From 30df7d70d360c6cc945622fe414b985993fc12e8 Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Sun, 4 Oct 2026 23:49:37 +0000 Subject: [PATCH 1/5] docs(hardware): the CRS326's 24HPOW was delivered 2026-09-26 (#444) The 24 V adapter the bench steps were waiting on was delivered on the evening of 2026-09-26, the same day the changelog called it still in transit. hardware.md, roadmap.md and swap-the-switch.md went on saying that for eight days. The roadmap's gate is now Phase 1 at the bench, which has not started, then a rack window. The runbook's intake step pointed at an "in transit" line that no longer exists, so it now names the line hardware.md keeps for the intake facts. The changelog gets a dated correction rather than an edit to the 2026-09-26 entry. Refs #444 Co-Authored-By: Claude Opus 5.5 --- docs/changelog.md | 6 ++++++ docs/hardware.md | 7 ++++--- docs/roadmap.md | 5 +++-- docs/runbooks/swap-the-switch.md | 8 +++++--- 4 files changed, 18 insertions(+), 8 deletions(-) diff --git a/docs/changelog.md b/docs/changelog.md index c0a38aa5..e7217964 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -19,6 +19,12 @@ docstring gives: it is a record, not a claim about now. ## 2026-10-04 +- **The CRS326's 24HPOW was delivered on 2026-09-26**, the evening of the + day the 2026-09-26 entry below called it still in transit. The repository + went on saying so for eight days. Nothing but the bench time gates Phase 1 + of [`swap-the-switch.md`](runbooks/swap-the-switch.md) now, and it has not + started ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). + - **`deploy-agent.sh` proves the log path with a line it writes itself.** Its arrival check asked Loki for any line from the host newer than the deploy. golem, an idle backup server, logged nothing in the three minutes, diff --git a/docs/hardware.md b/docs/hardware.md index cbdcb1d5..e410ff3e 100644 --- a/docs/hardware.md +++ b/docs/hardware.md @@ -732,8 +732,8 @@ revisions of this repository treated `shiva` as the hypervisor itself. `DC 10–28V`, beside a ground screw, with a blank plate where other units carry an inlet. PoE-in on port 1 is the other input. MikroTik rates the unit at 24 W maximum. A MikroTik 24HPOW[^24HPOW] (24 V, 2.5 A, North - American cord) was ordered 2026-09-23 and is in transit, and the bench - steps wait for it + American cord) was ordered 2026-09-23 and delivered 2026-09-26, so nothing + but the bench time gates Phase 1 now ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). **Not 48POW:** it is MikroTik's too, has the same plug, and puts 48 V into a jack labelled 10–28 V. The replacement for @@ -762,7 +762,8 @@ revisions of this repository treated `shiva` as the hypervisor itself. management MAC, that the rack ears and the power supply are in the box, and a netinstall or factory reset before it touches the network — a used RouterOS device arrives with whatever its last owner left on it, users - included. Those go here when it lands. + included. Those go here when the bench steps are done; as of 2026-10-04 the + switch has not been powered on. - USB stick holding the pfSense installer — **written 2026-09-27 and used for #92's rehearsal; it belongs in the rack beside the KVM.** It holds the **Netgate Installer**, which downloads the release during the install: diff --git a/docs/roadmap.md b/docs/roadmap.md index 993784d7..95eba77c 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -52,8 +52,9 @@ Closes when it is empty. - **[#444](https://github.com/Gerrrt/HomeLab/issues/444) Swap the MokerLink for the CRS326.** Decided by [ADR-0041](adr/0041-run-the-crs326-on-routeros-and-keep-neo-and-its-switch-lan.md). - The switch has been in hand since 2026-09-23, without a power adapter. - Gate: the 24HPOW landing, and a rack window outside working hours — `neo` + The switch has been in hand since 2026-09-23 and its 24HPOW since + 2026-09-26. Gate: Phase 1 at the bench, which has not started, then a rack + window outside working hours — `neo` carries every VLAN, so the swap cannot share the day with anyone working on them. → [runbook](runbooks/swap-the-switch.md) - **[#84](https://github.com/Gerrrt/HomeLab/issues/84) Retire the MokerLink's diff --git a/docs/runbooks/swap-the-switch.md b/docs/runbooks/swap-the-switch.md index 70a6a63c..96a51c5e 100644 --- a/docs/runbooks/swap-the-switch.md +++ b/docs/runbooks/swap-the-switch.md @@ -101,10 +101,12 @@ Confirm the OS and version it booted, the serial and the management MAC: Check the box for rack ears and a power supply — it is a used listing. **This model is DC-only**: a `DC 10–28V` barrel jack and no AC inlet, so "a power supply" means MikroTik's 24 V adapter, and the unit bought for this swap -arrived without one (2026-09-23). A 48 V MikroTik adapter has the same plug +arrived without one (2026-09-23); a 24HPOW was delivered for it on +2026-09-26. A 48 V MikroTik adapter has the same plug and is outside the jack's range. **These -facts go into [`hardware.md`](../hardware.md)**, replacing the "in transit" -line, and that edit can land on its own before the window. +facts go into [`hardware.md`](../hardware.md)**, replacing its "go here when +the bench steps are done" line, and that edit can land on its own before the +window. ### 1.3 Reset, then RouterOS From 56e0d5ecc421d9eab6495ba6fdff76bdcd22bc49 Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Sun, 4 Oct 2026 23:54:14 +0000 Subject: [PATCH 2/5] docs(roadmap): #444's entry states only its gate The roadmap admits a link, the gate, the order and why, and no date that is not a gate. The delivery dates and the not-started status belong to hardware.md, the changelog and the issue, which already carry them. Refs #444 Co-Authored-By: Claude Opus 5.5 --- docs/roadmap.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/docs/roadmap.md b/docs/roadmap.md index 95eba77c..a056fdfc 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -52,9 +52,7 @@ Closes when it is empty. - **[#444](https://github.com/Gerrrt/HomeLab/issues/444) Swap the MokerLink for the CRS326.** Decided by [ADR-0041](adr/0041-run-the-crs326-on-routeros-and-keep-neo-and-its-switch-lan.md). - The switch has been in hand since 2026-09-23 and its 24HPOW since - 2026-09-26. Gate: Phase 1 at the bench, which has not started, then a rack - window outside working hours — `neo` + Gate: Phase 1 at the bench, then a rack window outside working hours — `neo` carries every VLAN, so the swap cannot share the day with anyone working on them. → [runbook](runbooks/swap-the-switch.md) - **[#84](https://github.com/Gerrrt/HomeLab/issues/84) Retire the MokerLink's From 03d0ee2347fcbf4ce7f227a47a05611205c6c45a Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Mon, 5 Oct 2026 01:25:34 +0000 Subject: [PATCH 3/5] docs(hardware): the CRS326's intake, and its climb to RouterOS 7 (#444) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Phase 1 began at the bench. hardware.md gets what the runbook's intake step asked for: revision r2, the serial, the management MAC, and the RouterOS it arrived on (6.48.6, with MikroTik's default configuration). It went to 6.49.22 and then to 7.23.7 long-term, with matching RouterBOOT firmware, before the reset. 24 copper ports cover every copper port in use on the MokerLink, so no SFP+ module is needed. swap-the-switch.md §1.3 now says to upgrade to v7 first. Its commands are written for v7, and this unit came on an end-of-life v6. The section says how to do it with no internet at the bench, how to find which version is long-term, and that reconnecting after the reset is by MAC in WinBox. Refs #444 Co-Authored-By: Claude Opus 5.5 --- docs/changelog.md | 12 ++++++++++++ docs/hardware.md | 9 +++++++-- docs/runbooks/swap-the-switch.md | 14 +++++++++++++- 3 files changed, 32 insertions(+), 3 deletions(-) diff --git a/docs/changelog.md b/docs/changelog.md index e7217964..5f674972 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -17,6 +17,18 @@ roadmap as it read that day, and the *Done* entries keep the shape they had there. `check_docs.py` does not check this file, for the reason its module docstring gives: it is a record, not a claim about now. +## 2026-10-05 + +- **The CRS326 is on RouterOS 7, and reset.** Phase 1 of + [`swap-the-switch.md`](runbooks/swap-the-switch.md) began at the bench + ([#444](https://github.com/Gerrrt/HomeLab/issues/444)). The MokerLink's + configuration was exported, and the port map was checked against the wiki; + port 15 is `smaug`, and no more than 24 copper ports are in use. The CRS326 + arrived on RouterOS 6.48.6, which is end of life and older than the fix for + CVE-2023-30799. The runbook's commands are written for v7, so it went to + 6.49.22 and then to 7.23.7 long-term before the reset, so the reset ran on + the version it keeps. [`hardware.md`](hardware.md) has the serial and MAC. + ## 2026-10-04 - **The CRS326's 24HPOW was delivered on 2026-09-26**, the evening of the diff --git a/docs/hardware.md b/docs/hardware.md index e410ff3e..8e2ea715 100644 --- a/docs/hardware.md +++ b/docs/hardware.md @@ -762,8 +762,13 @@ revisions of this repository treated `shiva` as the hypervisor itself. management MAC, that the rack ears and the power supply are in the box, and a netinstall or factory reset before it touches the network — a used RouterOS device arrives with whatever its last owner left on it, users - included. Those go here when the bench steps are done; as of 2026-10-04 the - switch has not been powered on. + included. **Read at the bench on 2026-10-05:** revision r2, serial + `CD010CC8FC1F`, management MAC `48:8F:5A:0E:A3:FB` (`ether1`). It booted + RouterOS 6.48.6 long-term (factory 6.44.6) with MikroTik's default + configuration. It went to 6.49.22, then to 7.23.7, the long-term release + that day, with the RouterBOOT firmware to match, and was then reset with + no defaults. Its 24 copper ports cover every copper port in use on the + MokerLink, so no SFP+ copper module is needed. - USB stick holding the pfSense installer — **written 2026-09-27 and used for #92's rehearsal; it belongs in the rack beside the KVM.** It holds the **Netgate Installer**, which downloads the release during the install: diff --git a/docs/runbooks/swap-the-switch.md b/docs/runbooks/swap-the-switch.md index 96a51c5e..9c1c50a2 100644 --- a/docs/runbooks/swap-the-switch.md +++ b/docs/runbooks/swap-the-switch.md @@ -114,7 +114,19 @@ Boot RouterOS, not SwOS. ADR-0041 records why at length; briefly, SwOS serves HTTP only and speaks SNMP v1 and v2c only, which is both of the firmware limits this purchase exists to escape. -Wipe whatever the last owner left: +**Get it onto v7 long-term first.** The commands here use v7's syntax, and +the unit bought for this swap arrived on 6.48.6, which is end of life. With no +internet at the bench, download the ARM `.npk` files on the workstation and +drop them into WebFig's *Files*, at `192.168.88.1` from a static address on +that subnet. Go to the last 6.49 first, then to v7, rebooting after each, then +run `/system/routerboard/upgrade` and reboot once more. Ask the update server +which v7 is long-term rather than guessing from the download page: +`curl https://upgrade.mikrotik.com/routeros/NEWESTa7.long-term`. The switch +has 16 MB of flash. If an upload reports not enough space, the fallback is +Netinstall, which has no macOS build. + +Wipe whatever the last owner left. This also removes `192.168.88.1`, so +reconnect with WinBox's *Neighbors* tab, by MAC: ```text /system/reset-configuration no-defaults=yes skip-backup=yes From c61da7cb22112d5a88355ffedc619150d441b9ba Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Mon, 5 Oct 2026 01:55:21 +0000 Subject: [PATCH 4/5] docs(runbook): disable RouterOS 7.23's reverse-proxy, or WebFig hangs over HTTPS (#444) At the bench, the HTTPS login page loaded without a warning and WebFig then sat on Connecting, while plain http worked. RouterOS 7.23 enables a reverse-proxy service on 443 beside www-ssl. Disabling it fixed it. Step 1.4 now disables it, with ftp, telnet, api and api-ssl, which a reset to no defaults also leaves on. It also says to set the clock by hand, because on the bench the switch has nothing to take time from. Refs #444 Co-Authored-By: Claude Opus 5.5 --- docs/runbooks/swap-the-switch.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/docs/runbooks/swap-the-switch.md b/docs/runbooks/swap-the-switch.md index 9c1c50a2..993b905a 100644 --- a/docs/runbooks/swap-the-switch.md +++ b/docs/runbooks/swap-the-switch.md @@ -166,6 +166,20 @@ Confirm the browser trusts it without a warning. If it does not, the leaf is wrong or the CA is not installed on the workstation — fix that here, where there is no outage running. +**RouterOS 7.23 also puts a `reverse-proxy` service on `443`, enabled.** With +it on, the HTTPS login page loads without a warning and WebFig then sits on +"Connecting" while plain `http` works (2026-10-05). Disable it, along with the +other services that a reset to no defaults leaves on and nothing here uses: + +```text +/ip/service/disable reverse-proxy,ftp,telnet,api,api-ssl +``` + +That leaves `ssh`, `winbox` (the way back in by MAC), `www` until Phase 2 and +`www-ssl`. A reset switch has nothing to take time from on the bench and +keeps whatever date it last had, so set the clock by hand in UTC with +`/system/clock/set`. + ### 1.5 SNMPv3, and no v2c Follow §4 of [`rotate-snmp-community.md`](rotate-snmp-community.md) for the From bcdd07f71160153b974b05e7e79d012543e4564f Mon Sep 17 00:00:00 2001 From: Garrett Allen <98648590+Gerrrt@users.noreply.github.com> Date: Mon, 5 Oct 2026 02:06:08 +0000 Subject: [PATCH 5/5] docs(changelog): Phase 1 of the switch swap is done at the bench (#444) What the CRS326 was given at the bench: the identity, TLS from the estate CA, the services left on, one SNMPv3 user and no v2c, and the bridge built from the wiki's port map. VLAN 1 holds only the bridge and port 1, so an access port can no longer reach the switch's management, which the MokerLink allowed. The SNMP proof needs the switch racked, so it moves to Phase 2. Refs #444 Co-Authored-By: Claude Opus 5.5 --- docs/changelog.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/docs/changelog.md b/docs/changelog.md index 5f674972..b0d28ee4 100644 --- a/docs/changelog.md +++ b/docs/changelog.md @@ -28,6 +28,22 @@ docstring gives: it is a record, not a claim about now. CVE-2023-30799. The runbook's commands are written for v7, so it went to 6.49.22 and then to 7.23.7 long-term before the reset, so the reset ran on the version it keeps. [`hardware.md`](hardware.md) has the serial and MAC. +- **Phase 1 is done at the bench, apart from the SNMP proof.** + - The identity is `neo`. + - `www-ssl` serves the estate-CA leaf, and a browser at `10.7.7.2` showed + no warning. That needed `reverse-proxy` disabled, which 7.23 enables on + the same port. + - `ftp`, `telnet`, `api` and `api-ssl` are off. + - SNMP has one v3 user, `prometheus` (SHA1/AES), limited to `10.0.99.20`, + and the default `public` community is disabled. + - The bridge follows the wiki's 2026-09-17 port map. Port 1 is the trunk, + with all six VLANs tagged and management untagged on VLAN 1. Ports 2–24 + accept untagged frames only, each with its VLAN as PVID. VLAN 1 holds only + the bridge and port 1, so management is not reachable from an access port, + as it was on the MokerLink. The SFP+ cages are disabled. There is no + mirroring. + - `snmp-verify.sh` cannot reach a switch on a desk, so the v3-only proof + moves to Phase 2. ## 2026-10-04