Skip to content

docs(runbook): name the switch's firewall rules, and delete a stale one in the window (#444) - #913

Merged
Gerrrt merged 3 commits into
mainfrom
gerrrt/homelab-issue-444-window-rules
Oct 5, 2026
Merged

Gerrrt merged 3 commits into
mainfrom
gerrrt/homelab-issue-444-window-rules

Conversation

@Gerrrt

@Gerrrt Gerrrt commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Phase 2 of swap-the-switch.md now names the firewall rules it touches, as read from pfctl -sr on morpheus on 2026-10-05:

  • Step 1: Allow HTTP to LAN Switch, on the Hicks interface. Copy it with port 443 rather than editing it, so both ports are open during the window.
  • Step 7: delete the HTTP original and keep the HTTPS copy.
  • Step 8, new: delete Allow blackbox probe from Prometheus to Switch on the Winterfell interface (10.0.99.20 → 10.7.7.2:80). blackbox.yaml says it was dropped and no probe uses it, but it is still live. Once plain www is off it reaches nothing.

Docs only.

Refs #444

🤖 Generated with Claude Code

…ne in the window (#444)

Phase 2 named the pass for the switch UI only as "the rule in network.md".
On morpheus it is Allow HTTP to LAN Switch on the Hicks interface. Step 1
now names it and says to copy it with port 443 rather than edit it. Step 7
deletes the HTTP original.

pfctl -sr also lists Allow blackbox probe from Prometheus to Switch on the
Winterfell interface, 10.0.99.20 to 10.7.7.2:80. blackbox.yaml says that
rule was dropped and no probe uses it. A new step 8 deletes it once plain
www is off, and leaves the SNMP rule beside it.

Refs #444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 05:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Phase 2 requires a nonexistent switch-ui probe to be green.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Names firewall rules involved in the switch replacement and adds removal of an obsolete monitoring rule.

Changes:

  • Copies the HTTP rule to HTTPS before migration.
  • Deletes obsolete HTTP rules after validation.
File Description
docs/​runbooks/​swap-the-switch.md Clarifies Phase 2 firewall operations.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/runbooks/swap-the-switch.md
Gerrrt and others added 2 commits October 5, 2026 05:39
…that was removed (#444)

Step 6 said to confirm the switch-ui probe was green. That probe was
removed on 2026-09-06, as blackbox.yaml records, so the step could not be
passed as written. It now checks only up{job="snmp"}, because step 4
already proves the UI. The Phase 3 item about the probe is left to #653,
which rewrites it.

Refs #444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…o move (#444)

Phase 3 said to move the switch-ui blackbox target from http to https.
Both probes were removed on 2026-09-06, so there is nothing to move. This
takes #653's wording for the item, decided 2026-09-23: the probe is not
brought back, and the leaf's expiry becomes a dated row in
successor-handover.md instead. The last sentence says this phase adds that
row, because on main it does not exist yet.

Refs #444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Gerrrt
Gerrrt enabled auto-merge (squash) October 5, 2026 05:42
@Gerrrt
Gerrrt merged commit 827c6ee into main Oct 5, 2026
8 checks passed
@Gerrrt
Gerrrt deleted the gerrrt/homelab-issue-444-window-rules branch October 5, 2026 05:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants