feat(network): use pfv-netinfra-01/02 as redundant DNS and NTP

Route every host built by this project through the new
pfv-netinfra-01 (192.168.3.252) / pfv-netinfra-02 (192.168.3.253)
pair for both name resolution and time, with automatic failover.

- NTP: replace the single pfv-netboot.knel.net upstream with both
  netinfra servers (iburst) so time sync survives either one failing.
- DNS: add a managed static /etc/resolv.conf (new ConfigFiles/Resolv/).
  The repo previously had no resolver configuration at all. Both servers
  are listed so glibc falls through to the secondary on failure.
- DHCP: request domain-name-servers/domain-search/ntp-servers and
  supersede them to the netinfra pair, so a DHCP renew can't silently
  revert to whatever the DHCP server advertises.
- SetupNewSystem.sh: deploy resolv.conf (robustly replacing any
  systemd-resolved/NetworkManager symlink) and add pfv-netinfra to the
  NTP-server self-exclusion guard so those boxes don't client off
  themselves.

LAN IPs are used throughout (not the knel.net hostnames) because those
hostnames resolve to Tailscale CGNAT addresses, not the LAN addresses,
and NTP must come up before DNS. Add a validation test asserting the
config is present and both servers actually answer DNS and NTP queries.

🤖 Generated with [Crush](https://github.com/charmassociates/crush)

Assisted-by: GLM-5 via Crush <crush@charm.land>
This commit is contained in:
2026-07-28 05:23:13 -05:00
parent 4201f3e669
commit f010fa9609
5 changed files with 238 additions and 2 deletions
+9 -1
View File
@@ -267,6 +267,14 @@ function global-postPackageConfiguration() {
cat "$CONFIGFILES_PATH/DHCP/dhclient.conf" >/etc/dhcp/dhclient.conf
# Authoritative recursive DNS via the redundant pfv-netinfra-01/02 pair.
# Replace whatever is at /etc/resolv.conf (including a systemd-resolved or
# NetworkManager symlink) with the managed static file so every lookup goes
# to our servers and nothing else rewrites it behind our backs.
rm -f /etc/resolv.conf
cat "$CONFIGFILES_PATH/Resolv/resolv.conf" >/etc/resolv.conf
chmod 644 /etc/resolv.conf
systemctl stop snmpd && /etc/init.d/snmpd stop
cat "$CONFIGFILES_PATH/SNMP/snmp-sudo.conf" >/etc/sudoers.d/Debian-snmp
@@ -304,7 +312,7 @@ function global-postPackageConfiguration() {
fi
export NTP_SERVER_CHECK
NTP_SERVER_CHECK="$(hostname | egrep -c 'pfv-netboot|pfvsvrpi' || true)"
NTP_SERVER_CHECK="$(hostname | egrep -c 'pfv-netboot|pfvsvrpi|pfv-netinfra' || true)"
if [ "$NTP_SERVER_CHECK" -eq 0 ]; then