Commit Graph

  • c729275961 labsim: add IPv6 BGP config layer for the Gateway-API public-v6 rehearsal main Michal 2026-09-10 01:23:03 +01:00
  • a4dcc9b379 labsim: rehearse the 3-server k3s dual-stack conversion -- and it answers the plan Michal 2026-09-09 14:38:50 +01:00
  • 97ae6dea89 labsim etcd harness: the real fix -- protect-kernel-defaults sysctls Michal 2026-09-08 11:07:51 +01:00
  • 2048515578 labsim etcd harness: etcd timer tuning for the constrained host + run notes Michal 2026-09-08 00:32:11 +01:00
  • fd38c05c3e labsim: 3-server embedded-etcd k3s harness, driven by the production generator Michal 2026-09-07 23:49:51 +01:00
  • 3ed2099083 labctl: export the k3s config generators + a render CLI Michal 2026-09-07 23:48:04 +01:00
  • ac8653f519 IPv6 addressing phase closed: all five nodes bound, aitopatom included Michal 2026-09-06 23:18:55 +01:00
  • 6c94371c8e provisioning: default new nodes to EUI-64 link-locals so DHCPv6 reservations match Michal 2026-09-06 23:07:39 +01:00
  • 7c2cbfaf31 ROOT CAUSE found: EUI-64 vs stable-privacy link-local, not arch or DUID Michal 2026-09-06 22:58:42 +01:00
  • 3e43385639 window 2026-09-06: final state + handoff note Michal 2026-09-06 22:51:32 +01:00
  • d9f74aa294 CORRECTION: MAC reservations DO work -- I measured too early and said otherwise Michal 2026-09-06 22:49:59 +01:00
  • c392bb9233 window: option (b) mac-sources has no VyOS knob; noted for the attended decision Michal 2026-09-06 22:37:23 +01:00
  • 3c933b96e0 VLAN 2 IPv6 applied to production: RA proven, MAC reservations do NOT match Michal 2026-09-06 22:36:47 +01:00
  • 5c9f004759 labsim: rehearse VLAN 2 IPv6, RA and DHCPv6 reservations before production sees it Michal 2026-09-06 17:11:33 +01:00
  • 914135c47d labctl: refuse to write a k3s config naming an IPv6 the node does not have Michal 2026-09-06 17:00:30 +01:00
  • a9ff182bd6 Ubuntu autoinstall emitted invalid YAML for every role -- and now asks for IPv6 Michal 2026-09-06 16:31:53 +01:00
  • 51bf300474 labctl: k3s config can carry both address families Michal 2026-09-06 16:24:27 +01:00
  • cb03987c33 The drill evidence was silently gitignored by *.log Michal 2026-09-06 15:22:09 +01:00
  • 8a0ef52909 The drill measured IPv6 through a failover: zero HE calls, and it followed Michal 2026-09-06 15:15:53 +01:00
  • da86b60dce IPv6 model merged: mark the staging record, and what the merge caught Michal 2026-09-06 15:07:40 +01:00
  • d0b733f831 IPv6 follows master, deployed: vyos002 has a tunnel and a gate that holds it shut Michal 2026-09-06 14:46:44 +01:00
  • 395577850c IPv6 was never HA, and the WAN becoming HA is what exposed it Michal 2026-09-06 14:30:44 +01:00
  • 061b9e3d7e Close the last two items: config.boot pinned, and an upgrade runbook Michal 2026-09-06 10:39:59 +01:00
  • bda5854563 vif53-pin-boot-disable: get disable into config.boot without losing the WAN Michal 2026-09-06 10:31:56 +01:00
  • d08f68e28b PPPOE-HA: step 8 done -- model merged, zero drift Michal 2026-09-06 09:42:12 +01:00
  • e1c571d004 PPPOE-HA: the drill closed the two biggest unknowns Michal 2026-09-06 09:38:20 +01:00
  • 47ce0c1aea wan-drill: run the failover drill unattended, because the operator goes offline Michal 2026-09-06 09:35:05 +01:00
  • 85819e40c1 wan-drill-watchdog: bound the blast radius of a failover drill Michal 2026-09-06 09:34:05 +01:00
  • 13dcdff1ef wan-panic: a one-command revert that works with no internet and no Claude Michal 2026-09-06 09:29:23 +01:00
  • 8aa3d0ebaa PPPOE-HA: record that vyos001's config.boot lacks vif 53 disable Michal 2026-09-06 01:27:07 +01:00
  • 8fce03e705 PPPOE-HA: deployed to production Michal 2026-09-06 01:26:38 +01:00
  • 5ed0e4888a labsim: both matrices green end to end, numbers reproduced Michal 2026-09-06 00:42:01 +01:00
  • 97efb5abb2 labsim: record the failover numbers and how they were nearly wrong Michal 2026-09-06 00:27:38 +01:00
  • 6987b324f1 vrrp-wan: size GRACE from the measured hostile failover, not the theory Michal 2026-09-06 00:25:00 +01:00
  • 9221c71ff0 labsim: the session-control matrix was never setting session-control Michal 2026-09-06 00:15:45 +01:00
  • 4d47b609a2 PPPOE-HA: record the two failure modes found by running the thing Michal 2026-09-06 00:11:32 +01:00
  • b659e0d47e vrrp-wan: a flap holdoff must not tear down a live WAN session Michal 2026-09-06 00:04:41 +01:00
  • d626750010 labsim: hard failover and reboot safety hold; runbook for the production apply Michal 2026-09-05 19:21:13 +01:00
  • 93fed7826b labsim: PPPoE HA passes the matrix, and the health check had a real flap bug Michal 2026-09-05 19:11:07 +01:00
  • 4efd70c987 vyos: move PPPoE off the config plane onto a gated systemd unit Michal 2026-09-05 18:50:16 +01:00
  • 2e828b8af2 vyos: a failover you can actually trigger, and four bugs found triggering it Michal 2026-09-02 23:27:17 +01:00
  • 7bf3f42e19 vyos: WAN follows VRRP mastership, rehearsed in labsim Michal 2026-09-02 18:02:58 +01:00
  • 09ede73b67 migration: the watcher that caught vyos002, and what it found Michal 2026-09-02 15:51:47 +01:00
  • a973b51b9c migration: vyos001 converted in production, and the config vyos002 needs first Michal 2026-09-02 15:26:21 +01:00
  • d727a50ca0 migration: offline recovery card, and stop the leak test trusting a silent router Michal 2026-09-02 14:30:35 +01:00
  • 0481c38e09 labsim: prove the tagged-Management fix for kea's wrong-pool offers Michal 2026-09-02 14:03:44 +01:00
  • 23783b8486 vyos: VRRP health check so the WAN and the gateway VIP cannot separate Michal 2026-09-02 11:39:44 +01:00
  • 11344eab92 labsim: the IPAM switch needs no pod recycle when the CIDR sources agree Michal 2026-08-24 23:20:16 +01:00
  • e8679f45b5 labsim: rehearse the IPAM switch on 3 nodes, and catch the trap in it Michal 2026-08-24 23:13:20 +01:00
  • 527e0798ae bastion/k3s: bootstrap new clusters with cluster-pool IPAM Michal 2026-08-24 22:59:55 +01:00
  • 842408c0d9 labsim: prove k3s CAN be converted to dual-stack in place Michal 2026-08-24 22:46:27 +01:00
  • ad6eb7a9a6 labsim: default-deny firewall policy, proven in the sim Michal 2026-08-22 22:25:55 +01:00
  • 7f551081ad labsim: capture BGP, dual WAN and both ISP VMs as code Michal 2026-08-22 16:26:36 +01:00
  • f41ffdd039 feat(vyos): reconciler that keeps the HE 6in4 tunnel on the live WAN Michal 2026-08-21 02:04:43 +01:00
  • a187703a3a feat(vyos): pin a known-good config and restore it with one command Michal 2026-08-21 01:46:43 +01:00
  • 86c2a36f00 feat(labsim): a real Kubernetes cluster for rehearsing Cilium <-> VyOS BGP Michal 2026-08-19 13:15:45 +01:00
  • 27a343bc75 Merge branch 'feat/unifi-export-and-vyos-dhcp': USG to VyOS migration Michal 2026-08-18 12:19:48 +01:00
  • 672b89ce38 feat(labctl): install VyOS from a Pulumi-rendered bundle, and enable its API Michal 2026-08-18 12:18:53 +01:00
  • f4984e3962 fix(vyos): health-check the 10 gig primary so failover actually fires Michal 2026-08-18 12:18:41 +01:00
  • 7b5331ddcd fix(migration): the backup has no WAN by design; stop failing it for that Michal 2026-08-18 01:48:48 +01:00
  • ce6911c196 fix(migration): require a working WAN, not every WAN Michal 2026-08-18 01:37:14 +01:00
  • 54b21fa9ff fix(migration): poll for WAN health instead of sampling once at 25s Michal 2026-08-18 01:10:50 +01:00
  • ff86a421f4 fix(labsim): console-apply must handle both VyOS prompts, not just $ Michal 2026-08-18 01:00:19 +01:00
  • ee070371a8 feat(labsim): add WAN transport VLANs so the sim can host fake ISPs Michal 2026-08-18 00:44:11 +01:00
  • 41b5448f56 feat(pulumi-vyos): prototype VyOS subtrees as Pulumi resources with commit-confirm Michal 2026-08-17 01:09:05 +01:00
  • 63061e6e7e feat(migration): peer link cabled and verified; conntrack-sync enabled in deltas Michal 2026-08-17 00:37:16 +01:00
  • ccdd1e7e49 fix(migration): both boxes carry WAN and NAT; the backup just holds it down Michal 2026-08-17 00:30:23 +01:00
  • 64e748ea94 test(labsim): conntrack-sync verified, and it exposed a delta defect Michal 2026-08-17 00:17:21 +01:00
  • bb654d83f8 test(labsim): second VyOS router proves DHCP active-passive HA Michal 2026-08-16 23:29:12 +01:00
  • 952f5c66e3 feat(migration): complete the VyOS HA stack per the official docs Michal 2026-08-16 22:48:39 +01:00
  • f81c94af43 feat(migration): dual WAN, cloned MAC, and the new 10.8.0.0/23 Private VLAN Michal 2026-08-16 18:16:25 +01:00
  • febe4b72bc chore(migration): all DNS through VyOS to Google, NAS out of the path Michal 2026-08-16 17:16:17 +01:00
  • 3768657b91 chore(migration): firewalls resolve via 8.8.8.8/8.8.4.4 Michal 2026-08-16 16:49:27 +01:00
  • 2a8fcb3bd3 fix(migration): the runbook pointed at addresses that die with the USG Michal 2026-08-16 16:25:04 +01:00
  • fc31013ceb fix(migration): apply the reviewed reservation plan, not a recomputed one Michal 2026-08-16 14:31:30 +01:00
  • b37cd79432 fix(migration): refuse an unprobeable delta instead of warning past it Michal 2026-08-16 00:13:19 +01:00
  • 7e464a2828 docs(migration): record what the rehearsal proved and what it could not Michal 2026-08-16 00:08:13 +01:00
  • 01a923352f fix(migration): do not emit a NAT translation port for a port list Michal 2026-08-16 00:02:21 +01:00
  • 7f5d3517a3 fix(migration): create the WAN vif before PPPoE references it Michal 2026-08-15 23:51:13 +01:00
  • d56bbf6db0 feat(migration): reversible USG->VyOS switch, proven on the sim Michal 2026-08-15 23:30:28 +01:00
  • 6c4318d3ae feat(migration): reserve every active client at its current address Michal 2026-08-15 23:07:07 +01:00
  • f36ff4c6e3 feat(migration): pin firewall management NICs and reserve them in UniFi Michal 2026-08-15 22:12:42 +01:00
  • 44dbd5188c feat(migration): export UniFi config and generate VyOS DHCP+DNS from it Michal 2026-08-15 01:33:00 +01:00
  • b0b68f2edd Merge feat/vyos-unattended-install: VyOS HA install + DiskPressure incident fixes Michal 2026-08-14 23:22:21 +01:00
  • 72c54edce2 feat(k3s): enable swap and grow the rancher LV during host-prep feat/vyos-unattended-install Michal 2026-08-14 23:22:14 +01:00
  • 33be713d0c feat(bastion): size the rancher LV at 120G for k8s roles in kickstart Michal 2026-08-14 23:22:14 +01:00
  • a5b36678ed feat(labsim): live topology view with per-path latency Michal 2026-08-13 00:56:06 +01:00
  • c91e44f796 feat(labsim): libvirt replica of the lab network with LACP + VyOS routing Michal 2026-08-13 00:42:39 +01:00
  • df2dfc5d71 fix(bastion): pin the VyOS boot NIC by MAC, and detect pre-installer stalls Michal 2026-08-12 12:35:09 +01:00
  • 820fbd4353 docs(bastion): state the rescue-SSH evidence at its actual strength feat/arm64-pxe-support Michal 2026-08-11 15:36:58 +01:00
  • 346bd80c13 test(bastion): cover the rescue boot path and record what it exposed Michal 2026-08-11 15:25:57 +01:00
  • b75a4e0118 docs(bastion): document multi-arch PXE and the vendor-OS classification Michal 2026-08-11 13:08:32 +01:00
  • 572afb2624 fix(bastion): refuse to serve an x86-only kernel to an arm64 client Michal 2026-08-11 13:03:53 +01:00
  • 3fab400a96 test(bastion): add aarch64 network PXE integration test Michal 2026-08-11 13:00:18 +01:00
  • e32c20ca5c test(bastion): cover arm64 dispatch, the Spark guard, and option 93 tags Michal 2026-08-11 12:54:08 +01:00
  • 5c4ad6aecd feat(cli): observe the root device instead of assuming an LVM layout Michal 2026-08-11 12:54:08 +01:00
  • d25c0ce64d feat(bastion): refuse installs on machines running a vendor OS Michal 2026-08-11 12:48:24 +01:00
  • c4fa88d46a fix(bastion): match arm64 UEFI HTTP boot on option 93 value 19, not 20 Michal 2026-08-11 12:48:24 +01:00
  • 9c79915975 feat(bastion): serve per-architecture PXE kernels, resolved not flagged Michal 2026-08-11 12:48:09 +01:00
  • cba56becfc test(bastion): pin x86_64 iPXE script output with a golden fixture Michal 2026-08-11 12:47:57 +01:00