feat(ana-ml2): persist mesh return routes via ana-scale as an ifupdown if-up.d hook (playbooks/ana-ml2-mesh-routes.yaml, elway-applied, verified)
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# ana-ml2: persist the mesh return routes (via ana-scale 10.250.50.45) as an ifupdown if-up.d
|
||||
# hook on the VLAN-50 interface. Rerunnable; `ip route replace` is idempotent.
|
||||
# scripts/elway infra-ops@10.250.50.54 --playbook playbooks/ana-ml2-mesh-routes.yaml
|
||||
steps:
|
||||
- name: Install the if-up.d hook
|
||||
upload:
|
||||
src: playbooks/files/ana-ml2-mesh-routes.sh
|
||||
dest: /etc/network/if-up.d/mesh-routes
|
||||
mode: "0755"
|
||||
sudo: true
|
||||
|
||||
- name: Apply the routes now (same command the hook runs at ifup)
|
||||
shell: IFACE=enp97s0f0np0.50 /etc/network/if-up.d/mesh-routes
|
||||
sudo: true
|
||||
changed_when: "false"
|
||||
|
||||
verify:
|
||||
- name: All four routes present via ana-scale on the VLAN-50 NIC
|
||||
shell: test "$(ip route | grep -c 'via 10.250.50.45 dev enp97s0f0np0.50')" -eq 4
|
||||
changed_when: "false"
|
||||
|
||||
- name: Hook is executable and keyed on the VLAN interface
|
||||
shell: test -x /etc/network/if-up.d/mesh-routes && grep -q 'enp97s0f0np0.50' /etc/network/if-up.d/mesh-routes
|
||||
changed_when: "false"
|
||||
|
||||
- name: Off-site reachability holds (nh3-scale answers from here)
|
||||
shell: ping -c1 -W2 10.100.50.46 >/dev/null
|
||||
changed_when: "false"
|
||||
@@ -0,0 +1,11 @@
|
||||
#!/bin/sh
|
||||
# ifupdown hook: ana-ml2 mesh RETURN routes via ana-scale (10.250.50.45), on the VLAN-50 NIC.
|
||||
# Why: ana-ml2 has two DHCP defaults on two NICs; mesh traffic arrives on enp97s0f0np0.50 from
|
||||
# ana-scale and the reply would otherwise leave via the other NIC's default -> dropped at the
|
||||
# edge (off-site ssh to ana-ml2 timed out until 2026-09-08). Same-L2 next hop keeps both
|
||||
# directions on the VLAN-50 NIC. Managed from eshpfi-management playbooks/ana-ml2-mesh-routes.yaml.
|
||||
[ "$IFACE" = "enp97s0f0np0.50" ] || exit 0
|
||||
for n in 10.100.0.0/16 10.0.0.0/16 10.6.110.0/24 100.64.0.0/10; do
|
||||
ip route replace "$n" via 10.250.50.45 dev enp97s0f0np0.50
|
||||
done
|
||||
exit 0
|
||||
Reference in New Issue
Block a user