Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260926-0033-fleet-infra-fixes

rdmsm4x - changelog - fleet infra dns and orbstack fixes - claude - infraworker - fleet - 20260926-0033

Session: 2026-09-26 00:20:36 EDT to 00:33:23 EDT Ran on: rdmsm4x · Changed state on: rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m

Restored a drifted Tailscale DNS setting on four hosts (bare hostnames were resolving to tailnet IPs instead of LAN IPs, on the LAN) and fixed OrbStack auto-start on jdmbair13m5. Full report: /Users/richh/dev/_ops/reports/fleet-infra-20260926.md.

Scope

Hosts touched: rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m (Tailscale accept-dns) and jdmbair13m5 (OrbStack). rdmpw3265m was already correct, left alone. rdmbair13m5 is offline (physical/power issue, out of remote reach) and was not touched. GitHub repo audit and Xcode/CLT audit performed fleet-wide, read-only, no changes needed there.

Files created

Path What
/Users/richh/dev/_ops/reports/fleet-infra-20260926.md Full audit report (DNS, GitHub, Xcode, OrbStack)
/Users/richh/dev/_ops/reports/tailscale-prefs-backup-20260926/* Pre-change tailscale debug prefs backups, 4 hosts

Files modified

Commands run

# on each of rdmsm4x, rdmbair15m5, jdmbair13m5, rdmpw3275m:
tailscale debug prefs > <backup file>
sudo -n tailscale set --accept-dns=false
tailscale debug prefs | grep -i corpdns   # verify -> false
dscacheutil -flushcache; killall -HUP mDNSResponder
dig +short <hostname>                     # verify -> LAN IP, not tailnet IP

# on jdmbair13m5 only:
orb config get app.start_at_login          # was false
orb config set app.start_at_login true
orb start
orb status                                 # -> Running

Verification performed

How to undo

# Tailscale (per host, if MagicDNS convenience is ever wanted back):
sudo -n tailscale set --accept-dns=true

# OrbStack on jdmbair13m5:
orb config set app.start_at_login false
orb stop

Secrets

None written. No credential values referenced or displayed. tailscale debug prefs backups contain only zeroed-out placeholder key fields (privkey:0000..., nlpriv:0000...) by the tool's own design, plus a public Google profile-picture URL — no secrets.

Outstanding owner actions

  1. rdmbair13m5 is physically offline (~4h per the parallel EPIC-20260926-01 session) — needs eyes-on / physical check (power, sleep, disconnected). Once back, check its Tailscale accept-dns and OrbStack state for the same drift found on its four siblings.
  2. Root cause of the accept-dns drift (something re-running tailscale up without --accept-dns=false fleet-wide) was not tracked down — worth a ticket so it doesn't recur.
  3. Ollama on the two Intel hosts (rdmpw3265m, rdmpw3275m) is a pending baseline decision, flagged by the parallel session, not actioned here.