Skip to content

docs(roadmap): smaug is built and the pool is not - #487

Merged
Gerrrt merged 1 commit into
mainfrom
gerrrt/smaug-issues-milestones-41e256
Sep 17, 2026
Merged

Gerrrt merged 1 commit into
mainfrom
gerrrt/smaug-issues-milestones-41e256

Conversation

@Gerrrt

@Gerrrt Gerrrt commented Sep 17, 2026

Copy link
Copy Markdown
Owner

c938c37"smaug is placed, addressed and reachable on named ports" — edited
README.md, architecture.md, hardware.md, network.md, security.md and
build-the-nas.md. It did not edit roadmap.md, and neither did the three PRs
before it. So this file has spent two days describing a box in a van.

Its own header warns about this: "two places holding the same checkbox is how a
checkbox stops being true, and this file has already been wrong about the switch
answering SNMP and about the history purge."
This is the third time.

Three passages

The #95 paragraph said "Nothing is configured". Since 2026-09-16 the BIOS
is flashed, AMT is unprovisioned, the boot disk is fitted and SMART-baselined,
TrueNAS 25.10 is installed, the static and the Kea reservation are set, and the
inbound rules are created and verified. It now agrees with
architecture.md:193: the host is built and the pool is not.

Its firewall sentences were the part most likely to mislead. They described
ADR-0016's three rules as written-down-and-uncreated, which stopped being true
on 2026-09-16:

Said Says
"50→40 is not a rule to add" "not simply a rule to add" — the ordering warning was right, and position was checked with pfctl on morpheus rather than in the web UI, where an appended rule looks present while matching nothing
three rules, deliberately not created four created, because the Hicks pass is split rather than carrying a port list
Hicks on 22 (ADR-0016's table) Hicks on 443 — that port assumed a box administered over SSH, which was an OS decision sitting inside a firewall table. Port 22 survives on the Winterfell rule and is inert: TrueNAS ships SSH disabled
node_exporter scraped left open on purpose and pointed at #256 — TrueNAS has its own endpoint, and that answer costs a fifth rule

The reversal's cost is also widened from logs to logs, SMART and patch state,
which all ride the same push this host cannot make (#255, #483).

The PBS paragraph said the deferral's trigger had moved from a purchase to a
build. It had — and then the build happened. ADR-0027's trigger is the NAS
answering on 10.0.40.30, and it has since 2026-09-16. The blocker has not
cleared (there is no pool), and the sync job was designed against a Linux host
rather than TrueNAS, so the re-read is pointed at #485 rather than left to be
rediscovered.

One more found while in there

The arrival paragraph still listed serials, POST specs and SMART as owed.
They were read on 2026-09-15 and 2026-09-16. trinity's 512 GB SSD is an M.2
stick, so there is no 2.5" carrier and the second M.2 slot is free for the I226
card — which is the thing that sentence was actually worried about (#404).

Verification

make lint        PASS  (yamllint, markdownlint-cli2, shellcheck, actionlint, editorconfig-checker)
make check-docs  docs OK — 82 Prometheus + 18 Loki rules, 7 dashboards, 141 panels, 10 assertions

No behaviour, no config, no purchase — the buy-list table is untouched, and
nothing here implies one.

Closes #486

🤖 Generated with Claude Code

c938c37 edited README.md, architecture.md, hardware.md, network.md, security.md
and build-the-nas.md when the host came up. It did not edit roadmap.md, and nor
did the three PRs before it, so this file has spent two days describing a box in
a van. The header warns about exactly this — "two places holding the same
checkbox is how a checkbox stops being true, and this file has already been
wrong about the switch answering SNMP and about the history purge" — so this is
the third time rather than the first.

Three passages, and the file's habit of naming what it used to say is kept
rather than smoothed over.

The #95 paragraph said "Nothing is configured". Since 2026-09-16 the BIOS is
flashed, AMT is unprovisioned, the boot disk is fitted and SMART-baselined,
TrueNAS is installed, the static and the reservation are set, and the inbound
rules are created and verified. It now says what architecture.md:193 already
said: the host is built and the pool is not.

Its firewall sentences were the part most likely to mislead. "50→40 is not a
rule to add" was a warning about ordering, and the warning was right — so it
now says "not simply a rule to add" and records that position was checked with
pfctl on morpheus rather than in the web UI, where an appended rule looks
present while matching nothing. Three written-down-and-uncreated rules become
four created ones, with the reason there are four (the Hicks pass is split
rather than carrying a port list) and the reason one port changed (443, not the
22 ADR-0016's table names, which assumed a box administered over SSH). Port 22
survives on the Winterfell rule and is inert, because TrueNAS ships SSH
disabled. The scrape target is left open on purpose and pointed at #256, since
node_exporter against TrueNAS's own endpoint is a choice that costs a fifth
rule if it goes the second way.

The reversal's cost is widened from logs to logs, SMART and patch state, which
all ride the same push this host cannot make — #255 and #483.

The PBS paragraph said the deferral's trigger had moved from a purchase to a
build. It had, and then the build happened: ADR-0027's own trigger is the NAS
answering on 10.0.40.30, and it has since 2026-09-16. The blocker has not
cleared — there is no pool — and the sync job was designed against a Linux host
rather than TrueNAS, so the re-read is pointed at #485 rather than left to be
rediscovered.

And the arrival paragraph still listed serials, POST specs and SMART as owed.
They were read on 2026-09-15 and 2026-09-16. trinity's 512 GB SSD is an M.2
stick, so there is no 2.5" carrier and the second M.2 slot is free for the I226
card — which was the thing that sentence was actually worried about (#404).

make lint and make check-docs both pass.

Closes #486

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Gerrrt
Gerrrt merged commit 2f708cc into main Sep 17, 2026
3 checks passed
@Gerrrt
Gerrrt deleted the gerrrt/smaug-issues-milestones-41e256 branch September 17, 2026 02:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs/roadmap.md still says smaug is unconfigured and its firewall rules unwritten

1 participant