T10: floating-IP + Hetzner role (guest /32, v6 bootstrap, known_hosts)
closedParent: bug 75966cc (cell architecture tracking). Small but fiddly; pairs with T2/T4 work.
Goal
Ansible role owning the Hetzner floating-IP lifecycle on cell hosts.
Scope
- Guest-side persistent
/32floating-IP config (netplan/NetworkManager) baked by the role; primary IP/IPv6 retained for provisioning + Ansible. - Bootstrap path over IPv6 (firewall + sshd), then attach floating IP;
known_hostshandling for rebuilt hosts (changed keys). - Move procedure hook (hcloud API/CLI with token, unassign-old before assign-new — API enforces single attachment), fenced by T9 runbook order.
Acceptance
- Fresh cell provisions over primary/IPv6, converges, survives a rehearsed floating-IP move with no DNS change and relay-queue drain clean.
2 Comments
Scope revision (2026-09-13): network task deleted
Primary-IP recycling (see T9 revision comment on c2f7f81) removes the hetzner role’s network task entirely: primaries are configured by cloud-init at creation, there is no floating IP, no guest /32, no extra-vars plumbing.
Remaining T10 scope: SSH/v6 posture (sshd hardening snippet, UFW v6 confirmation),
~/.ssh/config-as-binding-layer documentation, known_hosts procedure (manualssh-keygen -R/ssh-keyscan; therecovery-bootstrapJustfile recipe automates the rotation pre-Ansible), and hcloud-CLI introspection notes (primary-IP resources namedmxN.<region>.sovrn.at-{4,6}, protection on, auto-delete off).OBE. Using PrimaryIPs and not FloatingIPs. Closing.