Current Build State
Dated Site A snapshot: working UCG Max bootstrap island, live edge VMs, and approved-but-not-yet-production OPNsense/L2 target as of 2026-07-26.
As of 2026-07-26, the working network remains the UCG Max, XG 6 PoE, and U7
Pro XGS bootstrap island. The four Site A Proxmox hosts have bootstrap addresses,
and the three edge VMs remain reachable through sa-edge-01; the XG6 does not fan
the flat network through an XG10. Its p4 copper lead serves one host or BMC at a
time, while p5/p6 stay disconnected. No XG10 ever connects to UCG Max or XG6. The clean-slate target is approved but
not yet production. Site B is parked and has not started.
Intent Is Not Deployment Evidence
The new VLANs, final IPs, switch profiles, and port assignments are target state until their A3-A8 gates are observed and recorded.
Status
| Component | State |
|---|---|
| Four Site A Proxmox nodes built and baselined using bootstrap addresses | complete |
sa-fw-01 hands-off provision/rebuild and baseline config | complete as of 2026-07-12 |
sa-uos-01 provision and first-run config | complete |
sa-bao-01 initialized, unsealed, and seeded | complete; manual Shamir unseal remains |
| UCG Max/XG6/AP backup, labels, and rollback map (A0) | must be re-verified before campaign |
Three new switches adopted to sa-uos-01 (A3) | pending |
| Final-addressed OPNsense VLAN/policy target (A4) | pending |
| Control-plane migration (A5) | pending |
| Final RSTP triangle and 36-port map (A6) | pending |
| AP/SSID/client migration on final LAN (A7) | pending |
| WAN-only ONT handoff and bootstrap retirement (A8) | pending |
final host IPs and sa-pve (A9) | pending |
| ZFS/PBS/DNS/monitoring (A10) | pending |
| Kubernetes/OpenShift (A11) | pending |
Observed Bootstrap Addresses
These addresses describe the bootstrap lifecycle, not simultaneous permanent
cabling. XG6 p4 is the one-at-a-time service/recovery lead. Once
sa-edge-01 nic0 occupies p4 for the edge VMs, leave it connected until A5
unless local console access is available.
| System | Address |
|---|---|
| UCG Max gateway | 192.168.0.1 |
sa-edge-01 Proxmox | 192.168.1.10 |
sa-cmp-01 Proxmox | 192.168.1.11 |
sa-cmp-02 Proxmox | 192.168.1.12 |
sa-stor-01 Proxmox | 192.168.1.20 |
sa-edge-01 IPMI | 192.168.0.10 |
sa-stor-01 IPMI | 192.168.0.20 |
sa-uos-01 | 192.168.1.40 |
sa-fw-01 seed management | 192.168.1.41 |
sa-bao-01 reserved lease | 192.168.1.136 |
sa-edge-01 Bridge Target
| Bridge | Physical NIC | Final role | Host IP |
|---|---|---|---|
vmbr0 | nic0 / onboard 1G #1 | Proxmox management, access VLAN 20 | 10.10.20.10 |
vmbr1 | nic3 / onboard 10G #1 | OPNsense WAN | none |
vmbr2 | nic2 / onboard 10G #2 | VLAN-aware OPNsense LAN trunk | none |
vmbr3 | nic1 / onboard 1G #2 | Corosync, access VLAN 25 | 10.10.25.10, no gateway |
Inside OPNsense, the LAN vNIC requires explicit Proxmox trunks
10;20;30;40;50;70;80;90;100;110;120. The current shared aorxi_core.Vm
component does not yet expose that property. UOS also needs a controlled
temporary dual-homing capability for A5. These are implementation gates, not
reasons to change the architecture.
Approved Final Edge Services
| VM | Final network | Final address |
|---|---|---|
sa-fw-01 | every routed Site A VLAN | .1 on 10,20,30,40,50,70,80,90,100,110,120 |
sa-uos-01 | VLAN 10 | 10.10.10.40 |
sa-bao-01 | VLAN 30 | 10.10.30.40 |
Site A does not configure VLAN 253 or 4040. 10.10.253.0/24 is reserved.
VLAN 999 is a no-IP/no-DHCP native sink.
Next Actions
- Reconcile A0 exports, labels, physical NIC identities, and rollback cabling.
- Add and preview the explicit OPNsense VM trunk support.
- Provide and preview controlled UOS temporary dual-homing across A3-A5.
- Bring up target VLAN 10, then build and adopt all three XG10s through the isolated edge nic2→sw1→sw2/sw3 tree at final addresses; keep XG6 p5/p6 disconnected.
- Execute A3-A7 until every endpoint uses final
10.10.x, then freeze the LAN and perform the A8 WAN-only handoff with local console access.
See Build Phases, Migration Phases, and Site A Port Map.
Site A Build Phases
Clean-slate A0-A11 Site A sequence from the working UCG Max bootstrap island through OPNsense, the L2 fabric, Proxmox, storage, and Kubernetes.
IPMI / KVM Remote Console
Runbook for Supermicro IPMI access and remote ISO installation via Java iKVM, HTML5 KVM, IPMIView, and SMB virtual media.