Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1355-restart-prep-and-udm-credential-restore

rdmsm4x-changelog-20260916-1355-restart-prep-and-udm-credential-restore

Prepared rdmsm4x for restart: re-measured all DNS/UDM state from the 09-14/09-15 work, restored a UDM credential that a secrets consolidation had broken, and published a restart-ready SESSION-STATE.md.

Changes

  1. Restored FLEET_UNIFI_ROOT_PASSWORD in ~/.secrets/global.env. The 2026-09-15 20:13 consolidation replaced it (12 → 14 chars) with a value that does not authenticate to the UDM; the archived 12-char value does. Backup of the broken state: ~/.secrets/global.env.bak-claude-20260916-1350. No secret value was printed.
  2. net/fleet-netmgmt: findings § 2026-09-16 and a rewritten SESSION-STATE.md answering the six continuity questions, incl. a RESUME AFTER RESTART checklist (commits b4d5f04, f0cd65a).

Verification (all re-measured today)

Restart risk to know

udm/gw.dataroo.net now reach the UDM only through cloudflared on rdmsm4x, and the WAN path is closed. Containers are restart: unless-stopped under OrbStack, a GUI app — a Mac sitting at the login window starts none of them. After a reboot, log in at the console on rdmsm4x, then run the §4 checklist in SESSION-STATE.md. Fallbacks: LAN https://192.168.1.1 (verified); tailnet via 18a-rdpi5b's 192.168.0.0/23 (unverified today — no off-LAN vantage was reachable); last resort, re-enable Direct Remote Access from the LAN.

Owner actions (Rich)

Portable runbook

The post-restart checklist is also published as a private page, because the wiki and dashboards that normally carry this run on rdmsm4x and are down exactly when it is needed: https://claude.ai/artifact/VowEBzmbMLf9ncbKKQfUAc