docs: node inventory for the two-host fleet; demo-hp on the tailnet
New documentation/operations/nodes.md: HP t740 hardware, disks (SanDisk system SSD 182195804614; Toshiba 1TB NVMe 58BS11AFT8MQ PRESENT AND UNENROLLED, still NTFS, do not touch), the five-NIC map and the trap that cost the first install, and the access path - no SSH key is baked, auth is the hub-vaulted G1 break-glass password. tailscale.md gains demo-hp, the operator-lab-exception warning so a future product-shape audit does not conclude the product ships tailscale, and the --accept-dns evidence: the join omitted the flag, MagicDNS rewrote /etc/resolv.conf, and it was reverted. Harmless at the vacation site, would have bitten silently at home where split-horizon matters. OPEN: key expiry still enabled on demo-hp (2027-01-17) - needs an admin-console toggle or an API token; a pre-auth key cannot do it.
This commit is contained in:
+17
@@ -3,6 +3,23 @@
|
||||
> Created with the REUSE.md rollout (2026-07-03). Authoritative history: `hub/CHANGELOG.md` (hub),
|
||||
> `website/CHANGELOG.md`, `scripts/CHANGELOG.md`; end-of-task detail in `REPORT.md`.
|
||||
|
||||
- **2026-07-21 — THE FLEET IS TWO HOSTS.** A second Proxmox node exists: **`demo-hp-bb76ea`**, an
|
||||
**HP t740 Thin Client** (Ryzen V1756B, 30 GiB, PVE node `felhom-host`, customer `demo-hp`), installed
|
||||
from the armed universal ISO the same day. Both hosts run **agent 0.92.1**; the N100 is
|
||||
`demo-felhom-8363b5`. **Full inventory: `documentation/operations/nodes.md`** — read it before
|
||||
touching the HP, because two things there are load-bearing: the box's **1TB Toshiba NVMe is present
|
||||
and UNENROLLED** (still carrying its old NTFS partition; a future Tárhely candidate that must join
|
||||
through the storage flow, never the installer), and there is **no operator SSH key baked** on it, so
|
||||
access is the hub-vaulted G1 break-glass password (R-61 is the fix for that lockout).
|
||||
**Both nodes are at the VACATION site and travel home ~2026-08-02.** `demo-hp` joined the tailnet as
|
||||
`100.76.96.79` — an **operator-lab exception**, not product shape; real customer boxes never get
|
||||
tailscale. **Second-hardware proof, worth keeping:** the pairing/day-0 chain ran end to end on virgin
|
||||
hardware it had never seen, the **shim loader booted with Secure Boot ENABLED** (so SB-off was an
|
||||
N100-firmware workaround, not a Felhom requirement), and the box **self-lifted the floor
|
||||
0.153.0 → 0.156.0 during day-0**. The install was not clean, and the failures are filed: **R-59**
|
||||
(no DHCP on the 4-port NIC → the installer baked a static fallback instead of aborting), **R-60**
|
||||
(first-boot NIC sweep self-heal), **R-61** (baked root password unknowable).
|
||||
|
||||
- **2026-07-19 — N100 MADE LOCATION-INDEPENDENT via Tailscale.** `felhom-pve` (the N100) joined the
|
||||
tailnet as a host package (`100.70.170.35`, expiry disabled); DooPlex already advertised
|
||||
`192.168.0.0/24` via its GitOps k3s `admin-system/tailscale` pod (`100.107.87.53`). `ssh felhom-pve`
|
||||
|
||||
Reference in New Issue
Block a user