docs: record lars as operator + the NM no-lease-after-replug trap

Applied to the device and idempotency-verified (run 1 changed=1, run 2
changed=0). Also notes the NetworkManager behaviour that looked like a
mis-plugged cable: after a re-plug the wired profile stays active with no
IPv4 until the connection is cycled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
This commit is contained in:
sjat 2026-09-01 22:16:32 +02:00
parent 4dc335321d
commit 1205c139f0

View file

@ -57,6 +57,9 @@ ssh-keygen -R '[127.0.0.1]:2222' # if the tunnel
(DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended (DHCP). Moving the cable flaps the link and NM re-selects a profile — pin the intended
one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts. one sticky (`autoconnect yes` + higher priority) and the other off, or it reverts.
Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool). Either profile works now that the mgmt VLAN serves DHCP (`.253` from the pool).
After a re-plug the link often comes up with **no IPv4 at all** (profile active, DHCP
never retried). `nmcli connection down/up "Wired connection 1"` fixes it — check for an
address before concluding the cable is in the wrong port.
- The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console - The `.venv` was built under `/home/sjat/…`; on a checkout at another path its console
scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv — scripts fail with exit 126 (stale shebang). Fix the shebangs or rebuild the venv —
the system `ansible` is not a substitute (no paramiko, newer `community.general`). the system `ansible` is not a substitute (no paramiko, newer `community.general`).
@ -98,8 +101,9 @@ Live on the device (2026-06-09): flat L2 switch on `10.2.30.0/24` — **DATA VLA
(mgmt `192.168.88.1/24`, no gateway/NTP/DNS), `vlan-filtering` on. The mgmt port also (mgmt `192.168.88.1/24`, no gateway/NTP/DNS), `vlan-filtering` on. The mgmt port also
serves DHCP (`192.168.88.10-.254`) + the web UI as a makerspace experiment (flags serves DHCP (`192.168.88.10-.254`) + the web UI as a makerspace experiment (flags
`switch_web_enabled`, `switch_mgmt_dhcp_enabled`). Default `admin` disabled. Operators `switch_web_enabled`, `switch_mgmt_dhcp_enabled`). Default `admin` disabled. Operators
(2026-09-01): `sjat` (keys: mamba seat + `claude@ubongo` automation seat) and `claus` (2026-09-01): `sjat` (keys: mamba seat + `claude@ubongo` automation seat), `claus`
(`claus@stjerno.dk`), both group `full`, both managed by `switch_operators` in `host_vars`. (`claus@stjerno.dk`) and `lars` (`lars@hrossen.dk`, the same key he uses on the MakerFLOSS
forgejo and VPS), all group `full`, all managed by `switch_operators` in `host_vars`.
All task files + `play_bootstrap`/`play_backup` are idempotency-verified. Design + cutover runbook: All task files + `play_bootstrap`/`play_backup` are idempotency-verified. Design + cutover runbook:
`docs/superpowers/specs/2026-06-09-crs310-flat-mgmtvlan-design.md`. `docs/superpowers/specs/2026-06-09-crs310-flat-mgmtvlan-design.md`.