rdmsm4x - changelog - fleet infra dns and orbstack fixes - claude - infraworker - fleet - 20260926-0033
Session: 2026-09-26 00:20:36 EDT to 00:33:23 EDT
Ran on: rdmsm4x · Changed state
on: rdmsm4x, rdmbair15m5,
jdmbair13m5, rdmpw3275m
Restored a drifted Tailscale DNS setting on four hosts (bare
hostnames were resolving to tailnet IPs instead of LAN IPs, on the LAN)
and fixed OrbStack auto-start on jdmbair13m5. Full report:
/Users/richh/dev/_ops/reports/fleet-infra-20260926.md.
Scope
Hosts touched: rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m (Tailscale accept-dns) and jdmbair13m5 (OrbStack). rdmpw3265m was already correct, left alone. rdmbair13m5 is offline (physical/power issue, out of remote reach) and was not touched. GitHub repo audit and Xcode/CLT audit performed fleet-wide, read-only, no changes needed there.
Files created
| Path | What |
|---|---|
/Users/richh/dev/_ops/reports/fleet-infra-20260926.md |
Full audit report (DNS, GitHub, Xcode, OrbStack) |
/Users/richh/dev/_ops/reports/tailscale-prefs-backup-20260926/* |
Pre-change
tailscale debug prefs backups, 4 hosts |
Files modified
- Tailscale preference
CorpDNS/accept-dnson rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m — wastrue(drifted), set back tofalse. Backup: full prefs JSON in/Users/richh/dev/_ops/reports/tailscale-prefs-backup-20260926/. - OrbStack
app.start_at_loginon jdmbair13m5 — wasfalse, set totrue; also started the OrbStack app (was stopped). No backup file needed (single boolean, trivially reversible).
Commands run
# on each of rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m:
tailscale debug prefs > <backup file>
sudo -n tailscale set --accept-dns=false
tailscale debug prefs | grep -i corpdns # verify -> false
dscacheutil -flushcache; killall -HUP mDNSResponder
dig +short <hostname> # verify -> LAN IP, not tailnet IP
# on jdmbair13m5 only:
orb config get app.start_at_login # was false
orb config set app.start_at_login true
orb start
orb status # -> Running
Verification performed
- Ran on rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m:
dig +short <bare-hostname>before and after the fix. Before: resolved to each host's Tailscale IP (100.x.x.x). After: resolves to the correct 192.168.0.0/23 LAN IPv4 for every host (192.168.0.29, 192.168.1.48, 192.168.1.225, 192.168.1.65 respectively). - Confirmed the off-LAN path
(
<host>.ts.dataroo.net) is unaffected: resolved correctly via plaindigAND independently via DNS-over-HTTPS (https://cloudflare-dns.com/dns-query, which bypasses any local/UDM bias) on all 6 hosts' names — all give the correct tailnet IP. - Checked
/etc/hostson all 5 reachable hosts for a stray override — clean, no fleet entries. - jdmbair13m5 OrbStack:
orb config get app.start_at_loginreturnstrue;orb statusreturnsRunning; no containers were defined on that host so nothing else to check.
How to undo
# Tailscale (per host, if MagicDNS convenience is ever wanted back):
sudo -n tailscale set --accept-dns=true
# OrbStack on jdmbair13m5:
orb config set app.start_at_login false
orb stop
Secrets
None written. No credential values referenced or displayed.
tailscale debug prefs backups contain only zeroed-out
placeholder key fields (privkey:0000...,
nlpriv:0000...) by the tool's own design, plus a public
Google profile-picture URL — no secrets.
Outstanding owner actions
- rdmbair13m5 is physically offline (~4h per the
parallel EPIC-20260926-01 session) — needs eyes-on / physical check
(power, sleep, disconnected). Once back, check its Tailscale
accept-dnsand OrbStack state for the same drift found on its four siblings. - Root cause of the
accept-dnsdrift (something re-runningtailscale upwithout--accept-dns=falsefleet-wide) was not tracked down — worth a ticket so it doesn't recur. - Ollama on the two Intel hosts (rdmpw3265m, rdmpw3275m) is a pending baseline decision, flagged by the parallel session, not actioned here.