Commit Graph
100 Commits
Author SHA1 Message Date
mrcharles 994959d4ad docs(questions): C4-C8 agent-stack + credentials-policy rulings [#767]
Detail: https://projects.knownelement.com/issues/767
2026-09-03 17:13:29 -05:00
mrcharles a2a45ea9d8 feat(bench): harness v1.1 — PSI latency, load, device identity context [#709]
Replaces unavailable latencytop; sysstat/iotop deployed fleet-wide
separately. Redmine: https://projects.knownelement.com/issues/709
2026-09-03 16:55:28 -05:00
mrcharles abb725be85 feat(oam): nginx vhost SoR — OAM docker UIs behind fleet TLS [#697]
4 subdomain vhosts proxying to local docker ports; SAN cert from fleet
CA; workstation chain-verified (ssl_verify=0 all four).

Detail: https://projects.knownelement.com/issues/697
2026-09-03 14:42:33 -05:00
mrcharles 8a4ee6f64f dns: oam UI subdomains — smokeping/netdisco/oxidized/unpoller → tsys-librenms [#697]
A + auto-PTR via dns-cli on primary; zone-snapshot + drift-check ALL
IN SYNC same session. Serves the fleet-TLS pass for the tsys-librenms
docker UIs.

Detail: https://projects.knownelement.com/issues/697
2026-09-03 14:39:24 -05:00
mrcharles ba4463c4d0 fix(oam): kuma inventory target-field bug + add-ping tooling [#343][#435]
kuma-inventory.py printed the junk url field (https://) instead of the
hostname for ping monitors — hid ~100 monitors from FQDN matching.
kuma-add-ping.py: idempotent ping-monitor adds (exists-check by name and
target). Matrix published to Discourse t/309 (canonical, #343).

Detail: https://projects.knownelement.com/issues/343
2026-09-03 14:34:44 -05:00
mrcharles a07d866116 fix(cmdb): canonical CI names — s7 rename map in seed generator [#705]
from-inventory.sh now applies the #307 s7 VM-name -> Tailscale-name
mapping (two-pass awk), so rr-middleware-01/preprod-proxmoxmailgw rows
emit canonical names. Seed regenerated; GLPI renames + dup purges done
in same session (78 CIs at parity).

Detail: https://projects.knownelement.com/issues/705
2026-09-03 14:22:05 -05:00
mrcharles 8666182d8b docs(cmdb): regenerate seed post-reconcile — 75 CIs, stale rows gone [#705]
Detail: https://projects.knownelement.com/issues/705
2026-09-03 14:05:04 -05:00
mrcharles 056412a311 feat(cmdb): inventory reconcile + GLPI software catalog seeder [#705]
#307 s6 rewritten post-verification: zone was ALREADY clean (zero DNS
deletes); 12 stale CIs purged from GLPI, 3 alive off-cluster systems
given proper CIs (tsys-cloudron, ultix-field/highside), 75-row seed
regenerated. software-catalog.sh: 21 products + 59 installs (wazuh
agents linked from live manager); version lookup fixed to client-side
parent filter (GLPI ignores softwares_id search param).

Detail: https://projects.knownelement.com/issues/705
2026-09-03 14:01:56 -05:00
mrcharles 4c461c14e1 refactor: move HA tooling + reference packs to KNEL/pfv-bms [#762]
HomeAssistant/ is now a redirect stub; AGENTS.md layout updated.
Zero HA impact — pfv-bms never loaded from PFVCluster.

Detail: https://projects.knownelement.com/issues/762
2026-09-03 13:34:55 -05:00
mrcharles 1620351028 feat(ca): artifact mirror live — pinned wazuh-agent debs on tsys-ca [#758]
dist/wazuh-agent/4.14.7-1/ (amd64+arm64+armhf) + SHA256SUMS, autoindex
enabled, workstation hash-verified against published manifest.
deploy-agent.sh now installs from the mirror (upstream fallback) and
auto-detects arch. #335: kali-tsys enrolled+active (30 total agents).

Detail: https://projects.knownelement.com/issues/758
2026-09-03 13:25:28 -05:00
mrcharles e27e3a06b8 feat(oam): codify garage-pdu-relay snmpd extend + timeout hardening [#733]
Deployed manually on tsys-librenms 2026-09-02 (founder relay ruling);
codified same-day rule. snmpget -t2 -r1 so a dark PDU answers in ~2s.
Deployed target: tsys-librenms:/usr/local/bin/garage-pdu-relay.

Detail: https://projects.knownelement.com/issues/733
2026-09-03 12:55:31 -05:00
mrcharles d3b9099d5f feat(mail): fleet mail-env audit + map; PMG VIP proposal [#696][#694]
Audit findings note (55/64 systems, read-only):
https://projects.knownelement.com/issues/696#note-4088

Map + deploy plan: https://community.turnsys.com/t/322
Key: relayhost empty fleet-wide (direct-to-MX today); prod PMG pair
already installed (VM 604/711, PMG 9.1, unclustered); VIP slot
proposed 192.168.3.249; open PQs in questions-v8.md.
2026-09-03 12:49:59 -05:00
mrcharles 7ca87c1200 docs(questions): C1-C3 CMDB change-control rulings needed [#705]
Detail: https://projects.knownelement.com/issues/705
2026-09-03 12:32:20 -05:00
mrcharles 412d706abd docs(questions): v7 — PMG design round PQ1-PQ7 [#696][#694]
Session-start note (ground truth + design questions):
https://projects.knownelement.com/issues/696#note-4086

No duplicate ticket: #696 (child of umbrella #694) already covers
PMG deploy + MX cut-over; session gated on #696.
2026-09-03 12:27:34 -05:00
mrcharles 07a0a3472b fix(cmdb): GLPI import fixes — input wrapper + Read-Only agent profile [#705]
Import executed live: 87 CIs seeded, scoped cmdb user (Read-Only)
verified read-ok / write-denied. Fixes: POST body needs {input:[...]}
(ERROR_BAD_ARRAY on bare array), profile swapped Technician ->
Read-Only per least-priv ruling, shape-tolerant user-exists check.

Detail: https://projects.knownelement.com/issues/705
2026-09-03 12:26:39 -05:00
mrcharles 379f7d376b docs(cmdb): regenerate seed — wnode-tsys5 ghost retired [#728]
#307 row annotated RETIRED (VM 500 gone from every node, not in the k8s
roster); seed regenerated via the converter. Also carries the ultix-offstage
retirement.
2026-09-03 11:46:36 -05:00
mrcharles b7eb9a5066 fix(bench): trixie libaio1 fallback in bench LXC installer [#709]
Redmine detail: https://projects.knownelement.com/issues/709
2026-09-03 11:43:48 -05:00
mrcharles d237e4a65d feat(monitoring): kuma notification tooling; app webhooks replace pushover [#435]
kuma-notifications.py (list/delete/usage). Deleted unused Pushover provider
'KNEL Alerts' per Charles — 211/211 monitors already on the ultix-sidecar +
Ultix-mini app webhooks. fleet-sync creation payload updated to the live
notification IDs.
2026-09-03 11:38:38 -05:00
mrcharles 4c2726b116 feat(cmdb): GLPI importer — agent user + seed import ready to fire [#705]
to-glpi.sh: initSession, creates scoped local 'cmdb' user (Technician @
root entity, random token -> ~/.creds/glpi-agent.env), then batch-imports
systems.csv as Computers (chunked, idempotent by name, --dry-run).
Fires the moment Charles drops the corrected GLPI_USER_TOKEN.
Pure bash/jq per house rules.
2026-09-03 09:59:32 -05:00
mrcharles b575a8e864 fix(perf): install libaio1t64 fallback for Debian 13 guests [#709] 2026-09-03 09:30:29 -05:00
mrcharles bf52f85ac5 docs(agents): field lessons from #684 PBS rollout + restore-drill incident
Meat: https://projects.knownelement.com/issues/684
2026-09-03 08:33:58 -05:00
mrcharles 7586605b70 fix(perf): bench jq direction bug + libaio + json note guard [#709]
- write tests read .write.* explicitly (jq // kept read=0 for writes)
- libaio1 installed everywhere (real aio engine, no sync cap)
- fio stdout notes stripped before jq parse

Ticket: https://projects.knownelement.com/issues/709
2026-09-03 07:53:37 -05:00
mrcharles 82fdb161cc feat(ca): fleet CA tooling — intermediate live on tsys-ca, first cert issued [#697]
ca-init/issue-cert/selftest (TDD loop, shellcheck clean); design doc on
Discourse t/320. Offline RSA-4096 root (Nitrokey ceremony later), 5y
intermediate, 825d SAN leaves. First cert: tsys-wazuh.knel.net (fingerprint
on the ticket note).
Meat: https://projects.knownelement.com/issues/697#note-4033
2026-09-03 07:52:07 -05:00
mrcharles 02bdeae9e7 feat(perf): standardized fleet benchmark artifact (fio/iperf3) [#709]
bench-run.sh: identical test shape everywhere (4k rand rw, 1M seq rw,
direct IO, grep-able BENCH| lines) - runs in guests, LXCs, containers.
install-bench.sh for Debian guests/LXCs; Dockerfile for registry image;
lxc-bench-setup.sh stands up the host-side bench LXC (proxmox = no docker).

Ticket: https://projects.knownelement.com/issues/709
2026-09-03 07:21:27 -05:00
mrcharles d75366edf5 feat(siem): agent fixes from fleet pass; IPv6 kill script [#335][#748]
deploy-agent.sh now self-heals the three postinst failure modes found on
PMG/PBS hosts (MANAGER_IP placeholder, missing wazuh user, root:root
ownership). scripts/disable-ipv6.sh: live sysctl + persisted conf, with
in-file rollback notes. Rollout state in #335/#748.
Meat: https://projects.knownelement.com/issues/335#note-4008
2026-09-03 07:13:28 -05:00
mrcharles 2485866ccd chore(dns): remove retired wnode-tsys5 ghost A record from knel.net [#737]
Node retired and replaced by ultix-streaming; tailnet-side entry still
requires admin-console removal (no TS API key in store). Zone snapshot
refreshed same-session per DNS sync rule.

Ticket: https://projects.knownelement.com/issues/737
2026-09-03 06:32:44 -05:00
mrcharles 06679d9a0c feat(siem): fleet rollout tooling — agents + PVE rsyslog forwarding [#335]
deploy-agent.sh (Ubuntu VMs) + deploy-rsyslog.sh (PVE hosts, TCP/514 via
Tailscale). Landed: agents on netinfra-01/02, librenms, awx (7 total
active on manager); rsyslog forwarding verified on all 7 PVE hosts
(persistent 514 sessions on the manager). Deferred: k8s nodes (k8s-chat
coordination), docker json-log caps (needs daemon restart window).
Meat + verification: https://projects.knownelement.com/issues/335#note-4006
2026-09-03 06:30:25 -05:00
mrcharles 5c5e173a1b feat(cmdb): seed tooling — inventory→CSV converter + 87-CI seed v0 [#705]
P0 of the CMDB/change-control plan (design: Discourse t/319). Regenerates
the GLPI seed dataset from the #307 inventory raw; re-runnable whenever
#307 changes. AGENTS.md: cmdb/ layout entry + Key Scripts row.

Meat + plan: https://projects.knownelement.com/issues/705#note-4004
2026-09-03 05:54:08 -05:00
mrcharles 6a38b4443c docs(agents): cross-linking house rule + mastodon post tool [#743][#441]
Clickable-refs mandate from Charles: ticket comments link commits,
commit bodies link the Redmine comment URL, Discourse links both —
one click between Redmine/Gitea/Discourse (GLPI/CMDB change control
will extend this). Mechanical body-URL check queued under #441.
scripts/mastodon/post.sh: zero-install curl poster; creds land in
~/.creds/mastodon.env (MASTODON_URL/MASTODON_TOKEN, write scope).
2026-09-03 05:28:57 -05:00
mrcharles 6c80b76b47 docs: questions v4 — pairing mechanism fork + gitea allowlist ask [#626][#734] 2026-09-02 23:10:07 -05:00
mrcharles 4a38e9bac8 docs(questions): v6 — Q5 resolved (separate roster repo, built); Q4 open (second human) [#345]
https://projects.knownelement.com/issues/345
2026-09-02 21:59:36 -05:00
mrcharles 7376763824 docs(questions): v5 — v4 answers recorded (relay hw, probe cleared, HA whitelist); PR approver questions [#345]
Founder answered Q1-Q3 2026-09-02; new Q4/Q5 ask for named PR
approvers and pfv-bms protection scope.

https://projects.knownelement.com/issues/345
2026-09-02 21:30:51 -05:00
mrcharles 04b85e9935 feat(perf): ZFS blacklist script, applied to all 7 tsys hosts [#737]
ZFS is unused on the fleet (zero pools). Blacklisted module + disabled
zfs service family + initramfs bake-in; ARC reclaimed live (tsys5 ~9G,
tsys6 ~13G, tsys7 ~16G, tsys1 ~3G). Guard aborts on zfs-rooted hosts.

Ticket: https://projects.knownelement.com/issues/737
2026-09-02 21:17:34 -05:00
mrcharles 6414fee6ec feat(sensors): labeled per-zone thermal layer in lmsensors-extend [#736]
Hosts opt in via /etc/snmp/lmsensors-zone-types (one zone type per
line, e.g. Jetson GPU-therm); each type renders its own zone-<type>
chip block so HA templates anchor on the chip name. Default behavior
unchanged; no snmpd restarts (extend re-execs per poll).
2026-09-02 21:16:34 -05:00
mrcharles c71d66e129 docs: remote-access decision question for founder [#626][#344] 2026-09-02 21:07:27 -05:00
mrcharles b958dd762f docs: ask 14 answered — dockerd bounce applied [#731]
Meat: https://projects.knownelement.com/issues/731#note-3929
2026-09-02 20:42:28 -05:00
mrcharles a4d4c1c91a feat(perf): reusable guest perf pack deploy script [#737]
Idempotent in-guest tuning: sysctl profile, fq/bbr, THP->madvise with
boot persistence (yields to tuned), fstrim.timer. First applied to
pfv-k8s-wnode-tsys3.

Ticket: https://projects.knownelement.com/issues/737
2026-09-02 20:37:03 -05:00
mrcharles 17c555adf5 docs(questions): v4 badge doorman modernization round [#345]
Opens the actuator/reader-format/whitelist questions for the badge
system modernization on #345/#355.

Findings note: https://projects.knownelement.com/issues/355#note-3955
2026-09-02 20:29:17 -05:00
mrcharles 4de1457eaa docs(agents): dhcpd AppArmor /etc/dhcp path constraint field lesson [#728] 2026-09-02 20:23:38 -05:00
mrcharles 1dbf16c9df feat(dns): zone-snapshot tooling + sync rule; refresh stale snapshots [#630][#728]
Founder rule: every Technitium/DNS/DHCP change ends with a same-session
SoR sync — zone-snapshot.sh then drift-check green, then commit. Added
the tool (tar-pulls the DZ store from the primary via the chokepoint),
wrote the rule into AGENTS.md (DNS change discipline + Key Scripts rows),
refreshed 4 stale snapshots (knel.net, 1/3.168.192 reverse, 119.70.100
— incl. the deleted ultix-offstage PTR). drift-check: ALL IN SYNC.
Also: last tsrouter mentions retired (AGENTS.md, setup.sh header).
2026-09-02 20:19:23 -05:00
mrcharles c2b7c91079 fix(dhcp): retire ultix-offstage reservation — VM 5112 deleted [#728][#420]
Founder ruling 2026-09-02: ultix-offstage is retired. Removed the host
block (bc:24:11:1f:9d:83 -> 192.168.3.79) from both SoR confs and deployed
to the live pair serially with health gates; failover reports both-normal.
A record + PTR deleted from Technitium both nodes; #307 inventory rows
annotated. Tailscale device removal is a founder console action.
2026-09-02 20:18:09 -05:00
mrcharles ffda5a68f0 feat(switches): add show-only audit cmds for 4 consoles [#732]
Fleet perf audit found only 2/6 consoles had repo cmds sets; these four
were improvised show-only and used for the 2026-09-02 conman pulls.

Report: https://community.turnsys.com/t/298/66
Ticket: https://projects.knownelement.com/issues/732
2026-09-02 20:14:14 -05:00
mrcharles d9aa989957 docs(agents): HA snmp two-layer + package dupe-key field lessons [#344] 2026-09-02 20:02:54 -05:00
mrcharles 76e50de25f fix(dns): retire tailscale-router references; netinfra pair is prod [#728]
Founder ruling 2026-09-02: tailscale-router retired, subnet routing now
pfv-netinfra-01/02 (both advertise 192.168.0.0/22 + exit routes, verified).
Drop dead tsrouter alias from the chokepoint script; setup/verify now use
the primary as production source; refresh verify record list (tsys-nsm is
also a dead name; add tsys-wazuh CNAME + tsys-siem).

archive/KNELServerBuild copies left as read-only history by design.
2026-09-02 19:42:15 -05:00
mrcharles e6f33ca32a docs: ask 13 answered — Cloudron API token received+verified [#727]
Stored 0600 in ~/.creds/cloudron.env; API verified (profile/apps 200).
Meat: https://projects.knownelement.com/issues/727#note-3928
2026-09-02 19:07:43 -05:00
mrcharles 13fcb13182 move cloudron kuma artifacts to KNEL/cloudron [#727]
cloudron-apps.txt + kuma-cloudron-sync.py now live at
KNEL/cloudron monitoring/ (path re-rooted there).
Meat: https://projects.knownelement.com/issues/727#note-3913
2026-09-02 18:51:20 -05:00
mrcharles e824a1fc72 docs: Cloudron asks 13/14 — API token + dockerd window [#727]
Bootstrap of KNEL/cloudron repo + script capture.
Meat: https://projects.knownelement.com/issues/727#note-3913
2026-09-02 18:44:50 -05:00
mrcharles 77811927e3 docs: finish questions consolidation — drop merged files [#344]
Leftover unstaged state from the parallel 09-02 sessions: delete
questions-v1/v2, HomeAssistant/needfromcharles.md, night-grind-plan.md
(content lives in questions-09022206.md / questions-v3.md / git history);
drop superseded UniFi API-key ask (#619 multicast fix made it moot).

Details: https://projects.knownelement.com/issues/344#note-3911
2026-09-02 18:26:14 -05:00
mrcharles 0c6aabbb4d fix(rules): accept any questions-v*.md version + restore questions file
The required-files check pinned questions-v1.md, which breaks every time
the Q&A file versions up (v2 was closed out by the parallel session,
leaving nothing matching). Now glob-accepts any version. questions-v3.md
restores the file; active question channel is ~/PTKR.md per founder.

Detail: https://projects.knownelement.com/issues/441 (latest notes)

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 18:12:52 -05:00
mrcharles e56442e694 docs(agents): HA todo HUD field lessons (get_items/rename pattern) [#441]
How to read and rename founder todo-list items via HA REST for the
Redmine [#NNN] sync-back workflow.

Detail: https://projects.knownelement.com/issues/441 (latest notes)

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 18:08:53 -05:00
mrcharles aa8239b74a docs: consolidate open asks into questions-09022206.md [#344]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 18:01:52 -05:00
mrcharles bacd7058a1 kuma: monitor the 7 booking instances + penpot [#685]
These 8 apps were the postgres connection hogs - invisible to monitoring
until now. Detail: https://projects.knownelement.com/issues/685
2026-09-02 17:57:56 -05:00
mrcharles dd74fccc08 feat(dhcp): reservations — DIRIGERA hub + 2 WiZ bulbs (forward/reverse DNS added) [#712][#344]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 17:57:16 -05:00
mrcharles 326860a80b docs: full-session close-out [#682] 2026-09-02 17:36:15 -05:00
mrcharles da3f365faa docs(agents): field lessons — 2026-09-02 HA deep session 2026-09-02 17:33:21 -05:00
mrcharles 4f9e7d521e feat(pdu): garage PDU SNMP relay on tsys-librenms (AP7830 v1-only) [#344]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 17:24:19 -05:00
mrcharles 069273531d docs(agents): no-wiki-in-Redmine ruling + fix tooling-cli paths [#441]
Discourse is the sole documentation space; Redmine wikis stay disabled
(verified 0/62 projects). Also repointed the stale redmine/discourse CLI
AGENTS.md references to ukrrs/connectors/KNEL-AIMiddleware.

Detail: https://projects.knownelement.com/issues/441 (latest note)

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 17:03:54 -05:00
mrcharles ebefbe47a7 feat(netinfra): NTP + Technitium zones into git SoR; drift-check full stack [#630]
ntp.conf captured (nodes byte-identical); 171 Technitium DZ zone files
captured from the primary; drift-check now covers dhcpd/pihole/ntp on
both nodes plus a zones md5-manifest check. Live run caught real drift:
node-02 dhcpd.conf was a stale primary copy missing the #614 minisplit
reservation — reconciled git->02 with dhcpd -t gate, serial restart,
failover "Both servers normal", all 7 checks in sync. Red-green unit
tests extended (gen_manifest, tracked-file invariants).

Results: https://projects.knownelement.com/issues/630#note-2
2026-09-02 16:33:33 -05:00
mrcharles bdf61ebe49 fix(kuma): Cloudron monitors under dedicated group; zero IP literals [#435]
New "Cloudron" group (id 277); all 55 app monitors moved there
(canary-verified). Deleted IP-literal monitor id=8 (dup of DNS-named
id=210) and repointed appletv monitor to new DNS name
stl-appletv-livingroom.knel.net. Fleet-wide IP literals in Kuma: 0.
Sync tool default group updated to 277.

Results: https://projects.knownelement.com/issues/435#note-5
2026-09-02 16:26:46 -05:00
mrcharles 14e7e4dabb docs: session close-out — HA software queue worked, masters #682/#683 cut [#344]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 15:21:33 -05:00
mrcharles f393a5ba5f feat(idrac): drac-extend — IPMI temps via snmpd extend (tsys6/7) [#625]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 14:56:21 -05:00
mrcharles 8bc1dc6612 feat(kuma): Cloudron HTTP-200 coverage + group discipline [#435]
55 http monitors added under "Cloud Systems" (blue/green: canary first,
verified green); 9 root-level strays re-homed into founder's groups
(root now zero). New tools: inventory (read-only dump), cloudron-sync
(idempotent diff/add from committed app list), regroup (lib-based moves;
raw editMonitor times out on this build). fleet-sync now requires
--group-id so it can never place monitors at root again.

Results: https://projects.knownelement.com/issues/435#note-4
2026-09-02 13:23:27 -05:00
mrcharles 53b847985e feat(ha): websocket driver tool; Govee integration live end-to-end [#620]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 12:59:36 -05:00
mrcharles a2ff60908e feat(mdns): one-shot browse tool; iDRAC SNMP live both DRACs; Govee creds [#619][#625]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 12:44:44 -05:00
mrcharles 2c12d7b39e docs(ha): session close-out — iDRAC creds ask, lock verdict, hygiene log [#619][#625]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 12:21:35 -05:00
mrcharles 4bf0c31609 chore: session close-out — k8s cluster rebuilt, 8/8 nodes Ready [#367][#368]
Details: https://projects.knownelement.com/issues/367
2026-09-02 12:10:07 -05:00
mrcharles 57946b7140 docs(ha): DHCP-table lock verdict — no lock OUIs, BLE-only likely [#619]
💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 12:08:40 -05:00
mrcharles 1f44a193a2 feat(k8s): cnode disks on TS5-SSD; worker roster — ultix-streaming replaces tsys5
- cnodes 102/705/603 moved to TS5-SSD storage by founder (etcd apply 4-5s -> <1s)
- wnode-tsys5 slot retired; ultix-streaming joins in its place (5 workers)
- ultix-offstage unreachable; stays excluded until back on tailnet

[#367][#368] https://projects.knownelement.com/issues/368
2026-09-02 12:03:26 -05:00
mrcharles babd6d2e25 fix(mdns): accumulate probe records across responses; unit tests [#619]
Live proof: ecobee answers unicast mDNS with PTR only
(_hap._tcp.local -> "Main Floor._hap._tcp.local"), so the old
replace-on-probe wiped learned records every cycle. Merge by
(name, type) instead. CONFIG_PATH now env-overridable for tests.
Details: https://projects.knownelement.com/issues/619#note-5

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-09-02 12:02:00 -05:00
mrcharles d3c5ae8beb fix(k8s): time-box remote cmds; k3s kubectl in post-setup; codify VM tuning
- join-workers.sh: timeout wrappers (30s token / 60s pre-clean / 300s install)
- post-setup.sh: bare kubectl/etcdctl do not exist on cnodes; use k3s kubectl
  and etcd-snapshot for health checks (taints silently failed before)
- k8s/proxmox-tuning.sh: codifies 2026-09-01 VM tuning (ssd=1,discard=on,
  queues=2, cpuunits, startup order) — dry-run default, RUN=1 applies

[#367][#368] https://projects.knownelement.com/issues/367
2026-09-01 19:32:51 -05:00
mrcharles c45be04bf5 feat(mdns): hap-bridge daemon — unicast probe to multicast replay [#619] 2026-09-01 18:43:04 -05:00
mrcharles aa510aac30 docs: ask for UniFi Integration API key [#619] 2026-09-01 18:38:40 -05:00
mrcharles 133b68ab40 fix(sensors): numeric parser anchors on degree symbol (label-digit bug) [#618] 2026-09-01 18:22:52 -05:00
mrcharles 6c8f839eaa fix(sensors): allowlist netinfra pair (TS subnet-route hairpin sources) [#618] 2026-09-01 18:16:19 -05:00
mrcharles 375a9fb3b2 fix(sensors): rocommunity6 for IPv6 ACL sources (snmpd config error) [#618] 2026-09-01 18:07:01 -05:00
mrcharles 7b922c507c feat(sensors): numeric -n mode + lmsensors_n extend for HA SNMP migration [#618] 2026-09-01 18:02:09 -05:00
mrcharles 196d0f597e docs: unattended night-grind plan for approval [#344] 2026-09-01 17:37:47 -05:00
mrcharles 3b1bf0adcb chore: HomeAssistant ops dir (config-repo pointer, needfromcharles asks); tidy test junk [#344] 2026-09-01 17:35:13 -05:00
mrcharles adfdcafeab feat(dns): git SoR + drift-check for pihole/dhcpd; serial-restart rule [#469][#420] 2026-09-01 17:07:23 -05:00
mrcharles e2d6e5c52f docs: session close-out — HA plant monitoring live, VM pipeline flowing [#344] 2026-09-01 16:12:39 -05:00
mrcharles 47323976e0 feat(dhcp): reserve pfv-minisplit-dongle 192.168.1.149 [#614][#629][#420] 2026-09-01 15:36:37 -05:00
mrcharles ab75a1713c fix(dns): reload Technitium when zone sync changes files (TDD) [#469][#344] 2026-09-01 13:41:27 -05:00
mrcharles a9a37266c7 docs(framework): field lessons + session close-out for pfv-bms stabilization [#344] 2026-09-01 13:08:30 -05:00
mrcharles 070172f93a feat(framework): VM_PORT support in remote.sh for HAOS debug SSH [#344] 2026-09-01 12:22:38 -05:00
mrcharles 39bb855a98 chore(archive): preserve KNELServerBuild remainder + layout notes [#474]
Archive the non-ported remainder of the legacy KNELServerBuild repo
under archive/KNELServerBuild/ with its original structure intact,
completing the legacy repo merge for everything except the live
LibreNMS patterns (ported in the previous commit).

Exclusions:
- .git history (superseded; legacy repo remains at its original path)
- ported files (Agents/librenms, Modules/OAM/oam-librenms.sh,
  ConfigFiles/SNMP/snmp-sudo.conf)
- vendored KNELShellFramework tree (byte-identical duplicate of the
  copy already vendored at vendor/ in this repo)
- SSH authorized-keys files (live access-control material; carrying
  them in an archive invites drift — key policy lives elsewhere)

The whole tree is skip-listed in tests/shellcheck.sh (archived legacy
code, not maintained — same standing as vendor/); check-rules.sh
already prunes archive/. Rule 9 (conflict markers) now also excludes
archive/ staged files: preserved-verbatim legacy scripts contain
decorative "====" banners that false-positive as conflict markers
(same archive exclusion precedent as rule 11).

AGENTS.md: note archive/KNELServerBuild and oam/librenms-agent in the
Repository Layout, and fix the stale KNELIAC path to
/home/reachableceo/projects/KNEL/KNELIAC.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-28 06:12:05 -05:00
mrcharles 75de9d7104 feat(oam): port LibreNMS agent tooling from KNELServerBuild [#474]
Port the live LibreNMS monitoring patterns from the legacy
KNELServerBuild repo into oam/librenms-agent/, joining the existing
OAM tooling (oxidized, unpoller, smokeping, netdisco):

- agent/ — upstream check_mk agent + snmp-extend scripts (dmi, dpkg,
  mysql, ntp-client, ntp-server, os-updates, postfix, raspberry, smart,
  ss, ups-nut), copied verbatim (md5-verified), never to be edited here
- setup.sh — deploy module ported from ProjectCode/Modules/OAM/
  oam-librenms.sh; only the legacy framework bootstrap was replaced
  with plain bash (path constants + print_info -> echo)
- snmp-sudo.conf — Debian snmpd sudo rule the extends require
  (Debian-snmp NOPASSWD /bin/cat); carried as a file only, sudoers
  install is a policy decision per AGENTS.md

Lint gates: extend the existing upstream-skip mechanism for the
verbatim agent scripts (tests/shellcheck.sh + check-rules.sh prune,
same precedent as archive/provisioning/Agents/librenms), and fix the
stale skip path there (provisioning/ moved to archive/provisioning in
6244c1c; the bash extends have been failing the whole-repo shellcheck
gate since).

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-28 06:11:08 -05:00
mrcharles f16397f95e feat(netinfra): DHCP hot-standby + dual-stack NTP/SNMP on netinfra pair [#420]
DNS/DHCP/NTP redundancy per founder ruling 2026-08-27:
- DHCP failover converted load-balance -> hot standby (split 255 on
  primary; secondary answers only if primary unreachable >3s). DHCP
  options now hand out BOTH nodes for DNS and NTP (active/active) —
  Tailscale hosts stay on MagicDNS 100.100.100.100.
- netinfra-02 ntpsec deployed (pool.ntp.org, all interfaces); 01
  repointed from debian pool zones to pool.ntp.org. NTP now redundant;
  GPS stratum-1 on pfvsvrpi tracked as follow-up ticket.
- snmpd on both nodes with scoped ACLs (LibreNMS LAN+TS sources only)
  and ntpq/dhcpd-lease extends — prep for DNS/DHCP/NTP graphing.
- Deployed sync-zones.sh (git version, DNS name instead of IP literal)
  to netinfra-02; zone sync verified 171/171 zones both nodes.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 13:02:26 -05:00
mrcharles ae8af3472b fix(framework): per-session ticket files unblock parallel sessions [#439]
The ticket gate required the single .crush/active-ticket file, so two
concurrent sessions overwrote each other's ticket mid-work. The gate now
accepts any non-empty .crush/active-ticket* file; each session keeps its
own (e.g. active-ticket-plant, active-ticket-core). Also prune .crush/
session scratch from both shellcheck scanners so one session's throwaway
probe scripts cannot block the other session's commits. Documented in
AGENTS.md Task Tracking.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 13:01:25 -05:00
mrcharles 5977eba503 feat(sensors): sysfs thermal fallback + SBC fleet coverage [#341][#457][#458]
lm-sensors is silent on SBCs (Pis, Jetson-class), so the wrapper now falls
back to /sys/class/thermal zones rendered in lm-sensors format when native
sensors output is empty; suppressed when native output exists to avoid
duplicates. TDD: 3 new unit tests (12 green). Sensor stack deployed to
jetson + pfvsvrpi + 3 subopis (verified from poller), HA pack extended to
16 sensors across 14 hosts, high-temp automation covers the SBC fleet.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 12:00:43 -05:00
mrcharles 2b6fc2b388 feat(ha): pfv-bms plant monitoring YAML pack [#439]
SNMP sensors for all 9 instrumented hosts (temps in °F per founder
ruling, °C converted at display layer), ACPI node-wattage feeds for
tsys6/7, UPS alert automations (on-battery, battery-low, comm-lost,
power-restored, high-temp) targeting Pushover, and Riemann-sum kWh
helpers for the Energy dashboard. PDU and iDRAC blocks left as pinned
placeholders pending PDU community and #462 OMSA work.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 11:35:58 -05:00
mrcharles d2f4214b8c fix(dhcp): correct pfv-tsys6-oob reservation MAC to live iDRAC6 [#460]
The reservation carried a4:ba:db:0b:df:a0 (core-switch OUI, mis-migrated
from pfv-netboot) so tsys6's iDRAC could never lease its reserved address.
Replaced with the in-band-verified BMC MAC; deployed to both failover
nodes, validated, restarted.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 11:23:09 -05:00
mrcharles df2a60e8b2 docs(framework): field-lessons section + parallel-session scratch protocol [#439]
Persist physical-plant session gotchas (venv trap, temperusb API, CLI body
scanner workaround, app-connector source IPs, NUT/udev restart quirks) so
future sessions inherit them. Document .crush/WORKING-PLANT.md split for
concurrent sessions sharing the repo.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 11:02:32 -05:00
mrcharles 333f2ae51b feat(sensors): lm-sensors+TEMPer SNMP extend on 6 hosts with scoped ACLs [#341][#439][#458][#459]
Native lm-sensors output plus optional TEMPer USB probe, unified in
lm-sensors format behind one snmpd extend (lmsensors). Idempotent
deploy binds snmpd to explicit LAN+Tailscale addresses only and
source-scopes the community to the pollers (LibreNMS, Home Assistant
app-connector LAN IP, admin workstation, Cloudron) per the founder's
security ruling. TDD unit suite included; fleet verified live (6 hosts)
and negative-tested (refused source).

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 10:46:57 -05:00
mrcharles 350d984e34 sync(dhcp): back-port live netinfra-01/02 dhcpd.conf to repo [#420]
The live configs were edited in place (canonical renames, stale block
removal, 7 new reservations, 69 total) but the repo copies were never
updated — the exact drift class that bit pi-hole. Repo and live state
now match on both failover nodes.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
EOF
2026-08-27 09:32:16 -05:00
mrcharles 721968bc3b docs(framework): complete TSYSGroupAIOS adoption + tracker/IaC rules [#454]
Bring the framework's global baseline (BASELINE-PROMPT.md, PATTERNS.md,
ADOPTING.md) into the repo — AGENTS.md referenced them but the files were
missing. AGENTS.md gains three rules adopted this session: TDD & Linting
(mandatory at the Ansible/IaC transition), IaC codification shadow-tracking
(every manual fleet change same-day ticketed to #454), and Redmine tracker
discipline (Support not Bug — the CLI default created nine misfiled
tickets, now corrected). Q10 records the direct-push vs PR conflict for
the founder to rule on.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-27 09:26:26 -05:00
mrcharles 28b28026bf docs: session close-out — WORKING.md cleared, handoff via #439/#454 [#446] 2026-08-27 09:20:54 -05:00
mrcharles cb327bcfed feat(netinfra): 192.168/16 reverse forwarding to Technitium on both nodes [#449]
pi-hole on netinfra-01/02 now conditionally forwards 192.168.0.0/16
reverse lookups to this node's Technitium over dnsnet, alongside the
existing knel.net + 100.64/10 pair. Technitium stays the single source
of truth; pollers (NetDisco, phpIPAM, UNPoller, Wazuh soon) resolving
via either node's :53 now get LAN PTRs. Both live revServer arrays and
this compose file are in sync; validated with forward, PTR (192.168 +
100.x), and external lookups against both nodes.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-26 21:21:15 -05:00
mrcharles a4920893b1 fix(test): scope local gate to unit suite [#420]
The full legacy suite mixes repo tests with deployment-target tests
(PAM packages, target resolv.conf, Proxmox repo reachability) that can
only pass on a provisioned server. The workstation gate now runs the
unit suite; validation/security stay invocable for sectestbed runs.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-26 20:56:28 -05:00
mrcharles 52e0e4cf4e chore(framework): complete TSYSGroupAIOS adoption + extend Kuma device coverage [#420][#435]
Fill the framework gaps the Makefile already referenced: scripts/test.sh
(wrapper over tests/run-tests.sh, now exercised by the pre-push full
audit) and up.sh/down.sh stubs for this non-compose repo. Extend
kuma-fleet-sync STATIC_GEAR with the fixed network/office devices
(printer, consrv, tsys6/7 OOB, scanners, label printer, r1-tor-top,
DOME) so future runs keep their ICMP monitors in sync; DOME added
paused like the other known-down systems.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-26 20:49:44 -05:00
mrcharles 28c2b16fd0 feat(kuma): fleet ICMP coverage sync script [#435]
Gap-analyzes the tailnet Linux fleet + static network gear (switches,
router, APs, PDU, stor1, Reston VPSes) against Uptime Kuma ping
monitors over the socket.io API, and can create missing monitors with
--add. Websocket transport is forced because the Cloudron proxy drops
engine.io polling pushes. First run closed the last 4 gaps: 84/84.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-26 19:12:28 -05:00