Restructure: move infra packages to root level

This commit is contained in:
Artemis
2026-06-14 19:53:10 -04:00
parent 6f4c54cdbb
commit a54d4cb0c9
49 changed files with 0 additions and 0 deletions

View File

@@ -0,0 +1,35 @@
# Tailscale Subnet Router LXC Deployment — CHECKPOINT
## Status: 2026-06-11 22:20 UTC
### Progress
-**3030** (MK33): Online, advertising `192.168.0.0/18`, route approved
-**3031** (MK33): FIXED — tailscaled running, route approved by Bobby in console
-**Skill created:** `tailscale-lxc-subnet-router` — documents 3031 fix + critical route hijacking pitfall
-**Artemis LAN partition FIXED:** `tailscale set --accept-routes=false` restored direct L2 routing
-**Bobby can now SSH directly to Artemis** (was blocked by Tailscale routing table hijacking)
-**3032/3033** (MK50): Terraform ready — awaiting deploy signal
### Critical Discovery — Tailscale Route Hijacking
**Root cause of Artemis "network partition":** `tailscale set --accept-routes=true` installed kernel routing rules (table 52) that redirected ALL `192.168.0.0/18` traffic through `tailscale0` instead of direct `eno1`.
| Before Fix | After Fix |
|-----------|-----------|
| `ip route get 192.168.50.41``dev tailscale0` | `ip route get 192.168.50.41``dev eno1` ✅ |
| Bobby could NOT SSH to Artemis via LAN | Bobby CAN SSH to Artemis via LAN ✅ |
| Artemis could NOT reach fleet nodes via LAN | Artemis routing table correct (pings still fail for some nodes — separate issues) |
**Standing rule:** Artemis must NOT `accept-routes` while advertising `192.168.0.0/18`. Subnet routers (3030/3031) handle tailnet→LAN; Artemis stays direct L2 for LAN peers.
### 3031 Fix Summary
**Root cause:** `/etc/default/tailscaled` missing `PORT` variable → systemd unit `--port=${PORT}` expanded to `--port=``INVALIDARGUMENT`
**Solution:** `pct exec` from MK33 host, wrote `PORT=41641` + `FLAGS=`, daemon-reload, restart, re-auth with route-capable key
### Credentials
- Latest LXC auth key stored in `fleet.env` as `TAILSCALE_AUTH_KEY_LXC`
- MK50 PVE API token exists in `fleet.env`
### Next Actions
1. Deploy 3032/3033 on MK50 via Terraform when Bobby signals
2. Verify all 4 LXCs advertise `192.168.0.0/18` and routes approved
3. Investigate remaining LAN unreachability for MK50/MK33/Shield (may be their own accept-routes conflicts)