DHCP clients should resolve via the k8s bind-resolvers cluster (PureLB 198.18.200.7), not the legacy 198.18.19.15 forwarder.
- Set dnsServers to 198.18.200.7 on all five KeaSubnets.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
Replaces the isc-dhcpd PXE-boot VM with the kea-operator (v0.1.0) and an
HA kea pair, managed by ArgoCD. Deploys on a new, unused anycast IP; the
production cutover off the current dhcpd address is a separate later task.
- Add apps/base/dhcp-system: namespace, kea-operator RBAC + Deployment,
VPA, and the kea.unkin.net CRDs pulled from the operator repo at v0.1.0.
- Add the CRs translating the legacy dhcpd config: KeaCluster (2 replicas,
hot-standby HA, main.unkin.net, 1200/86400 leases, AU ntp pool), five
KeaSubnets 198.18.13-17.0/24 (gateways .254 except .17->.1 per the puppet
dhcp hieradata), Legacy/UEFI-64 PXE client classes, and the KeaAPI.
- Pin the DHCP LoadBalancer Service to the free common-pool IP 198.18.200.10
via PureLB (not the current dhcpd anycast 198.18.19.18).
- Provision the KeaAPI bearer token via an operator-generated Secret.
- Commit generated kea.unkin.net JSON schemas for kubeconform.
- Register dhcp-system in the platform ApplicationSet and AppProject.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT