feat(netinfra): DHCP hot-standby + dual-stack NTP/SNMP on netinfra pair [#420]

DNS/DHCP/NTP redundancy per founder ruling 2026-08-27:
- DHCP failover converted load-balance -> hot standby (split 255 on
  primary; secondary answers only if primary unreachable >3s). DHCP
  options now hand out BOTH nodes for DNS and NTP (active/active) —
  Tailscale hosts stay on MagicDNS 100.100.100.100.
- netinfra-02 ntpsec deployed (pool.ntp.org, all interfaces); 01
  repointed from debian pool zones to pool.ntp.org. NTP now redundant;
  GPS stratum-1 on pfvsvrpi tracked as follow-up ticket.
- snmpd on both nodes with scoped ACLs (LibreNMS LAN+TS sources only)
  and ntpq/dhcpd-lease extends — prep for DNS/DHCP/NTP graphing.
- Deployed sync-zones.sh (git version, DNS name instead of IP literal)
  to netinfra-02; zone sync verified 171/171 zones both nodes.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
This commit is contained in:
2026-08-27 13:02:26 -05:00
parent ae8af3472b
commit f16397f95e
4 changed files with 47 additions and 4 deletions
+6 -1
View File
@@ -3,6 +3,11 @@
# Managed via Webmin DHCP module
#
# FAILOVER: this node is PRIMARY; peer is pfv-netinfra-02 (192.168.3.253)
# DESIGN [#420, founder ruling 2026-08-27]: DHCP failover = active/passive
# hot standby (split 255: primary serves all hashes; secondary answers only
# when primary unreachable for >3s via 'load balance max seconds').
# DNS + NTP options hand out BOTH servers (active/active). Tailscale hosts
# use 100.100.100.100 MagicDNS, redundant to both netinfra TS IPs.
# Global defaults
option domain-name "knel.net";
@@ -25,7 +30,7 @@ failover peer "pfv-dhcp" {
max-response-delay 30;
max-unacked-updates 10;
mclt 600;
split 128;
split 255;
load balance max seconds 3;
}
+9 -3
View File
@@ -1,8 +1,14 @@
# dhcpd.conf — pfv-netinfra-01 (PRIMARY)
# dhcpd.conf — pfv-netinfra-02 (SECONDARY)
# Migrated from pfv-netboot 2026-07-29
# Managed via Webmin DHCP module
#
# FAILOVER: this node is PRIMARY; peer is pfv-netinfra-02 (192.168.3.253)
# FAILOVER: this node is SECONDARY; peer is pfv-netinfra-01 (192.168.3.252)
# DESIGN [#420, founder ruling 2026-08-27]: DHCP failover = active/passive
# hot standby (primary split 255 serves all clients while healthy; this
# node answers only when primary unreachable for >3s via
# 'load balance max seconds 3').
# DNS + NTP options hand out BOTH servers (active/active). Tailscale hosts
# use 100.100.100.100 MagicDNS, redundant to both netinfra TS IPs.
# Global defaults
option domain-name "knel.net";
@@ -15,7 +21,7 @@ max-lease-time 7200;
ddns-update-style none;
authoritative;
# ----- failover peer (PRIMARY) -----
# ----- failover peer (SECONDARY) -----
failover peer "pfv-dhcp" {
secondary;
address 192.168.3.253;
+16
View File
@@ -0,0 +1,16 @@
# snmpd.conf — pfv-netinfra-01 [#420] scoped ACL for LibreNMS instrumentation
# Sources: tsys-librenms LAN (192.168.3.176) + Tailscale (100.86.204.77) only.
# No broad subnet grants (founder ruling 2026-08-27, matches dcinfra/sensors pattern).
sysLocation "Rack 3 netinfra (DNS/DHCP/NTP primary)"
sysContact ops@turnsys.com
agentaddress 127.0.0.1:161,192.168.3.252:161,100.70.181.72:161
rocommunity kn3lmgmt 127.0.0.1
rocommunity kn3lmgmt 192.168.3.176
rocommunity kn3lmgmt 100.86.204.77
# Instrumentation feeds for the monitoring session (DNS/DHCP/NTP graphing):
extend ntpq /usr/bin/ntpq -c rv
extend dhcpd-leases /bin/sh -c "grep -c '^lease' /var/lib/dhcp/dhcpd.leases"
extend dhcpd-active /bin/sh -c "grep -c 'binding state active' /var/lib/dhcp/dhcpd.leases"
+16
View File
@@ -0,0 +1,16 @@
# snmpd.conf — pfv-netinfra-02 [#420] scoped ACL for LibreNMS instrumentation
# Sources: tsys-librenms LAN (192.168.3.176) + Tailscale (100.86.204.77) only.
# No broad subnet grants (founder ruling 2026-08-27, matches dcinfra/sensors pattern).
sysLocation "Rack 3 netinfra (DNS/DHCP/NTP secondary)"
sysContact ops@turnsys.com
agentaddress 127.0.0.1:161,192.168.3.253:161,100.71.171.20:161
rocommunity kn3lmgmt 127.0.0.1
rocommunity kn3lmgmt 192.168.3.176
rocommunity kn3lmgmt 100.86.204.77
# Instrumentation feeds for the monitoring session (DNS/DHCP/NTP graphing):
extend ntpq /usr/bin/ntpq -c rv
extend dhcpd-leases /bin/sh -c "grep -c '^lease' /var/lib/dhcp/dhcpd.leases"
extend dhcpd-active /bin/sh -c "grep -c 'binding state active' /var/lib/dhcp/dhcpd.leases"