docs(runbook): name the switch's firewall rules, and delete a stale one in the window (#444) - #913
Merged
Merged
Conversation
…ne in the window (#444) Phase 2 named the pass for the switch UI only as "the rule in network.md". On morpheus it is Allow HTTP to LAN Switch on the Hicks interface. Step 1 now names it and says to copy it with port 443 rather than edit it. Step 7 deletes the HTTP original. pfctl -sr also lists Allow blackbox probe from Prometheus to Switch on the Winterfell interface, 10.0.99.20 to 10.7.7.2:80. blackbox.yaml says that rule was dropped and no probe uses it. A new step 8 deletes it once plain www is off, and leaves the SNMP rule beside it. Refs #444 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Phase 2 requires a nonexistent switch-ui probe to be green.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Names firewall rules involved in the switch replacement and adds removal of an obsolete monitoring rule.
Changes:
- Copies the HTTP rule to HTTPS before migration.
- Deletes obsolete HTTP rules after validation.
| File | Description |
|---|---|
docs/runbooks/swap-the-switch.md |
Clarifies Phase 2 firewall operations. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…that was removed (#444) Step 6 said to confirm the switch-ui probe was green. That probe was removed on 2026-09-06, as blackbox.yaml records, so the step could not be passed as written. It now checks only up{job="snmp"}, because step 4 already proves the UI. The Phase 3 item about the probe is left to #653, which rewrites it. Refs #444 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…o move (#444) Phase 3 said to move the switch-ui blackbox target from http to https. Both probes were removed on 2026-09-06, so there is nothing to move. This takes #653's wording for the item, decided 2026-09-23: the probe is not brought back, and the leaf's expiry becomes a dated row in successor-handover.md instead. The last sentence says this phase adds that row, because on main it does not exist yet. Refs #444 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Phase 2 of
swap-the-switch.mdnow names the firewall rules it touches, as read frompfctl -sronmorpheuson 2026-10-05:10.0.99.20 → 10.7.7.2:80).blackbox.yamlsays it was dropped and no probe uses it, but it is still live. Once plainwwwis off it reaches nothing.Docs only.
Refs #444
🤖 Generated with Claude Code