-
c729275961
labsim: add IPv6 BGP config layer for the Gateway-API public-v6 rehearsal
main
Michal
2026-09-10 01:23:03 +01:00
-
a4dcc9b379
labsim: rehearse the 3-server k3s dual-stack conversion -- and it answers the plan
Michal
2026-09-09 14:38:50 +01:00
-
97ae6dea89
labsim etcd harness: the real fix -- protect-kernel-defaults sysctls
Michal
2026-09-08 11:07:51 +01:00
-
2048515578
labsim etcd harness: etcd timer tuning for the constrained host + run notes
Michal
2026-09-08 00:32:11 +01:00
-
fd38c05c3e
labsim: 3-server embedded-etcd k3s harness, driven by the production generator
Michal
2026-09-07 23:49:51 +01:00
-
3ed2099083
labctl: export the k3s config generators + a render CLI
Michal
2026-09-07 23:48:04 +01:00
-
ac8653f519
IPv6 addressing phase closed: all five nodes bound, aitopatom included
Michal
2026-09-06 23:18:55 +01:00
-
6c94371c8e
provisioning: default new nodes to EUI-64 link-locals so DHCPv6 reservations match
Michal
2026-09-06 23:07:39 +01:00
-
7c2cbfaf31
ROOT CAUSE found: EUI-64 vs stable-privacy link-local, not arch or DUID
Michal
2026-09-06 22:58:42 +01:00
-
3e43385639
window 2026-09-06: final state + handoff note
Michal
2026-09-06 22:51:32 +01:00
-
d9f74aa294
CORRECTION: MAC reservations DO work -- I measured too early and said otherwise
Michal
2026-09-06 22:49:59 +01:00
-
c392bb9233
window: option (b) mac-sources has no VyOS knob; noted for the attended decision
Michal
2026-09-06 22:37:23 +01:00
-
3c933b96e0
VLAN 2 IPv6 applied to production: RA proven, MAC reservations do NOT match
Michal
2026-09-06 22:36:47 +01:00
-
5c9f004759
labsim: rehearse VLAN 2 IPv6, RA and DHCPv6 reservations before production sees it
Michal
2026-09-06 17:11:33 +01:00
-
914135c47d
labctl: refuse to write a k3s config naming an IPv6 the node does not have
Michal
2026-09-06 17:00:30 +01:00
-
a9ff182bd6
Ubuntu autoinstall emitted invalid YAML for every role -- and now asks for IPv6
Michal
2026-09-06 16:31:53 +01:00
-
51bf300474
labctl: k3s config can carry both address families
Michal
2026-09-06 16:24:27 +01:00
-
cb03987c33
The drill evidence was silently gitignored by *.log
Michal
2026-09-06 15:22:09 +01:00
-
8a0ef52909
The drill measured IPv6 through a failover: zero HE calls, and it followed
Michal
2026-09-06 15:15:53 +01:00
-
da86b60dce
IPv6 model merged: mark the staging record, and what the merge caught
Michal
2026-09-06 15:07:40 +01:00
-
d0b733f831
IPv6 follows master, deployed: vyos002 has a tunnel and a gate that holds it shut
Michal
2026-09-06 14:46:44 +01:00
-
395577850c
IPv6 was never HA, and the WAN becoming HA is what exposed it
Michal
2026-09-06 14:30:44 +01:00
-
061b9e3d7e
Close the last two items: config.boot pinned, and an upgrade runbook
Michal
2026-09-06 10:39:59 +01:00
-
bda5854563
vif53-pin-boot-disable: get
disable into config.boot without losing the WAN
Michal
2026-09-06 10:31:56 +01:00
-
d08f68e28b
PPPOE-HA: step 8 done -- model merged, zero drift
Michal
2026-09-06 09:42:12 +01:00
-
e1c571d004
PPPOE-HA: the drill closed the two biggest unknowns
Michal
2026-09-06 09:38:20 +01:00
-
47ce0c1aea
wan-drill: run the failover drill unattended, because the operator goes offline
Michal
2026-09-06 09:35:05 +01:00
-
85819e40c1
wan-drill-watchdog: bound the blast radius of a failover drill
Michal
2026-09-06 09:34:05 +01:00
-
13dcdff1ef
wan-panic: a one-command revert that works with no internet and no Claude
Michal
2026-09-06 09:29:23 +01:00
-
8aa3d0ebaa
PPPOE-HA: record that vyos001's config.boot lacks
vif 53 disable
Michal
2026-09-06 01:27:07 +01:00
-
8fce03e705
PPPOE-HA: deployed to production
Michal
2026-09-06 01:26:38 +01:00
-
5ed0e4888a
labsim: both matrices green end to end, numbers reproduced
Michal
2026-09-06 00:42:01 +01:00
-
97efb5abb2
labsim: record the failover numbers and how they were nearly wrong
Michal
2026-09-06 00:27:38 +01:00
-
6987b324f1
vrrp-wan: size GRACE from the measured hostile failover, not the theory
Michal
2026-09-06 00:25:00 +01:00
-
9221c71ff0
labsim: the session-control matrix was never setting session-control
Michal
2026-09-06 00:15:45 +01:00
-
4d47b609a2
PPPOE-HA: record the two failure modes found by running the thing
Michal
2026-09-06 00:11:32 +01:00
-
b659e0d47e
vrrp-wan: a flap holdoff must not tear down a live WAN session
Michal
2026-09-06 00:04:41 +01:00
-
d626750010
labsim: hard failover and reboot safety hold; runbook for the production apply
Michal
2026-09-05 19:21:13 +01:00
-
93fed7826b
labsim: PPPoE HA passes the matrix, and the health check had a real flap bug
Michal
2026-09-05 19:11:07 +01:00
-
4efd70c987
vyos: move PPPoE off the config plane onto a gated systemd unit
Michal
2026-09-05 18:50:16 +01:00
-
2e828b8af2
vyos: a failover you can actually trigger, and four bugs found triggering it
Michal
2026-09-02 23:27:17 +01:00
-
7bf3f42e19
vyos: WAN follows VRRP mastership, rehearsed in labsim
Michal
2026-09-02 18:02:58 +01:00
-
09ede73b67
migration: the watcher that caught vyos002, and what it found
Michal
2026-09-02 15:51:47 +01:00
-
a973b51b9c
migration: vyos001 converted in production, and the config vyos002 needs first
Michal
2026-09-02 15:26:21 +01:00
-
d727a50ca0
migration: offline recovery card, and stop the leak test trusting a silent router
Michal
2026-09-02 14:30:35 +01:00
-
0481c38e09
labsim: prove the tagged-Management fix for kea's wrong-pool offers
Michal
2026-09-02 14:03:44 +01:00
-
23783b8486
vyos: VRRP health check so the WAN and the gateway VIP cannot separate
Michal
2026-09-02 11:39:44 +01:00
-
11344eab92
labsim: the IPAM switch needs no pod recycle when the CIDR sources agree
Michal
2026-08-24 23:20:16 +01:00
-
e8679f45b5
labsim: rehearse the IPAM switch on 3 nodes, and catch the trap in it
Michal
2026-08-24 23:13:20 +01:00
-
527e0798ae
bastion/k3s: bootstrap new clusters with cluster-pool IPAM
Michal
2026-08-24 22:59:55 +01:00
-
842408c0d9
labsim: prove k3s CAN be converted to dual-stack in place
Michal
2026-08-24 22:46:27 +01:00
-
ad6eb7a9a6
labsim: default-deny firewall policy, proven in the sim
Michal
2026-08-22 22:25:55 +01:00
-
7f551081ad
labsim: capture BGP, dual WAN and both ISP VMs as code
Michal
2026-08-22 16:26:36 +01:00
-
f41ffdd039
feat(vyos): reconciler that keeps the HE 6in4 tunnel on the live WAN
Michal
2026-08-21 02:04:43 +01:00
-
a187703a3a
feat(vyos): pin a known-good config and restore it with one command
Michal
2026-08-21 01:46:43 +01:00
-
86c2a36f00
feat(labsim): a real Kubernetes cluster for rehearsing Cilium <-> VyOS BGP
Michal
2026-08-19 13:15:45 +01:00
-
27a343bc75
Merge branch 'feat/unifi-export-and-vyos-dhcp': USG to VyOS migration
Michal
2026-08-18 12:19:48 +01:00
-
-
672b89ce38
feat(labctl): install VyOS from a Pulumi-rendered bundle, and enable its API
Michal
2026-08-18 12:18:53 +01:00
-
f4984e3962
fix(vyos): health-check the 10 gig primary so failover actually fires
Michal
2026-08-18 12:18:41 +01:00
-
7b5331ddcd
fix(migration): the backup has no WAN by design; stop failing it for that
Michal
2026-08-18 01:48:48 +01:00
-
ce6911c196
fix(migration): require a working WAN, not every WAN
Michal
2026-08-18 01:37:14 +01:00
-
54b21fa9ff
fix(migration): poll for WAN health instead of sampling once at 25s
Michal
2026-08-18 01:10:50 +01:00
-
ff86a421f4
fix(labsim): console-apply must handle both VyOS prompts, not just $
Michal
2026-08-18 01:00:19 +01:00
-
ee070371a8
feat(labsim): add WAN transport VLANs so the sim can host fake ISPs
Michal
2026-08-18 00:44:11 +01:00
-
41b5448f56
feat(pulumi-vyos): prototype VyOS subtrees as Pulumi resources with commit-confirm
Michal
2026-08-17 01:09:05 +01:00
-
63061e6e7e
feat(migration): peer link cabled and verified; conntrack-sync enabled in deltas
Michal
2026-08-17 00:37:16 +01:00
-
ccdd1e7e49
fix(migration): both boxes carry WAN and NAT; the backup just holds it down
Michal
2026-08-17 00:30:23 +01:00
-
64e748ea94
test(labsim): conntrack-sync verified, and it exposed a delta defect
Michal
2026-08-17 00:17:21 +01:00
-
bb654d83f8
test(labsim): second VyOS router proves DHCP active-passive HA
Michal
2026-08-16 23:29:12 +01:00
-
952f5c66e3
feat(migration): complete the VyOS HA stack per the official docs
Michal
2026-08-16 22:48:39 +01:00
-
f81c94af43
feat(migration): dual WAN, cloned MAC, and the new 10.8.0.0/23 Private VLAN
Michal
2026-08-16 18:16:25 +01:00
-
febe4b72bc
chore(migration): all DNS through VyOS to Google, NAS out of the path
Michal
2026-08-16 17:16:17 +01:00
-
3768657b91
chore(migration): firewalls resolve via 8.8.8.8/8.8.4.4
Michal
2026-08-16 16:49:27 +01:00
-
2a8fcb3bd3
fix(migration): the runbook pointed at addresses that die with the USG
Michal
2026-08-16 16:25:04 +01:00
-
fc31013ceb
fix(migration): apply the reviewed reservation plan, not a recomputed one
Michal
2026-08-16 14:31:30 +01:00
-
b37cd79432
fix(migration): refuse an unprobeable delta instead of warning past it
Michal
2026-08-16 00:13:19 +01:00
-
7e464a2828
docs(migration): record what the rehearsal proved and what it could not
Michal
2026-08-16 00:08:13 +01:00
-
01a923352f
fix(migration): do not emit a NAT translation port for a port list
Michal
2026-08-16 00:02:21 +01:00
-
7f5d3517a3
fix(migration): create the WAN vif before PPPoE references it
Michal
2026-08-15 23:51:13 +01:00
-
d56bbf6db0
feat(migration): reversible USG->VyOS switch, proven on the sim
Michal
2026-08-15 23:30:28 +01:00
-
6c4318d3ae
feat(migration): reserve every active client at its current address
Michal
2026-08-15 23:07:07 +01:00
-
f36ff4c6e3
feat(migration): pin firewall management NICs and reserve them in UniFi
Michal
2026-08-15 22:12:42 +01:00
-
44dbd5188c
feat(migration): export UniFi config and generate VyOS DHCP+DNS from it
Michal
2026-08-15 01:33:00 +01:00
-
-
b0b68f2edd
Merge feat/vyos-unattended-install: VyOS HA install + DiskPressure incident fixes
Michal
2026-08-14 23:22:21 +01:00
-
-
72c54edce2
feat(k3s): enable swap and grow the rancher LV during host-prep
feat/vyos-unattended-install
Michal
2026-08-14 23:22:14 +01:00
-
33be713d0c
feat(bastion): size the rancher LV at 120G for k8s roles in kickstart
Michal
2026-08-14 23:22:14 +01:00
-
a5b36678ed
feat(labsim): live topology view with per-path latency
Michal
2026-08-13 00:56:06 +01:00
-
c91e44f796
feat(labsim): libvirt replica of the lab network with LACP + VyOS routing
Michal
2026-08-13 00:42:39 +01:00
-
df2dfc5d71
fix(bastion): pin the VyOS boot NIC by MAC, and detect pre-installer stalls
Michal
2026-08-12 12:35:09 +01:00
-
820fbd4353
docs(bastion): state the rescue-SSH evidence at its actual strength
feat/arm64-pxe-support
Michal
2026-08-11 15:36:58 +01:00
-
346bd80c13
test(bastion): cover the rescue boot path and record what it exposed
Michal
2026-08-11 15:25:57 +01:00
-
b75a4e0118
docs(bastion): document multi-arch PXE and the vendor-OS classification
Michal
2026-08-11 13:08:32 +01:00
-
572afb2624
fix(bastion): refuse to serve an x86-only kernel to an arm64 client
Michal
2026-08-11 13:03:53 +01:00
-
3fab400a96
test(bastion): add aarch64 network PXE integration test
Michal
2026-08-11 13:00:18 +01:00
-
e32c20ca5c
test(bastion): cover arm64 dispatch, the Spark guard, and option 93 tags
Michal
2026-08-11 12:54:08 +01:00
-
5c4ad6aecd
feat(cli): observe the root device instead of assuming an LVM layout
Michal
2026-08-11 12:54:08 +01:00
-
d25c0ce64d
feat(bastion): refuse installs on machines running a vendor OS
Michal
2026-08-11 12:48:24 +01:00
-
c4fa88d46a
fix(bastion): match arm64 UEFI HTTP boot on option 93 value 19, not 20
Michal
2026-08-11 12:48:24 +01:00
-
9c79915975
feat(bastion): serve per-architecture PXE kernels, resolved not flagged
Michal
2026-08-11 12:48:09 +01:00
-
cba56becfc
test(bastion): pin x86_64 iPXE script output with a golden fixture
Michal
2026-08-11 12:47:57 +01:00
-
-