Pin Athena LAN interface by permanent MAC

This commit is contained in:
Mikei386
2026-08-23 07:04:48 +02:00
parent 2ef894160a
commit 0887e4ba90
6 changed files with 77 additions and 6 deletions
+7 -3
View File
@@ -6,7 +6,8 @@ ADMIN_USER=mike
MODEL_DIR=/srv/mike-ai/models
# Installing a new NVIDIA driver can require one reboot. In that case this
# installer exits with code 20; rerun the same command after reboot.
# installer exits with code 20 (NVIDIA) or 21 (stable NIC rename); rerun the
# same command after reboot.
INSTALL_NVIDIA_DRIVER=true
# Optional: auf einen im offiziellen NVIDIA-Repository vorhandenen Hauptzweig
# festlegen (z. B. 610). Leer lassen, um dem aktuellen stabilen Zweig zu folgen.
@@ -20,8 +21,11 @@ FLUX_MODEL_DIR=/data/models/FLUX.2-klein-4B
# Headless remote recovery. The ASUS UEFI settings documented in
# docs/REMOTE_SITE_CHECKLIST.md are additionally required.
ENABLE_HARDWARE_WATCHDOG=true
PRIMARY_NETWORK_INTERFACE=enp7s0
WAKE_ON_LAN_INTERFACE=enp7s0
# Bind the physical NIC to a stable name independent of its PCIe slot path.
PRIMARY_NETWORK_MAC=58:11:22:BB:AD:0C
PERSISTENT_NETWORK_NAME=lan0
PRIMARY_NETWORK_INTERFACE=lan0
WAKE_ON_LAN_INTERFACE=lan0
SSH_KEY_ONLY=true
# WireGuard terminates in a dedicated Docker gateway. The Fritzbox export is a
+9 -1
View File
@@ -26,12 +26,20 @@ mit 60 Sekunden und konfiguriert Wake-on-LAN für das in
beim Boot als auch bei einem später erkannten Kabel aktiviert. SSH und Docker
müssen aktiviert sein.
Die physische Netzwerkkarte wird über ihre permanente MAC-Adresse erkannt und
durch `/etc/systemd/network/10-athena-lan.link` fest `lan0` genannt. Damit
ändert sich der produktive Interface-Name nicht, wenn Grafikkarten oder andere
PCIe-Geräte ergänzt oder entfernt werden. Nach der erstmaligen Einrichtung
beendet sich der Installer mit Exit-Code 21; nach dem erforderlichen Neustart
wird derselbe Installationsbefehl erneut ausgeführt.
Vor dem Transport prüfen:
```bash
systemctl is-enabled ssh docker mike-ai-container-vpn-guard
systemctl is-active ssh docker mike-ai-container-vpn-guard
ethtool enp7s0 | grep Wake-on
ip link show lan0
ethtool lan0 | grep Wake-on
systemctl show -p RuntimeWatchdogUSec
docker inspect -f '{{.State.Health.Status}}' mike-ai-wireguard-gateway
docker exec mike-ai-wireguard-gateway wg show wg0 latest-handshakes
+46
View File
@@ -70,6 +70,51 @@ install_base_packages() {
iproute2 pciutils rsync unattended-upgrades ethtool
}
setup_stable_network_name() {
local mac=${PRIMARY_NETWORK_MAC:-}
local desired=${PERSISTENT_NETWORK_NAME:-}
[[ -n $mac && -n $desired ]] || return 0
[[ $mac =~ ^([[:xdigit:]]{2}:){5}[[:xdigit:]]{2}$ ]] || \
die "PRIMARY_NETWORK_MAC ist ungültig: $mac"
[[ $desired =~ ^[a-zA-Z0-9_.-]+$ ]] || \
die "PERSISTENT_NETWORK_NAME ist ungültig: $desired"
mac=${mac,,}
local current="" path
for path in /sys/class/net/*; do
[[ -f $path/address ]] || continue
if [[ $(<"$path/address") == "$mac" ]]; then
current=${path##*/}
break
fi
done
[[ -n $current ]] || die "Keine Netzwerkkarte mit permanenter MAC $mac gefunden."
log "Stabilen Netzwerknamen $desired für $mac konfigurieren"
install -d -m 0755 /etc/systemd/network
cat >/etc/systemd/network/10-athena-lan.link <<EOF
[Match]
PermanentMACAddress=$mac
[Link]
Name=$desired
EOF
chmod 0644 /etc/systemd/network/10-athena-lan.link
if [[ $current != "$desired" ]]; then
[[ -f /etc/network/interfaces ]] || \
die "/etc/network/interfaces fehlt; sichere automatische Umstellung nicht möglich."
cp -a /etc/network/interfaces \
"/etc/network/interfaces.before-stable-name-$(date +%Y%m%d-%H%M%S)"
sed -i "s/\\<$current\\>/$desired/g" /etc/network/interfaces
grep -q "^iface $desired inet " /etc/network/interfaces || \
die "Netzwerkprofil wurde nicht auf $desired umgestellt."
log "Netzwerkname wird beim nächsten Boot von $current auf $desired geändert."
log "Bitte neu starten und denselben Installer danach erneut ausführen."
exit 21
fi
}
setup_remote_recovery() {
log "Remote-Recovery (Hardware-Watchdog und Wake-on-LAN) konfigurieren"
@@ -481,6 +526,7 @@ PY
hostnamectl set-hostname "$AI_HOSTNAME"
install_base_packages
setup_stable_network_name
setup_remote_recovery
setup_ssh_hardening
install_docker
+8
View File
@@ -32,6 +32,14 @@ else
fail "nvidia-smi fehlt"
fi
if [[ -e /sys/class/net/lan0 ]] && \
[[ "$(< /sys/class/net/lan0/address)" == "58:11:22:bb:ad:0c" ]] && \
[[ "$(< /sys/class/net/lan0/operstate)" == "up" ]]; then
pass "stabiles LAN-Interface lan0 aktiv (58:11:22:bb:ad:0c)"
else
fail "stabiles LAN-Interface lan0 fehlt, ist down oder hat die falsche MAC"
fi
container_healthy() {
local name=$1 state health
state="$(docker inspect --format '{{.State.Status}}' "$name" 2>/dev/null || true)"
+5
View File
@@ -0,0 +1,5 @@
[Match]
PermanentMACAddress=58:11:22:BB:AD:0C
[Link]
Name=lan0
+2 -2
View File
@@ -1,3 +1,3 @@
#!/bin/sh
[ "${IFACE:-}" = "enp7s0" ] || exit 0
/usr/sbin/ethtool -s enp7s0 wol g
[ "${IFACE:-}" = "lan0" ] || exit 0
/usr/sbin/ethtool -s lan0 wol g