Files
esh-pfi-infrastructure/servers/pfi-gx10
vh a95717e810 feat(gx10): rack networking — VLAN 50 via DHCP reservation, wired only
pfi-gx10 moved from desk Wi-Fi (10.100.10.226, VLAN 10) to the rack on
10.100.50.60 (nh3-servers, VLAN 50), reachable as pfi-gx10.nh3.internal.

The address is a DHCP RESERVATION on the UDM, not a host static. Operator
ruling during the move, and the better design: a host-side static works
until the box moves and is then a stale netplan file on a machine whose
address you no longer know. The pre-written playbook wrote a host static;
it is kept for its safety ordering and annotated as retired.

The port arrived on the native VLAN, not the server VLAN, so switch port 22
was repointed first. port_overrides is a whole-array PUT — two unrelated
overrides on ports 21 and 23 were read, preserved and written back, with the
original array backed up to a file before the change.

Wi-Fi stayed up as the escape hatch until the wired path was proven from
outside, and was downed last as its own step. The step worth keeping: while
Wi-Fi was up, traffic to nh3-dev still preferred wlP9s9 because that
interface sits directly on the userland subnet, so reachability proved
nothing about the wired path. `ping -I enP7s7` across the VLAN boundary is
what actually settled it before the hatch came down.
2026-09-03 15:59:09 -07:00
..

pfi-gx10 — ASUS Ascent GX10 (NVIDIA GB10)

Grace-Blackwell desktop supercomputer. Registered 2026-09-01.

GPU NVIDIA GB10, driver 580.173.02, compute capability 12.1 (sm_121)
CPU 20 cores, aarch64
Memory 121 GB unified (CPU and GPU share it — not 121 GB plus VRAM)
Storage 916 GB NVMe, 6% used
Kernel 6.17.0-1031-nvidia
Hostname pfi-gx10 (shipped with static gx10-a745, corrected)

⚠ The address in ssh-target is TEMPORARY

As of 2026-09-01 this box is on a desk, on Wi-Fi, holding a DHCP lease at 10.100.10.226 on nh3-userland (VLAN 10). Ethernet enP7s7 has no carrier.

It is going into the rack later. Target settled (operator, 2026-09-01): nh3-servers, VLAN 50, static 10.100.50.60 — clear of .40 nh3-docker, .42 nh3-extdev, .50 nh3-nas, .90 pbs-nh3, and below the .150 DHCP pool where fleet statics live.

Nothing was configured on the desk — an address that is about to be wrong is worse than DHCP. The move is playbooks/gx10-rack-network.yaml.

Nothing is needed from the operator beyond racking it. The wired NIC has its own MAC (30:c5:99:3d:a7:45, distinct from the Wi-Fi 50:bb:b5:a2:00:a8), so its post-move address is discoverable from the UDM without being told:

curl -sk "https://10.100.0.1/proxy/network/api/s/default/stat/sta" \
  -H "X-API-KEY: $(secret get unifi/pfi-udmse-api-key)" \
  | python3 -c "import json,sys;[print(c['ip'],c.get('sw_port')) for c in json.load(sys.stdin)['data'] if c['mac']=='30:c5:99:3d:a7:45']"

That also returns the switch port, which must be set to the nh3-servers network or the box lands back on VLAN 10.

Expect ~65–80 ms RTT until it is wired. That is Wi-Fi power-save, not a fault.

Access

infra-ops with NOPASSWD sudo (operator-bootstrapped). lkraven also has key auth but needs a password for sudo — automation must connect as infra-ops.

Headless conversion

playbooks/gx10-headless.yaml — run it with the infra-ops@ prefix, since elway's --sudo applies only to ad-hoc commands and playbook steps carry their own.

Ships booting to graphical.target with GDM and GNOME Remote Desktop. The playbook sets multi-user.target, stops the remote-desktop service, masks the sleep/suspend/hibernate targets, tells logind to ignore lid and idle, and adds sshd keepalives so a stalled link does not kill a long job.

⚠ GDM is static on Ubuntu — pulled in by display-manager.service, never "enabled". Guard and verify on is-active, not is-enabled; the latter passes trivially while the desktop is still running.

The playbook will not stop GDM while someone holds a seat session. Override with --var force_dm_stop=true, or just let the rack-install reboot handle it.

Relevance to Flash-Next

sm_121, not sm_120. The SGLang fork evaluated for ana-ml2 (henge item 49) narrows to exact SM120 and explicitly excludes SM121/GB10 — it does not apply here. This chip has its own path: the DGX Spark recipe, which mmaps the ~48 GiB PLE n-gram table from NVMe rather than holding it in memory. 121 GB unified and 822 GB of free NVMe make that viable on this box in a way it is not on a 96 GB discrete card.