Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 5 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -325,21 +325,18 @@ Open work is tracked in
[`docs/roadmap.md`](docs/roadmap.md) is the narrative β€” what is outstanding and
why it is in that order.

The current top items: rack the shelf switch, rehearse the firewall restore on
the ProDesk bought on 2026-09-08, and then build the sensitive tier on that same
box ([#404](https://github.com/Gerrrt/HomeLab/issues/404), [ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)). **Every purchase still outstanding, in one place:** a
The current top items: rehearse the firewall restore on the ProDesk bought on
2026-09-08, and then build the sensitive tier on that same box ([#404](https://github.com/Gerrrt/HomeLab/issues/404), [ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)). **Every purchase still outstanding, in one place:** a
second drive for that box sized to the photo library, and the NAS
([#95](https://github.com/Gerrrt/HomeLab/issues/95)). A dedicated firewall
spare is deferred, not on the list. This sentence used to name three purchases
coupled to the UPS work and omit the tier's host entirely, which is how one
ProDesk came to be bought for two jobs.
The UPS is finished β€” a pack went into `mjolnir` on 2026-08-28, passed its
self-test, and the card is set to test itself every fortnight
([#93](https://github.com/Gerrrt/HomeLab/issues/93)) β€” but the switch between
the monitoring host and the network still has no battery at all, so both laptops
stay running and go deaf on a mains cut
([#110](https://github.com/Gerrrt/HomeLab/issues/110), reopened on 2026-09-08
after a commit message had closed it by accident); and the config export
([#93](https://github.com/Gerrrt/HomeLab/issues/93)) β€” and since 2026-09-08 the
switch between the monitoring host and the network draws from it too, racked in
U4 ([#110](https://github.com/Gerrrt/HomeLab/issues/110)); and the config export
itself now leaves the monitoring host nightly, so the rehearsal is what is left
([#92](https://github.com/Gerrrt/HomeLab/issues/92)).

Expand Down
14 changes: 7 additions & 7 deletions docs/hardware.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,15 +10,15 @@ landfill.
| --- | --- | --- |
| U1–U2 | APC Smart-UPS[^UPS] | Power |
| U3 | HPE ProLiant DL360 Gen9[^Shiva] | Proxmox hypervisor (`Saruman`, BMC `shiva`) |
| U4 | 1U vented shelf, carrying the 8-port unmanaged TP-Link switch[^tp-linkswitch] | Feeds `prometheus` and `oracle`; on UPS power since 2026-09-08 |
| U5 | HP ProDesk 600 G4 Mini[^ProDesk] | pfSense firewall (`morpheus`) |
| U6 | MT-VIKI 8-port KVM[^KVM] | Console access |
| U7 | 10-outlet PDU[^PDU] | Power distribution |
| U8 | Jadol 24-port patch panel[^Panel] | Cabling |
| U9 | MokerLink 26-port managed switch[^MokerLink] | Core switching (`neo`) |

Off-rack: two Ubuntu Server laptops on a shelf (`prometheus`, `oracle`), an
8-port unmanaged TP-Link switch feeding them, and eero Pro 6E units distributed
through the house.
Off-rack: two Ubuntu Server laptops on a shelf (`prometheus`, `oracle`), fed
by the TP-Link in U4, and eero Pro 6E units distributed through the house.

The patch panel and the PDU were listed the other way round here until
2026-08-29. U8 is the panel and U7 is the PDU, confirmed against the rack.
Expand Down Expand Up @@ -76,10 +76,9 @@ revisions of this repository treated `shiva` as the hypervisor itself.
the card ([#93](https://github.com/Gerrrt/HomeLab/issues/93)). The card's
`upsBasicBatteryLastReplaceDate` still reads `08/15/2026` and wants resetting
to the fit date β€” it is the only record of the pack's age
- 1U vented rack shelf, 4-post with square-hole mounting β€” on hand, for U4 and
the unmanaged switch that feeds `prometheus` and `oracle`. It is not in the
rack table above because it is not yet in the rack
([#110](https://github.com/Gerrrt/HomeLab/issues/110))
- 1U vented rack shelf, 4-post with square-hole mounting β€” in U4 since
2026-09-08, carrying the unmanaged switch that feeds `prometheus` and
`oracle` ([#110](https://github.com/Gerrrt/HomeLab/issues/110))
- HP ProDesk 600 G4 Micro β€” i5-8500T, 32 GB, 512 GB SSD, the same model as
`morpheus` β€” ordered 2026-09-08, in transit. The sensitive tier's host and
the firewall's spare hardware in a disaster
Expand Down Expand Up @@ -107,6 +106,7 @@ revisions of this repository treated `shiva` as the hypervisor itself.
[^KVM]: [MT-VIKI 8-port rackmount KVM](https://a.co/d/2yQl4KH)
[^Panel]: [Jadol 24-port patch panel](https://a.co/d/izggRoK)
[^PDU]: [10-outlet 1U PDU](https://a.co/d/ibEygxZ)
[^tp-linkswitch]: [TP-Link 8-port gigabit switch](https://www.tp-link.com/us/business-networking/unmanaged-switch/)
[^MokerLink]: [MokerLink 26-port managed switch](https://a.co/d/gaJvCKV)
[^ProDeskRackmount]: [1U rackmount for ProDesk Mini](https://a.co/d/4d7klOL)
[^Sliderail]: [Sliding rails for ProLiant](https://a.co/d/5d4A4FO)
Expand Down
5 changes: 4 additions & 1 deletion docs/network.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,7 +145,10 @@ listed under [Hicks](#hicks--vlan-50--trusted), and nothing else.
Ubuntu Server on it, which is exactly the sort of hardware a homelab should be
built from.
- Port 3 of the main switch feeds an 8-port unmanaged switch[^tp-linkswitch]
that `prometheus` and `oracle` hang off.
that `prometheus` and `oracle` hang off. Since 2026-09-08 it sits on the U4
shelf and draws from a UPS-fed outlet, so on a mains cut the two laptops keep
their network as well as their batteries
([#110](https://github.com/Gerrrt/HomeLab/issues/110)).
- pfSense's admin UI is reachable on this interface from Hicks only, by a
named pass to `10.0.99.1:443`. Winterfell itself is blocked from it: the 99
interface drops HTTP and HTTPS to `10.0.99.1` above its egress rule.
Expand Down
31 changes: 12 additions & 19 deletions docs/roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -338,25 +338,6 @@ what left this one unfireable for months.
[ADR-0015](adr/0015-give-oracle-the-off-host-jobs.md) sends them to `oracle`
alongside the firewall exports, which fits β€” a set is 867 MB of `age`
ciphertext against 67 GB free β€” and leaves only the copying to build.
- **[#110](https://github.com/Gerrrt/HomeLab/issues/110) Rack the shelf switch.**
A 1U vented shelf in **U4**, carrying the unmanaged switch `prometheus` and
`oracle` hang off. Both shelf machines are laptops, so on a mains cut they stay
running and go deaf while the switch between them and the network has no
battery at all β€” the pack in #93 protects the rack, not the monitoring path.
**The shelf is on hand; what is left is the rack visit**, to the spec measured
at the rack on 2026-08-21: 4-post, square holes, full 1U with rear support
rather than a cantilever. The shelf carries the switch and nothing else:
the ProDesk from [#92](https://github.com/Gerrrt/HomeLab/issues/92) is the
sensitive tier's host ([ADR-0034](adr/0034-run-the-sensitive-tier-on-the-prodesk-and-make-it-the-spare-hardware.md)), and [#404](https://github.com/Gerrrt/HomeLab/issues/404) decides where that lives.
**Reopened 2026-09-08.** GitHub had closed the issue on 2026-08-27, when the
commit that wrote the runbook said the switch's power move "is the one that
closes #110" and the phrase was read as a close keyword. Nothing was racked;
this entry and every document beside it said so the whole time, and only the
issue's state was wrong. The lesson is the one ADR-0026 already draws β€” a
state nothing checks against the thing it describes drifts β€” with a
sharper edge: a commit message can close an issue about work it explicitly
says it did not do.
β†’ [runbook](runbooks/fit-the-ups-battery.md)
- **[#251](https://github.com/Gerrrt/HomeLab/issues/251) Put the wiki on
`oracle` into the repository, and back up its database.** ADR-0015 ratified a
host whose main service is not described anywhere here: `wiki` and its
Expand Down Expand Up @@ -700,6 +681,18 @@ them name the condition that would change the answer.

## Done

- [x] **[#110](https://github.com/Gerrrt/HomeLab/issues/110) Racked the shelf
switch in U4, on UPS power.** 2026-09-08. The 1U vented shelf, the
TP-Link that `prometheus` and `oracle` hang off moved onto it with its
uplink back on port 3 of `neo`, and its power onto a UPS-fed outlet β€”
the step that actually closes the gap, since a relocated switch on a
wall socket is tidier and no better protected. The two laptops now keep
their network on a mains cut as well as their batteries, which is what
#93's pack was always half of. Bought with that pack on 2026-08-27 and
closed the same day by a commit message that quoted "closes #110" β€”
twice, the second time by the commit documenting the first β€” while every
document said the shelf was on hand and not racked; reopened 2026-09-08
and done the same afternoon.
- [x] **[#234](https://github.com/Gerrrt/HomeLab/issues/234) Armed the lab
tripwire on ImaginationLAN.** 2026-09-08. The firewall rule arrived on
2026-09-06 with the untagged-LAN blocks, pointed at `Internal_Segments` β€”
Expand Down
8 changes: 5 additions & 3 deletions docs/runbooks/fit-the-ups-battery.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,9 +43,11 @@ un-silenced by hand at the right moment.**
> something that did not happen. Harmless today; wrong in four years, when it is
> the only record of how old the pack is.
>
> The shelf and the switch move (step 2, items 1–4) were not done, so
> [#110](https://github.com/Gerrrt/HomeLab/issues/110) is untouched and
> `prometheus` and `oracle` still go deaf on a mains cut.
> The shelf and the switch move (step 2, items 1–3) were not done that day;
> they were done on 2026-09-08, which closed
> [#110](https://github.com/Gerrrt/HomeLab/issues/110): the TP-Link is in U4
> on a UPS-fed outlet, and `prometheus` and `oracle` keep their network on a
> mains cut.
>
> **One thing to do differently next time.** The silence was deleted at 23:14
> UTC β€” *after* the 22:45 self-test, not before it. It cost nothing here because
Expand Down