fisi is decommissioned and boma retired Netbird (ADR-036), so the old Claude-on-fisi/Netbird access doctrine is gone. New order: VPS bastion ProxyJump onto wg1 (primary, isolation-clean), via mamba over the boma hub when on-site. Netbird control plane kept but demoted to legacy (operator decision, not an access path). Network map refreshed from live probing 2026-07-17: rack LAN is 10.0.0.0/24, wifi 172.17.3.0/24 does not route to it, 10.2.30.0/24 likely gone. Incident log covers the srv07/mf04 identity fix and re-established access. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2.3 KiB
2.3 KiB
CLAUDE.md — MakerFLOSS_Troubleshooting
Operating guide for working in this repo. This is a troubleshooting workspace for MakerFLOSS hosts at the Orange Makerspace.
What this repo is
Reference + thin runbooks. It does not hold authoritative IPs/topology/secrets — those live in the source repos. Keep it that way; link, don't copy.
Source repos (authoritative — most fixes land here)
~/Projects/AnsibleBaobabV4— canonical infra-as-code: makerfloss VPS,makerfloss1,mf04,wg1WireGuard plane, Netbird control plane, all containers. Git remote = baobab Forgejo. Has Ansible vault (prod).~/Projects/MakerFLOSS_Mikrotik— the CRS310 switch. Ansible vault (makerfloss). Strict lockout-safety rules — read its CLAUDE.md before touching the device.~/Projects/MakerFLOSS— docs/slides site (docs.makerfloss.eu).
Rules (decided 2026-06-09)
- Fixes go to the relevant source repo's
main. Apply directly there, then run. For live switch/infra, follow that repo's idempotency + lockout-safety rules (run device plays twice; enable VLAN-filtering last; detached self-reverting jobs for mgmt changes). - Access path for Claude (on ubongo): the VPS bastion. Single ProxyJump
via
makerfloss.eu:7576onto thewg1overlay addresses; via mamba (boma wg hub) when it's on-site and the LAN is needed raw. ubongo has no Netbird agent and must not join makerspace overlays. Isolation is a hard requirement — nothing from the makerspace should be able to reach the homelab. See access.md §C/§E. (Updated 2026-07-17; fisi is decommissioned.) - Reference, don't duplicate. When you need a fact, link to the source-repo file. If you cache a value here, note it can drift.
- Log real work in incidents/ — symptom, root cause, the source-repo commit, verification.
- Never commit secrets. Vault keys live under
~/.ansible/vault-keys/.
Start-of-session checklist
- access.md — pick a reach path for where you are.
- network-map.md — confirm host/subnet (note the open question about makerspace addressing).
- runbooks/ — find or write the runbook.
- Verify with evidence before claiming a fix works.