diff --git a/docs/changelog.md b/docs/changelog.md index c0a38aa5..b0d28ee4 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -17,8 +17,42 @@ roadmap as it read that day, and the *Done* entries keep the shape they had there. `check_docs.py` does not check this file, for the reason its module docstring gives: it is a record, not a claim about now. +## 2026-10-05 + +- **The CRS326 is on RouterOS 7, and reset.** Phase 1 of + [`swap-the-switch.md`](runbooks/swap-the-switch.md) began at the bench + ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). The MokerLink's + configuration was exported, and the port map was checked against the wiki; + port 15 is `smaug`, and no more than 24 copper ports are in use. The CRS326 + arrived on RouterOS 6.48.6, which is end of life and older than the fix for + CVE-2023-30799. The runbook's commands are written for v7, so it went to + 6.49.22 and then to 7.23.7 long-term before the reset, so the reset ran on + the version it keeps. [`hardware.md`](hardware.md) has the serial and MAC. +- **Phase 1 is done at the bench, apart from the SNMP proof.** + - The identity is `neo`. + - `www-ssl` serves the estate-CA leaf, and a browser at `10.7.7.2` showed + no warning. That needed `reverse-proxy` disabled, which 7.23 enables on + the same port. + - `ftp`, `telnet`, `api` and `api-ssl` are off. + - SNMP has one v3 user, `prometheus` (SHA1/AES), limited to `10.0.99.20`, + and the default `public` community is disabled. + - The bridge follows the wiki's 2026-09-17 port map. Port 1 is the trunk, + with all six VLANs tagged and management untagged on VLAN 1. Ports 2–24 + accept untagged frames only, each with its VLAN as PVID. VLAN 1 holds only + the bridge and port 1, so management is not reachable from an access port, + as it was on the MokerLink. The SFP+ cages are disabled. There is no + mirroring. + - `snmp-verify.sh` cannot reach a switch on a desk, so the v3-only proof + moves to Phase 2. + ## 2026-10-04 +- **The CRS326's 24HPOW was delivered on 2026-09-26**, the evening of the + day the 2026-09-26 entry below called it still in transit. The repository + went on saying so for eight days. Nothing but the bench time gates Phase 1 + of [`swap-the-switch.md`](runbooks/swap-the-switch.md) now, and it has not + started ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). + - **`deploy-agent.sh` proves the log path with a line it writes itself.** Its arrival check asked Loki for any line from the host newer than the deploy. golem, an idle backup server, logged nothing in the three minutes, diff --git a/docs/hardware.md b/docs/hardware.md index cbdcb1d5..8e2ea715 100644 --- a/docs/hardware.md +++ b/docs/hardware.md @@ -732,8 +732,8 @@ revisions of this repository treated `shiva` as the hypervisor itself. `DC 10–28V`, beside a ground screw, with a blank plate where other units carry an inlet. PoE-in on port 1 is the other input. MikroTik rates the unit at 24 W maximum. A MikroTik 24HPOW[^24HPOW] (24 V, 2.5 A, North - American cord) was ordered 2026-09-23 and is in transit, and the bench - steps wait for it + American cord) was ordered 2026-09-23 and delivered 2026-09-26, so nothing + but the bench time gates Phase 1 now ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). **Not 48POW:** it is MikroTik's too, has the same plug, and puts 48 V into a jack labelled 10–28 V. The replacement for @@ -762,7 +762,13 @@ revisions of this repository treated `shiva` as the hypervisor itself. management MAC, that the rack ears and the power supply are in the box, and a netinstall or factory reset before it touches the network — a used RouterOS device arrives with whatever its last owner left on it, users - included. Those go here when it lands. + included. **Read at the bench on 2026-10-05:** revision r2, serial + `CD010CC8FC1F`, management MAC `48:8F:5A:0E:A3:FB` (`ether1`). It booted + RouterOS 6.48.6 long-term (factory 6.44.6) with MikroTik's default + configuration. It went to 6.49.22, then to 7.23.7, the long-term release + that day, with the RouterBOOT firmware to match, and was then reset with + no defaults. Its 24 copper ports cover every copper port in use on the + MokerLink, so no SFP+ copper module is needed. - USB stick holding the pfSense installer — **written 2026-09-27 and used for #92's rehearsal; it belongs in the rack beside the KVM.** It holds the **Netgate Installer**, which downloads the release during the install: diff --git a/docs/roadmap.md b/docs/roadmap.md index 993784d7..a056fdfc 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -52,8 +52,7 @@ Closes when it is empty. - **[#444](https://github.com/Gerrrt/HomeLab/issues/444) Swap the MokerLink for the CRS326.** Decided by [ADR-0041](adr/0041-run-the-crs326-on-routeros-and-keep-neo-and-its-switch-lan.md). - The switch has been in hand since 2026-09-23, without a power adapter. - Gate: the 24HPOW landing, and a rack window outside working hours — `neo` + Gate: Phase 1 at the bench, then a rack window outside working hours — `neo` carries every VLAN, so the swap cannot share the day with anyone working on them. → [runbook](runbooks/swap-the-switch.md) - **[#84](https://github.com/Gerrrt/HomeLab/issues/84) Retire the MokerLink's diff --git a/docs/runbooks/swap-the-switch.md b/docs/runbooks/swap-the-switch.md index 70a6a63c..993b905a 100644 --- a/docs/runbooks/swap-the-switch.md +++ b/docs/runbooks/swap-the-switch.md @@ -101,10 +101,12 @@ Confirm the OS and version it booted, the serial and the management MAC: Check the box for rack ears and a power supply — it is a used listing. **This model is DC-only**: a `DC 10–28V` barrel jack and no AC inlet, so "a power supply" means MikroTik's 24 V adapter, and the unit bought for this swap -arrived without one (2026-09-23). A 48 V MikroTik adapter has the same plug +arrived without one (2026-09-23); a 24HPOW was delivered for it on +2026-09-26. A 48 V MikroTik adapter has the same plug and is outside the jack's range. **These -facts go into [`hardware.md`](../hardware.md)**, replacing the "in transit" -line, and that edit can land on its own before the window. +facts go into [`hardware.md`](../hardware.md)**, replacing its "go here when +the bench steps are done" line, and that edit can land on its own before the +window. ### 1.3 Reset, then RouterOS @@ -112,7 +114,19 @@ Boot RouterOS, not SwOS. ADR-0041 records why at length; briefly, SwOS serves HTTP only and speaks SNMP v1 and v2c only, which is both of the firmware limits this purchase exists to escape. -Wipe whatever the last owner left: +**Get it onto v7 long-term first.** The commands here use v7's syntax, and +the unit bought for this swap arrived on 6.48.6, which is end of life. With no +internet at the bench, download the ARM `.npk` files on the workstation and +drop them into WebFig's *Files*, at `192.168.88.1` from a static address on +that subnet. Go to the last 6.49 first, then to v7, rebooting after each, then +run `/system/routerboard/upgrade` and reboot once more. Ask the update server +which v7 is long-term rather than guessing from the download page: +`curl https://upgrade.mikrotik.com/routeros/NEWESTa7.long-term`. The switch +has 16 MB of flash. If an upload reports not enough space, the fallback is +Netinstall, which has no macOS build. + +Wipe whatever the last owner left. This also removes `192.168.88.1`, so +reconnect with WinBox's *Neighbors* tab, by MAC: ```text /system/reset-configuration no-defaults=yes skip-backup=yes @@ -152,6 +166,20 @@ Confirm the browser trusts it without a warning. If it does not, the leaf is wrong or the CA is not installed on the workstation — fix that here, where there is no outage running. +**RouterOS 7.23 also puts a `reverse-proxy` service on `443`, enabled.** With +it on, the HTTPS login page loads without a warning and WebFig then sits on +"Connecting" while plain `http` works (2026-10-05). Disable it, along with the +other services that a reset to no defaults leaves on and nothing here uses: + +```text +/ip/service/disable reverse-proxy,ftp,telnet,api,api-ssl +``` + +That leaves `ssh`, `winbox` (the way back in by MAC), `www` until Phase 2 and +`www-ssl`. A reset switch has nothing to take time from on the bench and +keeps whatever date it last had, so set the clock by hand in UTC with +`/system/clock/set`. + ### 1.5 SNMPv3, and no v2c Follow §4 of [`rotate-snmp-community.md`](rotate-snmp-community.md) for the