Berwn
ab8288aef9
Update vars via generator emergency-access for machine ns1
2026-06-14 15:00:24 +07:00
Berwn
7b292b8279
Update vars via generator emergency-access for machine control
2026-06-14 15:00:24 +07:00
Berwn
56f0af3153
Fix knot startup on ns1/ns2: TSIG key perms and port 53 conflict
...
knotd runs as the "knot" user, so the shared TSIG key file needs
owner/group knot — it was root-only and knot couldn't read it.
systemd-resolved's stub listener was holding port 53, so knot's
0.0.0.0@53 / ::@53 TCP bind failed. Disable the stub (resolution
still works via nss-resolve) to free the port.
2026-06-14 14:49:10 +07:00
Berwn
9de95b4fb5
update(inventory.json): Installed ns2
2026-06-14 13:34:17 +07:00
Berwn
099383ccfa
update(inventory.json): Installed ns1
2026-06-14 13:29:53 +07:00
Berwn
807785cdab
Add authoritative DNS on ns1/ns2 and finalize clan config
...
- Knot authoritative DNS: ns1 primary, ns2 secondary serving cnx.network,
buildfor.life and cnx.email over TSIG-secured zone transfer (modules/dns)
- Knot listens publicly + over ZeroTier; firewall opens port 53
- Complete clan inventory: name/domain, admin SSH key, control as the
zerotier controller, tor on all nixos machines
- Enable age yubikey/fido2-hmac secret plugins
2026-06-14 13:24:23 +07:00
Berwn
9f1a2861ce
Add ns2 to secret vars/shared/dns-tsig/tsig.conf
2026-06-14 13:22:43 +07:00
Berwn
2798e8e8f0
Update vars via generator dns-tsig for machine ns1
2026-06-14 13:22:39 +07:00
Berwn
a40c4d1800
Set disk schema of machine: ns2 to single-disk
2026-06-14 13:19:56 +07:00
Berwn
2a0bdc4a4b
Set disk schema of machine: ns1 to single-disk
2026-06-14 13:19:44 +07:00
Berwn
840b3ca407
machines/ns2/facter.json: update hardware configuration
2026-06-14 13:18:41 +07:00
Berwn
d757dc3c52
machines/ns1/facter.json: update hardware configuration
2026-06-14 13:16:11 +07:00
Berwn
80a9761878
Update vars via generator zerotier for machine ns2
2026-06-14 12:36:52 +07:00
Berwn
6aa68a0e4d
Update vars via generator zerotier for machine ns1
2026-06-14 12:36:51 +07:00
Berwn
67e60910be
update(inventory.json): Installed control
2026-06-14 12:36:24 +07:00
Berwn
bf65146a62
Set disk schema of machine: control to single-disk
2026-06-14 12:29:39 +07:00
Berwn
8938637c28
machines/control/facter.json: update hardware configuration
2026-06-14 12:27:20 +07:00
Berwn
ede5478952
Update vars via generator tor_tor for machine ns2
2026-06-14 12:20:30 +07:00
Berwn
e142ea93c4
Update vars via generator state-version for machine ns2
2026-06-14 12:20:28 +07:00
Berwn
8240948bf3
Update vars via generator root-password for machine ns2
2026-06-14 12:20:27 +07:00
Berwn
29312a9e8d
Update vars via generator openssh for machine ns2
2026-06-14 12:20:27 +07:00
Berwn
75f2df3ddf
Add machine ns2 to secrets
2026-06-14 12:20:27 +07:00
Berwn
b0a99eb16e
Update secret ns2-age.key
2026-06-14 12:20:27 +07:00
Berwn
f620ca0f48
Update vars via generator tor_tor for machine ns1
2026-06-14 12:20:27 +07:00
Berwn
585e523aff
Update vars via generator state-version for machine ns1
2026-06-14 12:20:25 +07:00
Berwn
14fc046763
Update vars via generator root-password for machine ns1
2026-06-14 12:20:25 +07:00
Berwn
061ffaffa0
Update vars via generator openssh for machine ns1
2026-06-14 12:20:24 +07:00
Berwn
8c8a97ab1f
Add machine ns1 to secrets
2026-06-14 12:20:24 +07:00
Berwn
63b6f7ce42
Update secret ns1-age.key
2026-06-14 12:20:24 +07:00
Berwn
f0672c5326
Update vars via generator zerotier for machine control
2026-06-14 12:20:24 +07:00
Berwn
474f367831
Update vars via generator tor_tor for machine control
2026-06-14 12:20:24 +07:00
Berwn
35fd5bae84
Update vars via generator state-version for machine control
2026-06-14 12:20:21 +07:00
Berwn
11ef4ed182
Update vars via generator root-password for machine control
2026-06-14 12:20:21 +07:00
Berwn
9aeaa94686
Update vars via generator openssh for machine control
2026-06-14 12:20:21 +07:00
Berwn
88511391c4
Add machine control to secrets
2026-06-14 12:20:21 +07:00
Berwn
89ccafa67d
Update secret control-age.key
2026-06-14 12:20:21 +07:00
Berwn
7d02499c0e
Add machine ns2
2026-06-14 12:14:12 +07:00
Berwn
bda1854376
Add machine ns1
2026-06-14 12:14:10 +07:00
Berwn
a86525d37c
Add machine control
2026-06-14 12:14:07 +07:00
Berwn
cb68cbe75d
Add user berwn to secrets
2026-06-14 12:11:28 +07:00
Berwn
0faa5884f2
Initial commit
2026-06-14 12:11:16 +07:00