Network

Pages 37-39 of the Bitsmasher Lab Operations Manual (62 pages)

Network Infrastructure

Addressing Scheme

The lab uses private IPv4 addressing across multiple subnets, organized by function:

tabularx}{}{l l X}

<strong>Subnet</strong> & <strong>Allocation</strong> & <strong>Purpose</strong> \\


10.10.8.0/21 & chonk, chonk-wifi, music.lan (via skynet) & Main office / desk area\\

10.10.12.0/& time, node90x, odroid-c1, blowfish, ns1 & Core infrastructure\\

10.10.13.0/ & ldap/bbb1 & Directory services (moved to working hosts)\\

10.10.14.0/ & blowfish (reassigned) & New allocation for blowfish\\

10.10.15.0/ & femputer & Guest / temporary hosts\\

10.10.16.0/& stargate, skynet, edge-t & Lab backbone / staging

tabularx}

Note: The full subnet masks vary by role and DHCP scope configuration on the Dream Machine (DHCP server).

DHCP

The dhcp} Ansible role manages the DHCP server configuration stored at roles/dhcp/files/dhcpd.conf}. Key reserved hosts include:

DNS

The DNS infrastructure is managed by the dns} Ansible role (BIND/named). Zones maintained include:

DNS role molecule testing confirms BIND packages install correctly and named.conf.options are written. The DNS server (ns1) has been offline during recent audits, which explains why many hosts in the 10.10.x.0/24 range cannot resolve -- ns1 is a single point of failure for lab DNS resolution.

Firewall and Access Control

Physical Topology

The lab spans multiple physical locations and subnets:

Routing between the 192.168.86.x subnet (music) and the rest of the lab requires hopping through skynet due to the non-standard routing configuration.