diff --git a/migration/CUTOVER.md b/migration/CUTOVER.md index fee7182..784f2fd 100644 --- a/migration/CUTOVER.md +++ b/migration/CUTOVER.md @@ -4,18 +4,45 @@ assistant and no web search. Everything you need is on this page and on the boxes themselves. +## Use these addresses. Not the other ones. + +| | use this | do NOT use | +|---|---|---| +| vyos001 (MASTER) | **`10.0.1.252`** | ~~192.168.8.143~~ | +| vyos002 (BACKUP) | **`10.0.1.253`** | ~~192.168.8.144~~ | + +`ssh vyos@10.0.1.252` — by IP, not by name. + +**The `192.168.8.x` addresses stop working the instant the USG is unplugged.** +That is not a maybe. Your workstation is on LoT (`10.0.0.210/23`) and reaching +`192.168.8.x` requires routing *through the USG*: + +``` +ip route get 192.168.8.143 -> via 10.0.0.1 <- the USG. Gone. +ip route get 10.0.1.252 -> dev lanbr0 <- same L2. Survives. +``` + +`10.0.1.252` and `.253` are on the LoT VLAN, the same broadcast domain as your +workstation, so they need no gateway at all. They are the only remote path that +survives the cutover. + +**Between unplugging the USG and finishing the switch there is no inter-VLAN +routing.** In that window: + +- the **JetKVMs are unreachable** from your workstation (they are on Management + and kvm) — they are *not* a fallback during the gap +- **Tailscale is down** with the internet +- your workstation keeps `10.0.0.210` (86400s lease) and can still resolve via + `10.0.0.194`, which is also link-scope + +If LoT SSH fails, the next step is physical console, not the network. + | | | |---|---| -| vyos001 (MASTER) | `192.168.8.143` — also `10.0.1.252` on LoT | -| vyos002 (BACKUP) | `192.168.8.144` — also `10.0.1.253` on LoT | -| JetKVMs | `192.168.1.28`, `192.168.1.29`, `192.168.3.6` | +| JetKVMs (after routing is restored) | `192.168.1.28`, `192.168.1.29`, `192.168.3.6` | | Switch script | `/config/vyos-unifi-switch` on each box | | Login | user `vyos` | -Both boxes have **two** reachable addresses on different interfaces. If `eth2` -(`192.168.8.x`) is unreachable, try the LoT address (`10.0.1.x`), and only then -the JetKVM. - --- ## If something is wrong, do this @@ -84,10 +111,19 @@ reference, and `translation port` rejects a port list. ## The cutover +0. **Open both SSH sessions BEFORE you unplug anything**, and leave them open: + ``` + ssh vyos@10.0.1.253 # vyos002, BACKUP + ssh vyos@10.0.1.252 # vyos001, MASTER + ``` + If either will not connect, stop. Do not unplug the USG. + 1. **Physically disconnect the USG.** Not just powered off — disconnected. The switch script refuses to run while anything still answers on a gateway address, because two devices on `.1` is the worst available outcome. -2. On **vyos002 (BACKUP) first**: + You cannot switch first and unplug after, for exactly that reason. + +2. In the **vyos002 (BACKUP)** session, first: ``` sudo /config/vyos-unifi-switch vyos ```