Skip to content

docs: lab-node commissioning runbook + static-address amendments - #22

Merged
jmgilman merged 1 commit into
masterfrom
docs/lab-node-commissioning
Aug 22, 2026
Merged

docs: lab-node commissioning runbook + static-address amendments#22
jmgilman merged 1 commit into
masterfrom
docs/lab-node-commissioning

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Companion docs for session 009 (lab01-03 commissioned into the Incus cluster; fleet#2, networking#13, secrets#29-#33).

  • New runbook: commission a lab compute node — MEBx/AMT provisioning (TLS-only AMT 19, consent NONE), the AMI Factory Key Provision Secure Boot recipe, both MAC-harvest methods, USB install with the rescue-wipe path, fingerprint verification, recovery-key escrow + the :retrieved acknowledgment gotcha, API join payload, smoke verification. Includes the hard prohibition on AMT IDER boot (reproducibly wedges this firmware).
  • Address plan: DHCP-reservation prose corrected — IncusOS mgmt addresses are static-in-seed (MAC-bound in fleet), lab AMT addresses are static-in-MEBx (OOB must survive gw01 outages); dead AMT reservations were removed from gw01 in networking#13.

Strict docs build passes.

Session 009 brought lab01-03 online. Documents the proven procedure
(MEBx/AMT, Secure Boot Factory Key Provision recipe, MAC harvest, USB
install, escrow, API join) and amends the address plan: IncusOS node
management addresses are static-in-seed and lab AMT addresses are
static-in-MEBx, not DHCP reservations.
@jmgilman
jmgilman merged commit be663ba into master Aug 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant