links below. Confirm live values before acting. Refreshed 2026-07-17 from
live probing (mamba wired on the rack LAN + the wg1 hub + mf01).
## Subnets seen live on 2026-07-17
| Subnet | Role | Notes / source of truth |
|--------|------|-------------------------|
| `10.0.0.0/24` | **Makerspace rack LAN** (the subnet you get wired into the rack switching). Gw `.1` (FreeBSD — likely flossfw). srv07 `.183`, mf01 `.223` (both DHCP, ssh `:7576`). Unidentified: Debian 13 trio `.10/.11/.12` (ssh `:22`, likely TaPPaaS nodes), ssh hosts `.158/.165/.209`. | live scan 2026-07-17; `AnsibleBaobabV4/host_vars/srv07.yml`, `mf01.yml` |
| `172.17.3.0/24` | **OrangeMakers house LAN / wifi** (mamba's wifi lands here). Does **not** route to `10.0.0.0/24`. `makerfloss1` recorded at `.51` — did not answer. Seen: a Raspberry Pi `.66`, a Debian 12 box `.215` (neither is ours). | live scan 2026-07-17 |
| `100.99.0.0/16` | **Netbird overlay** (legacy, kept for now — see `access.md` §D). Control plane `nb.makerfloss.eu` up; srv07 agent still enrolled (`100.99.133.190`); fisi peer gone (host decommissioned); ubongo deliberately not enrolled. | `specs/2026-05-27-makerspace-vpn-design.md` |
| `10.99.0.0/24` | **boma WireGuard hub** (homelab plane — hub on askari `.1`; ubongo `.2`, mamba `.10`). Only relevance here: it's how Claude reaches mamba from ubongo. Never bridged to makerspace nets. | `boma` repo, ADR-036 |
| `192.168.88.0/24` | CRS310 (sw01) mgmt VLAN — switch at `.1`, reachable only from the mgmt port. Post-recabling state **unverified**; sw01 p8 (mgmt) is patched out via pp01:3 and currently non-active. | `MakerFLOSS_Mikrotik`, switch runbook |
| `10.2.30.0/24` | Former CRS310 data VLAN 30. **Probably gone** — mf01 moved off it onto `10.0.0.x`, and nothing answered on it 2026-07-17. Treat references to it (older specs, host comments) as historical. | historical: `specs/2026-06-09-crs310-flat-mgmtvlan-design.md` |
## Open questions (check when on-site)
- **makerfloss1:** where is it, and is it still alive? Neither its LAN IP nor
its wg1 peer answered.
- **The `.10/.11/.12` trio and `.158/.165/.209`:** identify and label
(TAPPaaS nodes? APs?). Add to the hardware docs once known.
- **Switch mgmt path** after the rack re-cabling (sw01/sw06/sw07): confirm
how to reach `192.168.88.1` and update the switch runbook.