fisi is decommissioned and boma retired Netbird (ADR-036), so the old
Claude-on-fisi/Netbird access doctrine is gone. New order: VPS bastion
ProxyJump onto wg1 (primary, isolation-clean), via mamba over the boma hub
when on-site. Netbird control plane kept but demoted to legacy (operator
decision, not an access path). Network map refreshed from live probing
2026-07-17: rack LAN is 10.0.0.0/24, wifi 172.17.3.0/24 does not route to
it, 10.2.30.0/24 likely gone. Incident log covers the srv07/mf04 identity
fix and re-established access.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Switch mgmt-VLAN DHCP advertised a default gateway (192.168.88.1) that
stole mamba's default route from WiFi, cutting the netbird underlay to
askari. Fixed client-side with never-default/high-metric/ignore-auto-dns
on the wired NetworkManager profile; WiFi stays default, tunnel holds.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
One-command vault edit (replace flossfw.public_key) + wireguard-server
redeploy + verify handshake, for when the TaPPaaS operator sends their
WireGuard public key.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Standalone plan for the TaPPaaS operator's Claude Code: WireGuard client
(peer 10.13.0.9, split-tunnel), Caddy plain-HTTP backend on 10.13.0.9:80,
firewall lock to 10.13.0.1, internal split-horizon DNS. Bakes in the
verified VPS-side contract (hub endpoint/pubkey, preserved Host, *.tappaas
wildcard, public DNS) and the key-exchange handshake. Flags the internal-TLS
decision (internal CA vs Gandi DNS-01 vs no internal TLS).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Split-horizon DNS + public exposure under *.tappaas.makerfloss.eu,
reusing the proven mf01 publishing pattern (new wg1 peer, TLS terminates
at VPS, plain HTTP over wg1 to TaPPaaS Caddy). TaPPaaS-side config repo
left as an open item.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
How to publish HTTP services as <svc>.mf01.makerfloss.eu (VPS-terminated
TLS, wg1 inner hop, mf01 internal Traefik). Built + verified 2026-06-09.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- data ports give 10.2.30.0/24 (sjat got .227), gw 10.2.30.1
- 10.2.30.0/24 and 10.0.0.0/24 inter-route via makerspace router
- note mf04 IP drift: actual 10.0.0.183, host_vars says .184
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Scaffold for troubleshooting MakerFLOSS hosts at the makerspace.
Reference + thin runbooks model — authoritative data stays in the
source repos (AnsibleBaobabV4, MakerFLOSS_Mikrotik, MakerFLOSS).
- access.md: reach paths for mamba-on-LAN and fisi-tunneling-in
(netbird on-demand, VPS bastion, ProxyJump via kuku->mamba),
with the isolation rule.
- network-map.md: subnet pointers + open question on makerspace
addressing (10.2.30/172.17.3/10.0.0).
- runbooks/switch-crs310.md: CRS310 connectivity + lockout recovery.
- incidents/: dated log scaffold.
- CLAUDE.md: operating rules for this repo.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>