Pin Athena LAN interface by permanent MAC
This commit is contained in:
@@ -6,7 +6,8 @@ ADMIN_USER=mike
|
|||||||
MODEL_DIR=/srv/mike-ai/models
|
MODEL_DIR=/srv/mike-ai/models
|
||||||
|
|
||||||
# Installing a new NVIDIA driver can require one reboot. In that case this
|
# Installing a new NVIDIA driver can require one reboot. In that case this
|
||||||
# installer exits with code 20; rerun the same command after reboot.
|
# installer exits with code 20 (NVIDIA) or 21 (stable NIC rename); rerun the
|
||||||
|
# same command after reboot.
|
||||||
INSTALL_NVIDIA_DRIVER=true
|
INSTALL_NVIDIA_DRIVER=true
|
||||||
# Optional: auf einen im offiziellen NVIDIA-Repository vorhandenen Hauptzweig
|
# Optional: auf einen im offiziellen NVIDIA-Repository vorhandenen Hauptzweig
|
||||||
# festlegen (z. B. 610). Leer lassen, um dem aktuellen stabilen Zweig zu folgen.
|
# festlegen (z. B. 610). Leer lassen, um dem aktuellen stabilen Zweig zu folgen.
|
||||||
@@ -20,8 +21,11 @@ FLUX_MODEL_DIR=/data/models/FLUX.2-klein-4B
|
|||||||
# Headless remote recovery. The ASUS UEFI settings documented in
|
# Headless remote recovery. The ASUS UEFI settings documented in
|
||||||
# docs/REMOTE_SITE_CHECKLIST.md are additionally required.
|
# docs/REMOTE_SITE_CHECKLIST.md are additionally required.
|
||||||
ENABLE_HARDWARE_WATCHDOG=true
|
ENABLE_HARDWARE_WATCHDOG=true
|
||||||
PRIMARY_NETWORK_INTERFACE=enp7s0
|
# Bind the physical NIC to a stable name independent of its PCIe slot path.
|
||||||
WAKE_ON_LAN_INTERFACE=enp7s0
|
PRIMARY_NETWORK_MAC=58:11:22:BB:AD:0C
|
||||||
|
PERSISTENT_NETWORK_NAME=lan0
|
||||||
|
PRIMARY_NETWORK_INTERFACE=lan0
|
||||||
|
WAKE_ON_LAN_INTERFACE=lan0
|
||||||
SSH_KEY_ONLY=true
|
SSH_KEY_ONLY=true
|
||||||
|
|
||||||
# WireGuard terminates in a dedicated Docker gateway. The Fritzbox export is a
|
# WireGuard terminates in a dedicated Docker gateway. The Fritzbox export is a
|
||||||
|
|||||||
@@ -26,12 +26,20 @@ mit 60 Sekunden und konfiguriert Wake-on-LAN für das in
|
|||||||
beim Boot als auch bei einem später erkannten Kabel aktiviert. SSH und Docker
|
beim Boot als auch bei einem später erkannten Kabel aktiviert. SSH und Docker
|
||||||
müssen aktiviert sein.
|
müssen aktiviert sein.
|
||||||
|
|
||||||
|
Die physische Netzwerkkarte wird über ihre permanente MAC-Adresse erkannt und
|
||||||
|
durch `/etc/systemd/network/10-athena-lan.link` fest `lan0` genannt. Damit
|
||||||
|
ändert sich der produktive Interface-Name nicht, wenn Grafikkarten oder andere
|
||||||
|
PCIe-Geräte ergänzt oder entfernt werden. Nach der erstmaligen Einrichtung
|
||||||
|
beendet sich der Installer mit Exit-Code 21; nach dem erforderlichen Neustart
|
||||||
|
wird derselbe Installationsbefehl erneut ausgeführt.
|
||||||
|
|
||||||
Vor dem Transport prüfen:
|
Vor dem Transport prüfen:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
systemctl is-enabled ssh docker mike-ai-container-vpn-guard
|
systemctl is-enabled ssh docker mike-ai-container-vpn-guard
|
||||||
systemctl is-active ssh docker mike-ai-container-vpn-guard
|
systemctl is-active ssh docker mike-ai-container-vpn-guard
|
||||||
ethtool enp7s0 | grep Wake-on
|
ip link show lan0
|
||||||
|
ethtool lan0 | grep Wake-on
|
||||||
systemctl show -p RuntimeWatchdogUSec
|
systemctl show -p RuntimeWatchdogUSec
|
||||||
docker inspect -f '{{.State.Health.Status}}' mike-ai-wireguard-gateway
|
docker inspect -f '{{.State.Health.Status}}' mike-ai-wireguard-gateway
|
||||||
docker exec mike-ai-wireguard-gateway wg show wg0 latest-handshakes
|
docker exec mike-ai-wireguard-gateway wg show wg0 latest-handshakes
|
||||||
|
|||||||
+46
@@ -70,6 +70,51 @@ install_base_packages() {
|
|||||||
iproute2 pciutils rsync unattended-upgrades ethtool
|
iproute2 pciutils rsync unattended-upgrades ethtool
|
||||||
}
|
}
|
||||||
|
|
||||||
|
setup_stable_network_name() {
|
||||||
|
local mac=${PRIMARY_NETWORK_MAC:-}
|
||||||
|
local desired=${PERSISTENT_NETWORK_NAME:-}
|
||||||
|
[[ -n $mac && -n $desired ]] || return 0
|
||||||
|
[[ $mac =~ ^([[:xdigit:]]{2}:){5}[[:xdigit:]]{2}$ ]] || \
|
||||||
|
die "PRIMARY_NETWORK_MAC ist ungültig: $mac"
|
||||||
|
[[ $desired =~ ^[a-zA-Z0-9_.-]+$ ]] || \
|
||||||
|
die "PERSISTENT_NETWORK_NAME ist ungültig: $desired"
|
||||||
|
|
||||||
|
mac=${mac,,}
|
||||||
|
local current="" path
|
||||||
|
for path in /sys/class/net/*; do
|
||||||
|
[[ -f $path/address ]] || continue
|
||||||
|
if [[ $(<"$path/address") == "$mac" ]]; then
|
||||||
|
current=${path##*/}
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
[[ -n $current ]] || die "Keine Netzwerkkarte mit permanenter MAC $mac gefunden."
|
||||||
|
|
||||||
|
log "Stabilen Netzwerknamen $desired für $mac konfigurieren"
|
||||||
|
install -d -m 0755 /etc/systemd/network
|
||||||
|
cat >/etc/systemd/network/10-athena-lan.link <<EOF
|
||||||
|
[Match]
|
||||||
|
PermanentMACAddress=$mac
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
Name=$desired
|
||||||
|
EOF
|
||||||
|
chmod 0644 /etc/systemd/network/10-athena-lan.link
|
||||||
|
|
||||||
|
if [[ $current != "$desired" ]]; then
|
||||||
|
[[ -f /etc/network/interfaces ]] || \
|
||||||
|
die "/etc/network/interfaces fehlt; sichere automatische Umstellung nicht möglich."
|
||||||
|
cp -a /etc/network/interfaces \
|
||||||
|
"/etc/network/interfaces.before-stable-name-$(date +%Y%m%d-%H%M%S)"
|
||||||
|
sed -i "s/\\<$current\\>/$desired/g" /etc/network/interfaces
|
||||||
|
grep -q "^iface $desired inet " /etc/network/interfaces || \
|
||||||
|
die "Netzwerkprofil wurde nicht auf $desired umgestellt."
|
||||||
|
log "Netzwerkname wird beim nächsten Boot von $current auf $desired geändert."
|
||||||
|
log "Bitte neu starten und denselben Installer danach erneut ausführen."
|
||||||
|
exit 21
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
setup_remote_recovery() {
|
setup_remote_recovery() {
|
||||||
log "Remote-Recovery (Hardware-Watchdog und Wake-on-LAN) konfigurieren"
|
log "Remote-Recovery (Hardware-Watchdog und Wake-on-LAN) konfigurieren"
|
||||||
|
|
||||||
@@ -481,6 +526,7 @@ PY
|
|||||||
|
|
||||||
hostnamectl set-hostname "$AI_HOSTNAME"
|
hostnamectl set-hostname "$AI_HOSTNAME"
|
||||||
install_base_packages
|
install_base_packages
|
||||||
|
setup_stable_network_name
|
||||||
setup_remote_recovery
|
setup_remote_recovery
|
||||||
setup_ssh_hardening
|
setup_ssh_hardening
|
||||||
install_docker
|
install_docker
|
||||||
|
|||||||
@@ -32,6 +32,14 @@ else
|
|||||||
fail "nvidia-smi fehlt"
|
fail "nvidia-smi fehlt"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [[ -e /sys/class/net/lan0 ]] && \
|
||||||
|
[[ "$(< /sys/class/net/lan0/address)" == "58:11:22:bb:ad:0c" ]] && \
|
||||||
|
[[ "$(< /sys/class/net/lan0/operstate)" == "up" ]]; then
|
||||||
|
pass "stabiles LAN-Interface lan0 aktiv (58:11:22:bb:ad:0c)"
|
||||||
|
else
|
||||||
|
fail "stabiles LAN-Interface lan0 fehlt, ist down oder hat die falsche MAC"
|
||||||
|
fi
|
||||||
|
|
||||||
container_healthy() {
|
container_healthy() {
|
||||||
local name=$1 state health
|
local name=$1 state health
|
||||||
state="$(docker inspect --format '{{.State.Status}}' "$name" 2>/dev/null || true)"
|
state="$(docker inspect --format '{{.State.Status}}' "$name" 2>/dev/null || true)"
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
[Match]
|
||||||
|
PermanentMACAddress=58:11:22:BB:AD:0C
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
Name=lan0
|
||||||
@@ -1,3 +1,3 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
[ "${IFACE:-}" = "enp7s0" ] || exit 0
|
[ "${IFACE:-}" = "lan0" ] || exit 0
|
||||||
/usr/sbin/ethtool -s enp7s0 wol g
|
/usr/sbin/ethtool -s lan0 wol g
|
||||||
|
|||||||
Reference in New Issue
Block a user