unkin-agent 47e3bdc8f5 Add router role for prodnxsr0020 (#536)
prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq.

- add roles::infra::network::router (base + frrouting + frr_exporter)
- enable ip_forward and disable rp_filter via sysctl::base
- add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160)
- pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP
- listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP
- keep resolv.conf on the local dnsmasq (127.0.0.1)

Reviewed-on: #536
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 22:40:01 +10:00
2026-03-17 17:38:22 +11:00
2026-02-03 19:56:14 +11:00
2023-07-02 14:21:09 +10:00
2023-06-21 22:03:43 +10:00
2025-07-08 20:19:36 +10:00
2024-02-17 22:57:36 +11:00
S
Description
production puppet-control repository
3.8 MiB
Languages
Puppet 66.5%
HTML 27.6%
Ruby 5.9%