Archived
Document pve-test's wifi-primary network and add Claude node guardrails
pve-test was briefly clustered with pve1 then deliberately de-clustered so it could move to wifi-primary networking (4addr bridge mode, bonded with a wired LAN backup) - a change not achievable while clustered given corosync's latency requirements. Captures that as a reproducible script plus docs: cluster separation procedure, the wifi network design and the live-cutover pitfalls hit along the way, and node-role/history context. Also adds CLAUDE.md guardrails for pve1 (production) vs pve-test (sandbox) - this repo had none before, despite scripts here being able to make real changes to both. Separately: both nodes' mgmt firewalls were dropping ICMP by default (TCP 22/8006 only), which looked like an outage mid-troubleshooting even though SSH/web UI were fine. Added an explicit ping-allow rule to the firewall template, applied it live on both nodes, and added an audit.sh check so it stays enforced.
This commit is contained in:
@@ -11,6 +11,17 @@ PVE datacenter firewall (default-deny inbound otherwise). That's
|
||||
sufficient until Stage 2 needs actual separate physical/VLAN paths for
|
||||
corosync and Ceph traffic — see below.
|
||||
|
||||
## pve-test as built (sandbox, current)
|
||||
|
||||
Different node, different design, not a Stage 1/2 example to generalize
|
||||
from: `pve-test` runs `vmbr0` bridged over a wifi NIC in 4addr client mode
|
||||
(active-backup bonded with a wired NIC as an automatic fallback). Full
|
||||
detail, including why this is normally impossible and how it was
|
||||
validated before trusting it with the management IP, in
|
||||
`06-pve-test-wifi-network.md`. This is intentionally a one-off for a
|
||||
standalone sandbox box — never extend it to a node that's clustered or
|
||||
Ceph-connected (see the Stage 2 note in `00-overview.md`).
|
||||
|
||||
## Target design (Stage 2, future cluster)
|
||||
|
||||
## Required separation
|
||||
|
||||
Reference in New Issue
Block a user