Skip to content

Swap the MokerLink for the CRS326 (ADR-0041) #444

Description

@Gerrrt

Where this stands

Bought 2026-09-13 (#463): a used MikroTik CRS326-24G-2S+RM, in hand since 2026-09-23 without a power adapter; the MikroTik 24HPOW for it was delivered 2026-09-26. Phase 1 was done at the bench on 2026-10-05, apart from the SNMP proof, which needs the switch racked. What's left is Phase 2, the rack window. Decided by ADR-0041 ahead of the window: RouterOS over SwOS; it inherits the name neo and 10.7.7.2; www-ssl from the estate's CA with plain www off; an SNMPv3 authPriv user; port mirroring left disabled per ADR-0006. Procedure written: docs/runbooks/swap-the-switch.md, two phases — Phase 1 is two hours at a bench, everything but the cabling, and can happen the day the box lands; Phase 2 is the rack window, which shares a visit because neo carries every VLAN and no reboot happens while Mekenna is on the clock.

Moved to Nothing blocks these today: nothing in any other milestone gates it, and it is the thing that closes #84.

What the body as filed got wrong

  • SNMPv3 was never a selection criterion. ADR-0036 found the MokerLink answers v3 on the wire; the comment of 2026-09-10 called the "Move the iLO and the UPS card to SNMPv3 authPriv (ADR-0036) #85 — no SNMPv3" residual "already wrong when the issue was written". The switch was bought for the TLS management interface, the one argument left standing, with Retire the MokerLink switch's previous SNMP community #84 riding along. The buy list says so in those words.
  • "Purchases this needs: the switch, $150–350" — bought; the roadmap took the row off the buy table in the same commit.
  • "Replace neo" — the name and address stay. What is replaced is the MokerLink.

Done when

swap-the-switch.md Phase 3: snmp-verify.sh clean over GET and GETBULK against the CRS326, the UI reachable over https with the estate's chain, the MokerLink out of the rack. Then close #84, then this.


Body as filed, superseded 2026-09-19

neo is now carrying its third accepted firmware residual, and
ADR-0018 says
what to do about it: "A TLS management interface belongs in the selection
criteria whenever this switch is replaced."

This is the issue for that.

The three residuals, and why they are one purchase

  • #84 — it still accepts its
    previous SNMP community, and the stock public and private besides,
    measured twice. The firmware will not persist a deletion, and drops its SNMP
    agent on each attempt. The other three devices refuse both.
  • #85 — no SNMPv3. Three of
    four devices could move to authPriv; this one is the blocker for doing it
    uniformly.
  • ADR-0018 — no TLS listener and no certificate import, checked against the
    live device. So the switch admin password crosses the wire in cleartext,
    through neo itself
    — the device the password protects. A mirrored port or
    a foothold on the switch sees the credential to the switch. And unlike the
    SNMP communities, that one is read-write.

The roadmap already names a replacement as the thing that would close #84, #85
and ADR-0018's residual together, and records that it was never decided. This
is the decision.

Selection criteria, from ADR-0018 and #85

  • A TLS management interface.
  • SNMPv3 authPriv.
  • 24+ ports with 802.1Q.
  • Port mirroring — worth having even though
    #437 mirrors at the
    hypervisor, because it is the thing that would let the estate inspect a
    segment morpheus cannot see.

Roughly $150–350: MikroTik CRS326 around $180, TP-Link TL-SG3428 around
$200, Ubiquiti USW-Pro-24 around $380.

What replacing it costs

A cabling window with the house offline — neo carries every VLAN. Worth
pairing with another rack visit rather than scheduling its own.

Per the roadmap's own rule, the PR that acts on this edits Everything still to
buy
in the same commit.

Purchases this needs

The switch. $150–350.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsecurityA credential, an exposure, or a control that is weaker than recordedseq/1Step 1 within its milestone; same number = can run in parallel

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions