-up.d/mesh-routes + sudo: true + changed_when: "false" + +verify: + - name: All four routes present via ana-scale on the VLAN-50 NIC + shell: test "$(ip route | grep -c 'via 10.250.50.45 dev enp97s0f0np0.50')" -eq 4 + changed_when: "false" + + - name: Hook is executable and keyed on the VLAN interface + shell: test -x /etc/network/if-up.d/mesh-routes && grep -q 'enp97s0f0np0.50' /etc/network/if-up.d/mesh-routes + changed_when: "false" + + - name: Off-site reachability holds (nh3-scale answers from here) + shell: ping -c1 -W2 10.100.50.46 >/dev/null + changed_when: "false" diff --git a/playbooks/files/ana-ml2-mesh-routes.sh b/playbooks/files/ana-ml2-mesh-routes.sh new file mode 100644 index 0000000..7101577 --- /dev/null +++ b/playbooks/files/ana-ml2-mesh-routes.sh @@ -0,0 +1,11 @@ +#!/bin/sh +# ifupdown hook: ana-ml2 mesh RETURN routes via ana-scale (10.250.50.45), on the VLAN-50 NIC. +# Why: ana-ml2 has two DHCP defaults on two NICs; mesh traffic arrives on enp97s0f0np0.50 from +# ana-scale and the reply would otherwise leave via the other NIC's default -> dropped at the +# edge (off-site ssh to ana-ml2 timed out until 2026-09-08). Same-L2 next hop keeps both +# directions on the VLAN-50 NIC. Managed from eshpfi-management playbooks/ana-ml2-mesh-routes.yaml. +[ "$IFACE" = "enp97s0f0np0.50" ] || exit 0 +for n in 10.100.0.0/16 10.0.0.0/16 10.6.110.0/24 100.64.0.0/10; do + ip route replace "$n" via 10.250.50.45 dev enp97s0f0np0.50 +done +exit 0