diff --git a/README.md b/README.md index 686c419..bc9be29 100644 --- a/README.md +++ b/README.md @@ -325,9 +325,8 @@ Open work is tracked in [`docs/roadmap.md`](docs/roadmap.md) is the narrative — what is outstanding and why it is in that order. -The current top items: rack the shelf switch, rehearse the firewall restore on -the ProDesk bought on 2026-09-08, and then build the sensitive tier on that same -box ([#404](https://github.com/Gerrrt/HomeLab/issues/404), [ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)). **Every purchase still outstanding, in one place:** a +The current top items: rehearse the firewall restore on the ProDesk bought on +2026-09-08, and then build the sensitive tier on that same box ([#404](https://github.com/Gerrrt/HomeLab/issues/404), [ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)). **Every purchase still outstanding, in one place:** a second drive for that box sized to the photo library, and the NAS ([#95](https://github.com/Gerrrt/HomeLab/issues/95)). A dedicated firewall spare is deferred, not on the list. This sentence used to name three purchases @@ -335,11 +334,9 @@ coupled to the UPS work and omit the tier's host entirely, which is how one ProDesk came to be bought for two jobs. The UPS is finished — a pack went into `mjolnir` on 2026-08-28, passed its self-test, and the card is set to test itself every fortnight -([#93](https://github.com/Gerrrt/HomeLab/issues/93)) — but the switch between -the monitoring host and the network still has no battery at all, so both laptops -stay running and go deaf on a mains cut -([#110](https://github.com/Gerrrt/HomeLab/issues/110), reopened on 2026-09-08 -after a commit message had closed it by accident); and the config export +([#93](https://github.com/Gerrrt/HomeLab/issues/93)) — and since 2026-09-08 the +switch between the monitoring host and the network draws from it too, racked in +U4 ([#110](https://github.com/Gerrrt/HomeLab/issues/110)); and the config export itself now leaves the monitoring host nightly, so the rehearsal is what is left ([#92](https://github.com/Gerrrt/HomeLab/issues/92)). diff --git a/docs/hardware.md b/docs/hardware.md index d515c3c..10986f4 100644 --- a/docs/hardware.md +++ b/docs/hardware.md @@ -10,15 +10,15 @@ landfill. | --- | --- | --- | | U1–U2 | APC Smart-UPS[^UPS] | Power | | U3 | HPE ProLiant DL360 Gen9[^Shiva] | Proxmox hypervisor (`Saruman`, BMC `shiva`) | +| U4 | 1U vented shelf, carrying the 8-port unmanaged TP-Link switch[^tp-linkswitch] | Feeds `prometheus` and `oracle`; on UPS power since 2026-09-08 | | U5 | HP ProDesk 600 G4 Mini[^ProDesk] | pfSense firewall (`morpheus`) | | U6 | MT-VIKI 8-port KVM[^KVM] | Console access | | U7 | 10-outlet PDU[^PDU] | Power distribution | | U8 | Jadol 24-port patch panel[^Panel] | Cabling | | U9 | MokerLink 26-port managed switch[^MokerLink] | Core switching (`neo`) | -Off-rack: two Ubuntu Server laptops on a shelf (`prometheus`, `oracle`), an -8-port unmanaged TP-Link switch feeding them, and eero Pro 6E units distributed -through the house. +Off-rack: two Ubuntu Server laptops on a shelf (`prometheus`, `oracle`), fed +by the TP-Link in U4, and eero Pro 6E units distributed through the house. The patch panel and the PDU were listed the other way round here until 2026-08-29. U8 is the panel and U7 is the PDU, confirmed against the rack. @@ -76,10 +76,9 @@ revisions of this repository treated `shiva` as the hypervisor itself. the card ([#93](https://github.com/Gerrrt/HomeLab/issues/93)). The card's `upsBasicBatteryLastReplaceDate` still reads `08/15/2026` and wants resetting to the fit date — it is the only record of the pack's age -- 1U vented rack shelf, 4-post with square-hole mounting — on hand, for U4 and - the unmanaged switch that feeds `prometheus` and `oracle`. It is not in the - rack table above because it is not yet in the rack - ([#110](https://github.com/Gerrrt/HomeLab/issues/110)) +- 1U vented rack shelf, 4-post with square-hole mounting — in U4 since + 2026-09-08, carrying the unmanaged switch that feeds `prometheus` and + `oracle` ([#110](https://github.com/Gerrrt/HomeLab/issues/110)) - HP ProDesk 600 G4 Micro — i5-8500T, 32 GB, 512 GB SSD, the same model as `morpheus` — ordered 2026-09-08, in transit. The sensitive tier's host and the firewall's spare hardware in a disaster @@ -107,6 +106,7 @@ revisions of this repository treated `shiva` as the hypervisor itself. [^KVM]: [MT-VIKI 8-port rackmount KVM](https://a.co/d/2yQl4KH) [^Panel]: [Jadol 24-port patch panel](https://a.co/d/izggRoK) [^PDU]: [10-outlet 1U PDU](https://a.co/d/ibEygxZ) +[^tp-linkswitch]: [TP-Link 8-port gigabit switch](https://www.tp-link.com/us/business-networking/unmanaged-switch/) [^MokerLink]: [MokerLink 26-port managed switch](https://a.co/d/gaJvCKV) [^ProDeskRackmount]: [1U rackmount for ProDesk Mini](https://a.co/d/4d7klOL) [^Sliderail]: [Sliding rails for ProLiant](https://a.co/d/5d4A4FO) diff --git a/docs/network.md b/docs/network.md index 11ef9eb..af5ea72 100644 --- a/docs/network.md +++ b/docs/network.md @@ -145,7 +145,10 @@ listed under [Hicks](#hicks--vlan-50--trusted), and nothing else. Ubuntu Server on it, which is exactly the sort of hardware a homelab should be built from. - Port 3 of the main switch feeds an 8-port unmanaged switch[^tp-linkswitch] - that `prometheus` and `oracle` hang off. + that `prometheus` and `oracle` hang off. Since 2026-09-08 it sits on the U4 + shelf and draws from a UPS-fed outlet, so on a mains cut the two laptops keep + their network as well as their batteries + ([#110](https://github.com/Gerrrt/HomeLab/issues/110)). - pfSense's admin UI is reachable on this interface from Hicks only, by a named pass to `10.0.99.1:443`. Winterfell itself is blocked from it: the 99 interface drops HTTP and HTTPS to `10.0.99.1` above its egress rule. diff --git a/docs/roadmap.md b/docs/roadmap.md index 52dd624..b51702d 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -338,25 +338,6 @@ what left this one unfireable for months. [ADR-0015](adr/0015-give-oracle-the-off-host-jobs.md) sends them to `oracle` alongside the firewall exports, which fits — a set is 867 MB of `age` ciphertext against 67 GB free — and leaves only the copying to build. -- **[#110](https://github.com/Gerrrt/HomeLab/issues/110) Rack the shelf switch.** - A 1U vented shelf in **U4**, carrying the unmanaged switch `prometheus` and - `oracle` hang off. Both shelf machines are laptops, so on a mains cut they stay - running and go deaf while the switch between them and the network has no - battery at all — the pack in #93 protects the rack, not the monitoring path. - **The shelf is on hand; what is left is the rack visit**, to the spec measured - at the rack on 2026-08-21: 4-post, square holes, full 1U with rear support - rather than a cantilever. The shelf carries the switch and nothing else: - the ProDesk from [#92](https://github.com/Gerrrt/HomeLab/issues/92) is the - sensitive tier's host ([ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)), and [#404](https://github.com/Gerrrt/HomeLab/issues/404) decides where that lives. - **Reopened 2026-09-08.** GitHub had closed the issue on 2026-08-27, when the - commit that wrote the runbook said the switch's power move "is the one that - closes #110" and the phrase was read as a close keyword. Nothing was racked; - this entry and every document beside it said so the whole time, and only the - issue's state was wrong. The lesson is the one ADR-0026 already draws — a - state nothing checks against the thing it describes drifts — with a - sharper edge: a commit message can close an issue about work it explicitly - says it did not do. - → [runbook](runbooks/fit-the-ups-battery.md) - **[#251](https://github.com/Gerrrt/HomeLab/issues/251) Put the wiki on `oracle` into the repository, and back up its database.** ADR-0015 ratified a host whose main service is not described anywhere here: `wiki` and its @@ -700,6 +681,18 @@ them name the condition that would change the answer. ## Done +- [x] **[#110](https://github.com/Gerrrt/HomeLab/issues/110) Racked the shelf + switch in U4, on UPS power.** 2026-09-08. The 1U vented shelf, the + TP-Link that `prometheus` and `oracle` hang off moved onto it with its + uplink back on port 3 of `neo`, and its power onto a UPS-fed outlet — + the step that actually closes the gap, since a relocated switch on a + wall socket is tidier and no better protected. The two laptops now keep + their network on a mains cut as well as their batteries, which is what + #93's pack was always half of. Bought with that pack on 2026-08-27 and + closed the same day by a commit message that quoted "closes #110" — + twice, the second time by the commit documenting the first — while every + document said the shelf was on hand and not racked; reopened 2026-09-08 + and done the same afternoon. - [x] **[#234](https://github.com/Gerrrt/HomeLab/issues/234) Armed the lab tripwire on ImaginationLAN.** 2026-09-08. The firewall rule arrived on 2026-09-06 with the untagged-LAN blocks, pointed at `Internal_Segments` — diff --git a/docs/runbooks/fit-the-ups-battery.md b/docs/runbooks/fit-the-ups-battery.md index bf5eb8d..cf379a6 100644 --- a/docs/runbooks/fit-the-ups-battery.md +++ b/docs/runbooks/fit-the-ups-battery.md @@ -43,9 +43,11 @@ un-silenced by hand at the right moment.** > something that did not happen. Harmless today; wrong in four years, when it is > the only record of how old the pack is. > -> The shelf and the switch move (step 2, items 1–4) were not done, so -> [#110](https://github.com/Gerrrt/HomeLab/issues/110) is untouched and -> `prometheus` and `oracle` still go deaf on a mains cut. +> The shelf and the switch move (step 2, items 1–3) were not done that day; +> they were done on 2026-09-08, which closed +> [#110](https://github.com/Gerrrt/HomeLab/issues/110): the TP-Link is in U4 +> on a UPS-fed outlet, and `prometheus` and `oracle` keep their network on a +> mains cut. > > **One thing to do differently next time.** The silence was deleted at 23:14 > UTC — *after* the 22:45 self-test, not before it. It cost nothing here because