Route every host built by this project through the new pfv-netinfra-01 (192.168.3.252) / pfv-netinfra-02 (192.168.3.253) pair for both name resolution and time, with automatic failover. - NTP: replace the single pfv-netboot.knel.net upstream with both netinfra servers (iburst) so time sync survives either one failing. - DNS: add a managed static /etc/resolv.conf (new ConfigFiles/Resolv/). The repo previously had no resolver configuration at all. Both servers are listed so glibc falls through to the secondary on failure. - DHCP: request domain-name-servers/domain-search/ntp-servers and supersede them to the netinfra pair, so a DHCP renew can't silently revert to whatever the DHCP server advertises. - SetupNewSystem.sh: deploy resolv.conf (robustly replacing any systemd-resolved/NetworkManager symlink) and add pfv-netinfra to the NTP-server self-exclusion guard so those boxes don't client off themselves. LAN IPs are used throughout (not the knel.net hostnames) because those hostnames resolve to Tailscale CGNAT addresses, not the LAN addresses, and NTP must come up before DNS. Add a validation test asserting the config is present and both servers actually answer DNS and NTP queries. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
15 lines
541 B
Plaintext
15 lines
541 B
Plaintext
driftfile /var/lib/ntp/ntp.drift
|
|
leapfile /usr/share/zoneinfo/leap-seconds.list
|
|
|
|
# Redundant upstream time sources: pfv-netinfra-01/02 (Technitium/Pi-hole hosts
|
|
# also serving NTP). IPs are used (not hostnames) because the knel.net name for
|
|
# these hosts resolves to a Tailscale CGNAT address, not the LAN address, and
|
|
# because NTP must come up before DNS is available. iburst speeds initial sync.
|
|
server 192.168.3.252 iburst
|
|
server 192.168.3.253 iburst
|
|
|
|
restrict 127.0.0.1
|
|
restrict ::1
|
|
interface ignore wildcard
|
|
interface listen 127.0.0.1
|