rdmbair13m5-changelog-20260829-0316-codex-ssh-route-repair
Codex SSH access to the local rdmbair13m5 host now
bypasses a stale LAN record through the verified fleet tailnet name;
rdmbair15m5 recovered without configuration changes.
Scope
- Host changed:
rdmbair13m5only. - Hosts tested read-only:
rdmbair13m5andrdmbair15m5. - No UDM Beast, Cloudflare, Tailscale,
/etc/hosts, Remote Login, firewall, TCC, provider-authentication, or remote-host state was changed.
Files touched
/Users/richh/.ssh/config- Added a
Host rdmbair13m5block whoseHostNameisrdmbair13m5.ts.dataroo.netand whose user isrichh.
- Added a
/Users/richh/.ssh/config.bak-20260829-0320-codex-route- Mode-0600 pre-change backup.
/Users/richh/dev/LLM/Claude/changelogs/rdmbair13m5-changelog-20260829-0316-codex-ssh-route-repair.md- This durable record.
Diagnosis
- The local Mac is
rdmbair13m5at live LAN address192.168.0.131. /etc/hostshas a managedfleet-lan-hostsblock dated 2026-08-24 that still maps barerdmbair13m5to192.168.1.177.- The UDM Beast resolver at
192.168.1.1also returns192.168.1.177for barerdmbair13m5andrdmbair13m5.dataroo.net. - Cloudflare authoritative nameservers return the correct tailnet
address
100.75.186.59forrdmbair13m5.ts.dataroo.net. - Codex logs initially reported
SSH: codex path probe timed out after 60000msfor both Airs.rdmbair15m5subsequently connected without a configuration change. After the SSH alias was added, Codex'srdmbair13m5path and version probes succeeded via the expected host fingerprint, but the redundant self-remote then timed out bootstrapping a second app-server on the same Mac.
Commands and verification
- Resolved the actual host with
scutil --get ComputerName. - Compared live interface, macOS resolver,
/etc/hosts, UDM direct DNS, Cloudflare authoritative DNS, Tailscale status, TCP/22, SSH authentication, remote host identity, host-key fingerprints, and Codex CLI version. - Verified
rdmbair13m5.ts.dataroo.netreaches host keySHA256:E+262mKu6uY5Y2oo+zjOqlOQGAHBnOPLoEopKAnHClk. - Verified
ssh -G rdmbair13m5now reportshostname rdmbair13m5.ts.dataroo.net. - Verified
ssh -o BatchMode=yes -o ConnectTimeout=5 richh@rdmbair13m5returns remote namerdmbair13m5andcodex-cli 0.150.1. - Verified Codex's own post-change log shows the SSH config block
being applied, authentication to
100.75.186.59, and successful path/version probes. - Verified
rdmbair15m5reached Codex app stateconnectedand its remote task catalog was readable.
Backups and undo
- Backup:
/Users/richh/.ssh/config.bak-20260829-0320-codex-route. - Original SHA-256:
327f7de2d21e3d717ea9265a3e86bf5be4ede0f707f479956ce569195abd46e6. - Updated SHA-256:
aa40c2f06c414dcef0e2eba641237a09cfbe38d809a1b3ed199b03e626fbed43. - Undo by restoring the backup over
/Users/richh/.ssh/config, preserving mode 0600.
Outstanding owner actions
- Correct or remove the stale
rdmbair13m5local/DHCP host record on the UDM Beast; the current correct LAN address is192.168.0.131at observation time. - Regenerate or remove the stale
fleet-lan-hostsblock in/etc/hostsafter the UDM record is corrected. Do not replace it with another ephemeral LAN address without understanding the generator. - Remove the redundant Codex SSH-remote entry named
rdmbair13m5from this Mac if desired; this Mac should use Codex's Local host. Deletion was not performed.