From 47e3bdc8f50dc5b44ed7bd24bccd8b70481ee64d Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 3 Oct 2026 22:40:01 +1000 Subject: [PATCH] Add router role for prodnxsr0020 (#536) prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq. - add roles::infra::network::router (base + frrouting + frr_exporter) - enable ip_forward and disable rp_filter via sysctl::base - add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160) - pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP - listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP - keep resolv.conf on the local dnsmasq (127.0.0.1) Reviewed-on: https://git.unkin.net/unkin/puppet-prod/pulls/536 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- .../nodes/prodnxsr0020.main.unkin.net.yaml | 45 +++++++++++++++++++ hieradata/roles/infra/network/router.yaml | 26 +++++++++++ site/roles/manifests/infra/network/router.pp | 12 +++++ 3 files changed, 83 insertions(+) create mode 100644 hieradata/nodes/prodnxsr0020.main.unkin.net.yaml create mode 100644 hieradata/roles/infra/network/router.yaml create mode 100644 site/roles/manifests/infra/network/router.pp diff --git a/hieradata/nodes/prodnxsr0020.main.unkin.net.yaml b/hieradata/nodes/prodnxsr0020.main.unkin.net.yaml new file mode 100644 index 0000000..4d58a76 --- /dev/null +++ b/hieradata/nodes/prodnxsr0020.main.unkin.net.yaml @@ -0,0 +1,45 @@ +--- +# primary interface is the WAN uplink; pin host identity to the dum0 loopback +networking_loopback0_ip: 198.18.2.160 +networking_loopback1_ip: 198.18.21.160 + +# dns: keep the local dnsmasq resolver +profiles::dns::base::nameservers: + - 127.0.0.1 +profiles::dns::base::search: + - main.unkin.net +profiles::dns::base::primary_interface: dum0 +profiles::dns::updater::deny_ranges: + - 198.18.199.0/24 + - 198.18.200.0/24 + - 10.42.0.0/16 + - 10.43.0.0/16 + - 10.10.12.0/24 # wg0 + - 103.216.190.0/23 # wan uplink +profiles::consul::client::host_addr: "%{hiera('networking_loopback0_ip')}" + +# ssh: listen on localhost and dum0 only; knock out the common wan primary ip +lookup_options: + ssh::server::options: + merge: + strategy: deep + knockout_prefix: '--' +ssh::server::options: + ListenAddress: + - "--%{facts.networking.ip}" + - 127.0.0.1 + - "%{hiera('networking_loopback0_ip')}" +profiles::ssh::sign::principals: + - "%{hiera('networking_loopback0_ip')}" + +# frrouting +frrouting::ospfd_router_id: "%{hiera('networking_loopback0_ip')}" +frrouting::ospfd_interfaces: + dum0: + area: 0.0.0.0 + dum1: + area: 0.0.0.0 + bond0.201: + area: 0.0.0.0 +frrouting::ospf_preferred_source_enable: true +frrouting::ospf_preferred_source: "%{hiera('networking_loopback1_ip')}" diff --git a/hieradata/roles/infra/network/router.yaml b/hieradata/roles/infra/network/router.yaml new file mode 100644 index 0000000..91ef40b --- /dev/null +++ b/hieradata/roles/infra/network/router.yaml @@ -0,0 +1,26 @@ +--- +hiera_include: + - frrouting + - exporters::frr_exporter + +# routing +sysctl::base::values: + net.ipv4.ip_forward: + value: '1' + net.ipv4.conf.all.rp_filter: + value: '0' + net.ipv4.conf.default.rp_filter: + value: '0' + +# frrouting +exporters::frr_exporter::enable: true +frrouting::ospfd_redistribute: + - connected +frrouting::daemons: + ospfd: true + +# consul +profiles::consul::client::node_rules: + - resource: service + segment: frr_exporter + disposition: write diff --git a/site/roles/manifests/infra/network/router.pp b/site/roles/manifests/infra/network/router.pp new file mode 100644 index 0000000..3a48da7 --- /dev/null +++ b/site/roles/manifests/infra/network/router.pp @@ -0,0 +1,12 @@ +# roles::infra::network::router +# an ospf router; frr only, interfaces and firewall are managed outside puppet +# +class roles::infra::network::router { + if $facts['firstrun'] { + include profiles::defaults + include profiles::firstrun::init + }else{ + include profiles::defaults + include profiles::base + } +}