Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 34 additions & 0 deletions docs/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,42 @@ roadmap as it read that day, and the *Done* entries keep the shape they had
there. `check_docs.py` does not check this file, for the reason its module
docstring gives: it is a record, not a claim about now.

## 2026-10-05

- **The CRS326 is on RouterOS 7, and reset.** Phase 1 of
[`swap-the-switch.md`](runbooks/swap-the-switch.md) began at the bench
([#444](https://github.com/Gerrrt/HomeLab/issues/444)). The MokerLink's
configuration was exported, and the port map was checked against the wiki;
port 15 is `smaug`, and no more than 24 copper ports are in use. The CRS326
arrived on RouterOS 6.48.6, which is end of life and older than the fix for
CVE-2023-30799. The runbook's commands are written for v7, so it went to
6.49.22 and then to 7.23.7 long-term before the reset, so the reset ran on
the version it keeps. [`hardware.md`](hardware.md) has the serial and MAC.
- **Phase 1 is done at the bench, apart from the SNMP proof.**
- The identity is `neo`.
- `www-ssl` serves the estate-CA leaf, and a browser at `10.7.7.2` showed
no warning. That needed `reverse-proxy` disabled, which 7.23 enables on
the same port.
- `ftp`, `telnet`, `api` and `api-ssl` are off.
- SNMP has one v3 user, `prometheus` (SHA1/AES), limited to `10.0.99.20`,
and the default `public` community is disabled.
- The bridge follows the wiki's 2026-09-17 port map. Port 1 is the trunk,
with all six VLANs tagged and management untagged on VLAN 1. Ports 2–24
accept untagged frames only, each with its VLAN as PVID. VLAN 1 holds only
the bridge and port 1, so management is not reachable from an access port,
as it was on the MokerLink. The SFP+ cages are disabled. There is no
mirroring.
- `snmp-verify.sh` cannot reach a switch on a desk, so the v3-only proof
moves to Phase 2.

## 2026-10-04

- **The CRS326's 24HPOW was delivered on 2026-09-26**, the evening of the
day the 2026-09-26 entry below called it still in transit. The repository
went on saying so for eight days. Nothing but the bench time gates Phase 1
of [`swap-the-switch.md`](runbooks/swap-the-switch.md) now, and it has not
started ([#444](https://github.com/Gerrrt/HomeLab/issues/444)).

- **`deploy-agent.sh` proves the log path with a line it writes itself.**
Its arrival check asked Loki for any line from the host newer than the
deploy. golem, an idle backup server, logged nothing in the three minutes,
Expand Down
12 changes: 9 additions & 3 deletions docs/hardware.md
Original file line number Diff line number Diff line change
Expand Up @@ -732,8 +732,8 @@ revisions of this repository treated `shiva` as the hypervisor itself.
`DC 10–28V`, beside a ground screw, with a blank plate where other units
carry an inlet. PoE-in on port 1 is the other input. MikroTik rates the
unit at 24 W maximum. A MikroTik 24HPOW[^24HPOW] (24 V, 2.5 A, North
American cord) was ordered 2026-09-23 and is in transit, and the bench
steps wait for it
American cord) was ordered 2026-09-23 and delivered 2026-09-26, so nothing
but the bench time gates Phase 1 now
([#444](https://github.com/Gerrrt/HomeLab/issues/444)). **Not 48POW:** it
is MikroTik's too, has the same plug, and puts 48 V into a jack labelled
10–28 V. The replacement for
Expand Down Expand Up @@ -762,7 +762,13 @@ revisions of this repository treated `shiva` as the hypervisor itself.
management MAC, that the rack ears and the power supply are in the box, and
a netinstall or factory reset before it touches the network — a used
RouterOS device arrives with whatever its last owner left on it, users
included. Those go here when it lands.
included. **Read at the bench on 2026-10-05:** revision r2, serial
`CD010CC8FC1F`, management MAC `48:8F:5A:0E:A3:FB` (`ether1`). It booted
RouterOS 6.48.6 long-term (factory 6.44.6) with MikroTik's default
configuration. It went to 6.49.22, then to 7.23.7, the long-term release
that day, with the RouterBOOT firmware to match, and was then reset with
no defaults. Its 24 copper ports cover every copper port in use on the
MokerLink, so no SFP+ copper module is needed.
- USB stick holding the pfSense installer — **written 2026-09-27 and used
for #92's rehearsal; it belongs in the rack beside the KVM.** It holds the
**Netgate Installer**, which downloads the release during the install:
Expand Down
3 changes: 1 addition & 2 deletions docs/roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,8 +52,7 @@ Closes when it is empty.
- **[#444](https://github.com/Gerrrt/HomeLab/issues/444) Swap the MokerLink
for the CRS326.** Decided by
[ADR-0041](adr/0041-run-the-crs326-on-routeros-and-keep-neo-and-its-switch-lan.md).
The switch has been in hand since 2026-09-23, without a power adapter.
Gate: the 24HPOW landing, and a rack window outside working hours — `neo`
Gate: Phase 1 at the bench, then a rack window outside working hours — `neo`
carries every VLAN, so the swap cannot share the day with anyone working
on them. → [runbook](runbooks/swap-the-switch.md)
- **[#84](https://github.com/Gerrrt/HomeLab/issues/84) Retire the MokerLink's
Expand Down
36 changes: 32 additions & 4 deletions docs/runbooks/swap-the-switch.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,18 +101,32 @@ Confirm the OS and version it booted, the serial and the management MAC:
Check the box for rack ears and a power supply — it is a used listing. **This
model is DC-only**: a `DC 10–28V` barrel jack and no AC inlet, so "a power
supply" means MikroTik's 24 V adapter, and the unit bought for this swap
arrived without one (2026-09-23). A 48 V MikroTik adapter has the same plug
arrived without one (2026-09-23); a 24HPOW was delivered for it on
2026-09-26. A 48 V MikroTik adapter has the same plug
and is outside the jack's range. **These
facts go into [`hardware.md`](../hardware.md)**, replacing the "in transit"
line, and that edit can land on its own before the window.
facts go into [`hardware.md`](../hardware.md)**, replacing its "go here when
the bench steps are done" line, and that edit can land on its own before the
window.

### 1.3 Reset, then RouterOS

Boot RouterOS, not SwOS. ADR-0041 records why at length; briefly, SwOS serves
HTTP only and speaks SNMP v1 and v2c only, which is both of the firmware limits
this purchase exists to escape.

Wipe whatever the last owner left:
**Get it onto v7 long-term first.** The commands here use v7's syntax, and
the unit bought for this swap arrived on 6.48.6, which is end of life. With no
internet at the bench, download the ARM `.npk` files on the workstation and
drop them into WebFig's *Files*, at `192.168.88.1` from a static address on
that subnet. Go to the last 6.49 first, then to v7, rebooting after each, then
run `/system/routerboard/upgrade` and reboot once more. Ask the update server
which v7 is long-term rather than guessing from the download page:
`curl https://upgrade.mikrotik.com/routeros/NEWESTa7.long-term`. The switch
has 16 MB of flash. If an upload reports not enough space, the fallback is
Netinstall, which has no macOS build.

Wipe whatever the last owner left. This also removes `192.168.88.1`, so
reconnect with WinBox's *Neighbors* tab, by MAC:

```text
/system/reset-configuration no-defaults=yes skip-backup=yes
Expand Down Expand Up @@ -152,6 +166,20 @@ Confirm the browser trusts it without a warning. If it does not, the leaf is
wrong or the CA is not installed on the workstation — fix that here, where there
is no outage running.

**RouterOS 7.23 also puts a `reverse-proxy` service on `443`, enabled.** With
it on, the HTTPS login page loads without a warning and WebFig then sits on
"Connecting" while plain `http` works (2026-10-05). Disable it, along with the
other services that a reset to no defaults leaves on and nothing here uses:

```text
/ip/service/disable reverse-proxy,ftp,telnet,api,api-ssl
```

That leaves `ssh`, `winbox` (the way back in by MAC), `www` until Phase 2 and
`www-ssl`. A reset switch has nothing to take time from on the bench and
keeps whatever date it last had, so set the clock by hand in UTC with
`/system/clock/set`.

### 1.5 SNMPv3, and no v2c

Follow §4 of [`rotate-snmp-community.md`](rotate-snmp-community.md) for the
Expand Down
Loading