rdmsm4x-changelog-20260916-1355-restart-prep-and-udm-credential-restore
Prepared rdmsm4x for restart: re-measured all DNS/UDM state from the 09-14/09-15 work, restored a UDM credential that a secrets consolidation had broken, and published a restart-ready SESSION-STATE.md.
- When: 2026-09-16 13:42 – 13:55 EDT
- Scope:
~/.secrets/global.env(one value restored),net/fleet-netmgmtdocs; everything else read-only - Tickets: ISSUE-20260916-17 opened (secrets consolidation defect); SEC-20260915-02 still open (credential rotation)
Changes
- Restored
FLEET_UNIFI_ROOT_PASSWORDin~/.secrets/global.env. The 2026-09-15 20:13 consolidation replaced it (12 → 14 chars) with a value that does not authenticate to the UDM; the archived 12-char value does. Backup of the broken state:~/.secrets/global.env.bak-claude-20260916-1350. No secret value was printed. net/fleet-netmgmt: findings § 2026-09-16 and a rewritten SESSION-STATE.md answering the six continuity questions, incl. a RESUME AFTER RESTART checklist (commits b4d5f04, f0cd65a).
Verification (all re-measured today)
- Cloudflare zone: 39 records, no drift since 09-15 18:42 apart from my own udm/gw change.
- UDM:
direct_connect_enabled: falsepersisted; 13 dnsmasq host-records; LANhttps://192.168.1.1= 200. starlink18a.dataroo.netresolves to 100.103.136.116 via the UDM resolver and DoH.- Restored credential verified by authenticating with it from
global.env. - Tunnel
dataroo-homelab-tunnel: read as "down, 0 conns" at ~13:50, then healthy with 4 connections at 13:52. cloudflared logged a QUICno recent network activitydrop and reconnected on its own. All 12 containersUp 47 hours— nothing had restarted.
Restart risk to know
udm/gw.dataroo.net now reach the UDM
only through cloudflared on rdmsm4x, and the WAN path
is closed. Containers are restart: unless-stopped under
OrbStack, a GUI app — a Mac sitting at the login window starts none of
them. After a reboot, log in at the console on rdmsm4x, then run the §4
checklist in SESSION-STATE.md. Fallbacks: LAN
https://192.168.1.1 (verified); tailnet via 18a-rdpi5b's
192.168.0.0/23 (unverified today — no off-LAN vantage was
reachable); last resort, re-enable Direct Remote Access from the
LAN.
Owner actions (Rich)
- ISSUE-20260916-17: confirm where the 14-char UDM
value came from, whether other hosts received it, and whether the 85 →
22 key split of
global.env(63 keys moved to~/.secrets/scavenged-20260915.env, none lost) is intended. Scripts sourcingglobal.envfor those 63 keys will miss them. - SEC-20260915-02: rotate the UDM device SSH password and API token exposed on 09-15.
- Confirm UniFi mobile / ui.com remote access over UI relay.
Portable runbook
The post-restart checklist is also published as a private page, because the wiki and dashboards that normally carry this run on rdmsm4x and are down exactly when it is needed: https://claude.ai/artifact/VowEBzmbMLf9ncbKKQfUAc