Devices and sites
Devices and sites
Publishing…Source of truth: mikrotik-dashboard/inventory.json. REST is allow-listed to hp02. Addresses below are the management IPs the dashboard uses (vlan89 10.9.8.x first).
L3 routers
10.9.8.252
RSTP root of production (0x1000). OSPF RID 10.255.255.16.
Standby
core-sb (CHR on hp02)
10.9.8.251
VRRP backup, OSPF vlan34/36.
Primary WAN
CCR2004 Quickline
10.9.8.200
OSPF vlan33 cost 10 + BFD. WAN on CRS317.
Backup WAN
CCR2004 Wingo
10.9.8.216
OSPF vlan32 cost 20 + BFD.
Mgmt island
CCR2004-16G-2S+
10.9.8.1
vlan89 gateway, own WAN, WireGuard 10.9.9.1.
Switch fabric
10.9.8.212
vlan448 island root
Spine
CRS326-24S+2Q+_A
10.9.8.205
production 0x2000
Access-core
CRS326-24S+2Q+_C
10.9.8.213
production 0x3000; servers, UniFi, garage, core-sb trunk
Copper access
CRS326-24G-2S+
10.9.8.249
vlan50 / vlan62 / vlan59
Desk
CRS310-8G+2S+
10.9.8.203
work / IoT / brother
PoE (vlan448 + OOB)
CRS418-8P-8G-2S+
10.9.8.204
access
Mgmt fabric
CRS309-1G-8S+
10.9.8.210
vlan89 star
Mgmt PoE
CRS328-24P-4S+
10.9.8.232
hp02 mgmt, iLO, NanoKVM, hex-ci
Mgmt leaf
CRS305-1G-4S+
10.9.8.202
vlan89
Servers and DNS
172.16.62.253 vlan62, 10.9.8.253 vlan89
Dashboard :8787, Gitea :3030, CHR labs, syslog, backups. Only host allowed to hit RouterOS REST. iLO 10.9.8.218.
hp04
172.16.62.40 vlan62 and 213.221.211.30/28 public
Workspace + CI runners. Cannot reach vlan89. Must not forward public ↔ LAN. iLO 10.9.8.224.
mag01
172.16.62.246
CI lab runner (lab label).
apu01
10.9.8.206 / 192.168.53.3 / wg0 172.16.75.1
Unbound + FRR. SSH bodo. DNS APUs.
apu02
10.9.8.207 / 192.168.53.2
Same without wg-home.
NanoKVM
10.9.8.225 / .229 / .230
OOB console.
CPE and lab hardware
172.16.99.69
Trunk vlan58/59/99 to CRS326-C sfp14. ether2 = Luxtronik. REST from hp02's vlan62 address (no vlan89 route).
Luxtronik
172.16.58.10
Isolated on vlan58. Path attested on /pathproof.
hex-ci
10.9.8.240
Physical hEX lab on vlan89. Agents may reconfigure it. Dual uplink into CRS328, RSTP blocks one. Rescue 192.168.88.1.
hex-ci2
10.9.8.241
Same pattern, CRS328 ether7/8.
Lab networks on chrlab/fwlab stay in 198.18.0.0/15 (and the other documentation prefixes). Never put a lab bridge on 10.9.8.0/24, 172.16.0.0/12, 192.168.53.0/24, or 100.64.0.0/10.
Remote sites
Reached from hp02's production NIC, not vlan89.
172.16.52.1
Quickline WG / EoIP; prefixes also via apu01 OSPF
hex_19
172.16.18.1
Same
hex_81
213.221.211.19
On the vlan448 public segment
/sites is the live tunnel view (peers, last handshake). A leftover NEVER peer is a display bug, not a down site.
Operator surfaces
/apu
Anycast probes; metrics over SSH after HOST-APU-01
Gitea
http://172.16.62.253:3030/bodo/mikrotik-dashboard
Issues, PRs, CI
Grafana APUs
http://10.9.8.206:3000/ · http://10.9.8.207:3000/
vlan89 only
Related books
Rules that do not change because a page exists
Agents never write production routers. Deliverable is a dry-run script plus a one-liner for bodo. hp02 is the jump host. This book is the picture, not a change ticket.