docs(netbird): N1 sandbox handoff — §7(cont.) partial run, baseline+privilege findings (#258)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Backtalk6858
2026-09-18 13:11:51 -05:00
parent 655a38e2b6
commit 1569cccae4
@@ -143,3 +143,51 @@ deferred systemd timer registrations (Twingate connector self-heal + NetBird rel
## Update instructions
Fill in sandbox results for steps 2, 4, 6; mark buildplan items (b)/(c) RESOLVED; then spin §3–§5 into
`playbook_netbird_phases.md` and start the build on server-01.
---
## 7 (cont.) — N1 sandbox handoff (2026-09-18, background agent)
**Status: partially_succeeded — stopped at the privileged / production-mutating boundary; nothing deployed.**
### What was done
- SSH + baseline inventory of server-01. Vault AppRole login from primary (172.16.16.18:8200) → read
`secret/netbird/oidc` + `secret/cloudflare/dns-api` (all values masked) → token revoke-self (204).
- OIDC discovery fetched from server-01.
### Results for the agent-testable steps
- **Step 4 (OIDC wiring, part 1 — DONE):** `.well-known/openid-configuration` returns `issuer=
https://auth.reverseproxyserver.net` (HTTPS — the XFP fix holds). Endpoints present: authorization,
token, userinfo, jwks, **device_authorization**. `grant_types_supported` includes `authorization_code`
and `urn:ietf:params:oauth:grant-type:device_code`; `code_challenge_methods=[S256]`. Vault OIDC secret
carries client_id/client_secret/issuer, `token_endpoint_auth_method=client_secret_post`, scopes.
→ Authelia IdP side is wired and already advertises device-flow.
- **Step 4 part 2 (dashboard config.json): NOT done** — needs the stack up.
- **Step 2 (DNS-01 cert): NOT done** — would write `_acme-challenge` TXT to the **production**
reverseproxyserver.net zone. Held for owner-in-the-loop (see discrepancy below). CF token verified present
in Vault (scope Zone:DNS:Edit, zone_id captured).
- **Step 5 (peer enrollment + relay-transport): BLOCKED** — requires root WireGuard on the host (netbird
client install + wg interface + firewall block to force relay). That is a privileged sudo mutation needing
sudo-bridge announce-first, which a non-interactive background agent cannot obtain. `relay_transport`,
`relay_is_cloudflare`, `coturn_needed` therefore UNDETERMINED.
### device-flow + coturn verdicts
- **device-flow:** IdP-supported (endpoint + grant advertised); end-to-end still owner-to-verify against a
live sandbox. Setup-keys remain the guaranteed fallback.
- **coturn:** undetermined — the relay test that would decide it did not run.
### ⚠️ Baseline discrepancy (owner must resolve before N1 re-runs)
Prompt/runbook §4.7 assume server-01 ends as "Ollama/GPU + Obsidian only." **Actual** running set on
2026-09-18: `hermes, jenkins, n8n-prod, n8n-sandbox, vault-sandbox (unhealthy), bitwarden-bridge-sandbox,
agent-sudo`; plus `sudo-bridge` (Created) and exited `coolify-proxy/coolify-sentinel/postgres-sandbox/
ollama`. Ollama present but stopped; RTX 2060 Super GPU present; no Obsidian container; ports 80/443/33073/
10000 free. The teardown success-criterion is unsatisfiable as written, and the host is shared with
prod-ish services (n8n-prod, hermes, jenkins) — deploying a WireGuard/management overlay here is not the
zero-risk single-host sandbox the runbook pictured.
### Next step
Owner to: (1) record the TRUE current container set as the teardown/restore baseline (or move the sandbox
to a genuinely clean host); (2) authorize the production DNS-01 challenge for the sandbox cert; (3) sanction
a path for the root-WireGuard peer/relay test — either sudo-bridge allowlist entries for `netbird`/`wg`/
firewall-block, or a fully containerized two-peer NET_ADMIN design. Then re-run to deploy + capture
`relay_transport`. Cross-NAT DIRECT streaming stays an N2 item (a single host cannot represent it).