Phase A of the reachableceo drop merge. Working-tree diff (excluding
.git/.ansible/.crush/.fact_cache) showed zero content differences vs
this clone; drop HEAD matched df22156. Preserved the two loose analysis
notes from the drop root under docs/. Session state (.ansible,
.fact_cache) archived outside git per procedure.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
2.4 KiB
2.4 KiB
KNELIAC Basis — Executive Summary
Question: How does legacy KNELServerBuild (bash) become KNELIAC (Ansible), and how does the PFVCluster netinfra dns/dhcp/ntp code (Redmine #472) move into KNELIAC?
Headline: KNELIAC is not greenfield — the fleet-build port from KNELServerBuild is already ~complete (9 roles, AWX-driven, inventory already lists pfv-netinfra-01/02 in ntp_servers/dhcp_servers/dns_servers groups). The real work is #472: porting PFVCluster's netinfra/ into four new roles.
Key findings
- KNELServerBuild: architecturally sound bash (phases, modules, preflight, tests) but end-of-life — vendored-framework runtime dependency, deprecated CDN var, documented code-review debt, and a drifted
dns-cluster-setupcopy at repo root. Treat as specification only; ~90% already ported. Nothing else needs porting except tests and a few docs. - KNELIAC conventions to follow:
<area>_<thing>role names,preflightfacts (is_dhcp_server...) from inventory groups,run_*toggles, strict no-secrets AGENTS.md,setup_<purpose>.ymlplaybooks. - #472 mapping (PFVCluster
netinfra/→ new roles):dhcp/→roles/dhcp_server(dhcpd.conf.j2, failover vars, primary/secondary host_vars); Pi-hole + Technitium compose +technitium-zone-syncsystemd timer →roles/dns_pihole/roles/dns_technitium(rsync sync, not AXFR — Pi-hole owns :53); host ntpsec →roles/ntp_server; netinfra snmpd (scoped ACL + lease extends) → variant insystem_config. All driven by oneplaybooks/setup_netinfra.yml. - Gaps: ntpsec config exists only on hosts (capture before repave); Webmin hand-edits will fight templates; Technitium
auth.configcontains creds and must never enter git; zone data must survive re-runs (idempotency); SNMP community currently plaintext in group_vars → move to Vault; port from the PFVCluster copies of duplicated scripts (they carry the fixes). - Sequencing: (0) capture ntpsec + zone/gravity snapshots → (1) group/host_vars → (2) ntp_server role → (3) dhcp_server role → (4) DNS containers + zone-sync → (5) snmp + AWX job templates → (6) replace PFVCluster
netinfra/subdirs with pointer stubs (Discourse 306 pattern), keepswitches/and audit artifacts → (7) stub the KNELServerBuild duplicate. Old scripts stay until each role runs green on both nodes; nothing else in PFVCluster referencesnetinfra/, so blast radius is minimal.
Full detail: kneliac-basis-analysis.md