Commit graph

6 commits

Author SHA1 Message Date
1205c139f0 docs: record lars as operator + the NM no-lease-after-replug trap
Applied to the device and idempotency-verified (run 1 changed=1, run 2
changed=0). Also notes the NetworkManager behaviour that looked like a
mis-plugged cable: after a re-plug the wired profile stays active with no
IPv4 until the connection is cycled.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 22:16:32 +02:00
e6c1651da1 feat(users): model operators as accounts; add claus
Replace the single `switch_admin_user` day-2 task with a `switch_operators`
list in host_vars: one RouterOS user per person, each with the public keys
that may log in as it. Logins become attributable and revocable per person
instead of accreting as extra keys on `sjat`.

Adds claus@stjerno.dk as user `claus` (group full), and codifies the two
keys already on the device (sjat's mamba seat, the claude@ubongo automation
seat that was hand-imported earlier today).

Two things the mechanism has to get right:
- Idempotency: query /user/ssh-keys first and upload only missing keys.
  An unconditional net_put reports changed on every run.
- No passwordless accounts: WinBox/console accept an empty password and
  WinBox is deliberately left on for recovery, so each operator gets a
  vaulted password. users.yml asserts one exists before touching anything.

Verified: yamllint, ansible-lint (production), syntax-check, and the play
run twice against crs310-maker — second run changed=0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 20:29:18 +02:00
d96ec189d4 fix: repair stdout callback + refresh the access recipe
community.general 12 removed the `yaml` stdout callback, so every ansible
invocation died with a [DEPRECATED] error. Use the core default callback
with `callback_result_format = yaml` — identical output, no collection dep.

CLAUDE.md's access recipe still described the retired `-J kuku … 10.8.0.4`
hop; `mamba` is now an ssh alias over the wg overlay. Also record two things
that cost time on the 2026-09-01 bench session: the vaulted admin password
cannot authenticate over SSH at all (RouterOS refuses password auth for a
user holding an SSH key while always-allow-password-login=no), so each
operator seat needs its own key imported; and the checked-in .venv carries
shebangs from the original /home/sjat path.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 20:20:46 +02:00
sjat
2796616d05 docs: capture topology + operational learnings in CLAUDE.md/README
Bring the everyday guides up to the live state (flat data VLAN 30 + isolated mgmt
VLAN 99 on ether8, DHCP + web UI experiment) and record the gotchas that cost time:
the bench tunnel (paramiko ignores ProxyJump), mamba NM-profile stickiness on cable
flap, the RouterOS find-by-address quirk, and the commit-confirmed detached-flip
pattern for lockout-prone changes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 13:04:35 +02:00
sjat
67554c0b38 docs: mark domain tasks implemented; note deferred vlans device run
Implements Task 10 doc updates. README/CLAUDE/role-README now reflect that all
task files + play_bootstrap/play_backup are implemented and idempotency-verified,
that vlans is built+validated but its device run is deferred (placeholder topology,
on-site recovery needed), and that the bootstrap/backup plays exist. Corrects the
bootstrap invocation example (-e ansible_user=admin --ask-pass).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 19:45:36 +02:00
sjat
12001abac6 docs: README, role README, CLAUDE.md
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 19:22:43 +02:00