diff --git a/CLAUDE.md b/CLAUDE.md index d09b87e..ef3716c 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -57,6 +57,9 @@ ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel (DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts. Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool). + After a re-plug the link often comes up with **no IPv4 at all** (profile active, DHCP + never retried). `nmcli connection down/up "Wired connection 1"` fixes it — check for an + address before concluding the cable is in the wrong port. - The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv — the system `ansible` is not a substitute (no paramiko, newer `community.general`). @@ -98,8 +101,9 @@ Live on the device (2026-06-09): flat L2 switch on `10.2.30.0/24` — **DATA VLA (mgmt `192.168.88.1/24`, no gateway/NTP/DNS), `vlan-filtering` on. The mgmt port also serves DHCP (`192.168.88.10-.254`) + the web UI as a makerspace experiment (flags `switch_web_enabled`, `switch_mgmt_dhcp_enabled`). Default `admin` disabled. Operators -(2026-09-01): `sjat` (keys: mamba seat + `claude@ubongo` automation seat) and `claus` -(`claus@stjerno.dk`), both group `full`, both managed by `switch_operators` in `host_vars`. +(2026-09-01): `sjat` (keys: mamba seat + `claude@ubongo` automation seat), `claus` +(`claus@stjerno.dk`) and `lars` (`lars@hrossen.dk`, the same key he uses on the MakerFLOSS +forgejo and VPS), all group `full`, all managed by `switch_operators` in `host_vars`. All task files + `play_bootstrap`/`play_backup` are idempotency-verified. Design + cutover runbook: `docs/superpowers/specs/2026-06-09-crs310-flat-mgmtvlan-design.md`.