Add router role for prodnxsr0020 #536

Merged
benvin merged 3 commits from benvin/router-role into develop 2026-10-03 22:40:02 +10:00
Member

prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq.

  • add roles::infra::network::router (base + frrouting + frr_exporter)
  • enable ip_forward and disable rp_filter via sysctl::base
  • add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160)
  • pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP
  • listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP
  • keep resolv.conf on the local dnsmasq (127.0.0.1)
prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq. - add roles::infra::network::router (base + frrouting + frr_exporter) - enable ip_forward and disable rp_filter via sysctl::base - add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160) - pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP - listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP - keep resolv.conf on the local dnsmasq (127.0.0.1)
unkin-agent added 1 commit 2026-10-03 20:40:35 +10:00
Add router role for prodnxsr0020
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
4a7d509943
Author
Member
  • hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:20 — ssh::server::options ListenAddress is 0.0.0.0/:: but the PR body says ssh is pinned to dum0, and this exposes sshd on the WAN uplink (103.216.190.0/23) → set ListenAddress to 127.0.0.1 + networking_loopback0_ip (as k8s.yaml does), or fix the body if all-address listening is intended.
  • nit: hieradata/roles/infra/network/router.yaml:2 — hiera_include lacks profiles::selinux::frr, which incus/node.yaml includes alongside frrouting → add it if the host runs SELinux enforcing.
- hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:20 — ssh::server::options ListenAddress is 0.0.0.0/:: but the PR body says ssh is pinned to dum0, and this exposes sshd on the WAN uplink (103.216.190.0/23) → set ListenAddress to 127.0.0.1 + networking_loopback0_ip (as k8s.yaml does), or fix the body if all-address listening is intended. - nit: hieradata/roles/infra/network/router.yaml:2 — hiera_include lacks profiles::selinux::frr, which incus/node.yaml includes alongside frrouting → add it if the host runs SELinux enforcing.
unkin-agent added 1 commit 2026-10-03 20:44:58 +10:00
pin prodnxsr0020 sshd to localhost and dum0
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was canceled
ci/woodpecker/pr/puppet-validate Pipeline was canceled
f4f4a12b52
Author
Member
  • hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:28 — sshd now listens only on 127.0.0.1/dum0 but profiles::ssh::sign::principals is not set, so the host cert principals are hostname/fqdn/WAN IP and omit 198.18.2.160 → add profiles::ssh::sign::principals: ["%{hiera('networking_loopback0_ip')}"] as k8s.yaml:203 and k8s/node.yaml:160 do
  • hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:12 — deny_ranges replaces the default list (no merge), so the four defaults are copied by hand and will drift → nit: acceptable, but note it in a comment or accept the drift
- hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:28 — sshd now listens only on 127.0.0.1/dum0 but `profiles::ssh::sign::principals` is not set, so the host cert principals are hostname/fqdn/WAN IP and omit 198.18.2.160 → add `profiles::ssh::sign::principals: ["%{hiera('networking_loopback0_ip')}"]` as k8s.yaml:203 and k8s/node.yaml:160 do - hieradata/nodes/prodnxsr0020.main.unkin.net.yaml:12 — `deny_ranges` replaces the default list (no merge), so the four defaults are copied by hand and will drift → nit: acceptable, but note it in a comment or accept the drift
unkin-agent added 1 commit 2026-10-03 20:46:46 +10:00
add dum0 ip to prodnxsr0020 ssh host cert principals
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
5e745e4507
Author
Member
  • hieradata/roles/infra/network/router.yaml:1 — frr-extras and frr-stable default to ensure: absent (os/AlmaLinux/all_releases.yaml:108-123) and the role does not enable them, so puppet removes the FRR repos and frrouting/frr_exporter packages cannot install or update → add profiles::yum::global::repos: {frr-extras: {ensure: present}, frr-stable: {ensure: present}} as dhcp/server.yaml, dns/resolver.yaml and k8s.yaml do.
- hieradata/roles/infra/network/router.yaml:1 — frr-extras and frr-stable default to `ensure: absent` (os/AlmaLinux/all_releases.yaml:108-123) and the role does not enable them, so puppet removes the FRR repos and `frrouting`/`frr_exporter` packages cannot install or update → add `profiles::yum::global::repos: {frr-extras: {ensure: present}, frr-stable: {ensure: present}}` as dhcp/server.yaml, dns/resolver.yaml and k8s.yaml do.
benvin merged commit 47e3bdc8f5 into develop 2026-10-03 22:40:02 +10:00
benvin deleted branch benvin/router-role 2026-10-03 22:40:02 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/puppet-prod#536