docs(netbird): N1 sandbox handoff — §7(cont.) partial run, baseline+privilege findings (#258)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -143,3 +143,51 @@ deferred systemd timer registrations (Twingate connector self-heal + NetBird rel
|
||||
## Update instructions
|
||||
Fill in sandbox results for steps 2, 4, 6; mark buildplan items (b)/(c) RESOLVED; then spin §3–§5 into
|
||||
`playbook_netbird_phases.md` and start the build on server-01.
|
||||
|
||||
---
|
||||
|
||||
## 7 (cont.) — N1 sandbox handoff (2026-09-18, background agent)
|
||||
|
||||
**Status: partially_succeeded — stopped at the privileged / production-mutating boundary; nothing deployed.**
|
||||
|
||||
### What was done
|
||||
- SSH + baseline inventory of server-01. Vault AppRole login from primary (172.16.16.18:8200) → read
|
||||
`secret/netbird/oidc` + `secret/cloudflare/dns-api` (all values masked) → token revoke-self (204).
|
||||
- OIDC discovery fetched from server-01.
|
||||
|
||||
### Results for the agent-testable steps
|
||||
- **Step 4 (OIDC wiring, part 1 — DONE):** `.well-known/openid-configuration` returns `issuer=
|
||||
https://auth.reverseproxyserver.net` (HTTPS — the XFP fix holds). Endpoints present: authorization,
|
||||
token, userinfo, jwks, **device_authorization**. `grant_types_supported` includes `authorization_code`
|
||||
and `urn:ietf:params:oauth:grant-type:device_code`; `code_challenge_methods=[S256]`. Vault OIDC secret
|
||||
carries client_id/client_secret/issuer, `token_endpoint_auth_method=client_secret_post`, scopes.
|
||||
→ Authelia IdP side is wired and already advertises device-flow.
|
||||
- **Step 4 part 2 (dashboard config.json): NOT done** — needs the stack up.
|
||||
- **Step 2 (DNS-01 cert): NOT done** — would write `_acme-challenge` TXT to the **production**
|
||||
reverseproxyserver.net zone. Held for owner-in-the-loop (see discrepancy below). CF token verified present
|
||||
in Vault (scope Zone:DNS:Edit, zone_id captured).
|
||||
- **Step 5 (peer enrollment + relay-transport): BLOCKED** — requires root WireGuard on the host (netbird
|
||||
client install + wg interface + firewall block to force relay). That is a privileged sudo mutation needing
|
||||
sudo-bridge announce-first, which a non-interactive background agent cannot obtain. `relay_transport`,
|
||||
`relay_is_cloudflare`, `coturn_needed` therefore UNDETERMINED.
|
||||
|
||||
### device-flow + coturn verdicts
|
||||
- **device-flow:** IdP-supported (endpoint + grant advertised); end-to-end still owner-to-verify against a
|
||||
live sandbox. Setup-keys remain the guaranteed fallback.
|
||||
- **coturn:** undetermined — the relay test that would decide it did not run.
|
||||
|
||||
### ⚠️ Baseline discrepancy (owner must resolve before N1 re-runs)
|
||||
Prompt/runbook §4.7 assume server-01 ends as "Ollama/GPU + Obsidian only." **Actual** running set on
|
||||
2026-09-18: `hermes, jenkins, n8n-prod, n8n-sandbox, vault-sandbox (unhealthy), bitwarden-bridge-sandbox,
|
||||
agent-sudo`; plus `sudo-bridge` (Created) and exited `coolify-proxy/coolify-sentinel/postgres-sandbox/
|
||||
ollama`. Ollama present but stopped; RTX 2060 Super GPU present; no Obsidian container; ports 80/443/33073/
|
||||
10000 free. The teardown success-criterion is unsatisfiable as written, and the host is shared with
|
||||
prod-ish services (n8n-prod, hermes, jenkins) — deploying a WireGuard/management overlay here is not the
|
||||
zero-risk single-host sandbox the runbook pictured.
|
||||
|
||||
### Next step
|
||||
Owner to: (1) record the TRUE current container set as the teardown/restore baseline (or move the sandbox
|
||||
to a genuinely clean host); (2) authorize the production DNS-01 challenge for the sandbox cert; (3) sanction
|
||||
a path for the root-WireGuard peer/relay test — either sudo-bridge allowlist entries for `netbird`/`wg`/
|
||||
firewall-block, or a fully containerized two-peer NET_ADMIN design. Then re-run to deploy + capture
|
||||
`relay_transport`. Cross-NAT DIRECT streaming stays an N2 item (a single host cannot represent it).
|
||||
|
||||
Reference in New Issue
Block a user