Eric Li DevOps & Infrastructure

The Manual That Invented Itself

Homelab · 2026-09-25 · Friday · 11:48 PM · 6 min read · 78% AI · Eric Li

The morning started with the Elgato Stream Deck's official MCP server, which only runs locally on Windows or macOS through the Stream Deck app. My first plan was to run Claude directly on the PC. That's backwards for how I work: my Claude workspace is the server container I connect to from anywhere, so the design became a reverse SSH tunnel from the PC into the server. Nothing's built yet. Separately, reaching the hotel's IPTV admin pages from home over Tailscale worked once the connection stopped routing through a DERP relay and went direct after a tailscale ping. It was slow at first but never broken.

Hermus's rack was never fibre

Photos of Hermus's rack, taken the night before, got analysed and produced a wrong picture: a fibre run into an isolated 8-room building, a media converter, a candidate SFP purchase. On site, all of that fell apart. There's no fibre into that rack. The uplink is a brown copper Ethernet cable, landing at roughly port 22 on a confirmed UniFi Enterprise switch and running maybe 30 to 40 metres back to the main rack by my own estimate, well inside copper Ethernet's 100-metre limit. The Hermus outdoor ports feed outdoor Wi-Fi APs and don't make a second building link. I cancelled the SFP purchase, dropped the fibre-based layout, and settled on a direct copper run. Every doc that had the fibre story got corrected in place, with the wrong inference left visible and marked.

The other end of that copper cable got settled the same day, during a live trace of the hotel's main equipment rack. It took about half an hour and covered the rack itself and the links running out to the two smaller ones. Most of its local switch feeds Wi-Fi access points around the building, one port per AP, with only a couple of ports doing anything else. Behind it are several patch panels, each covering a different slice of the hotel. Some are patched straight through to one of the two core switches, some are cross-connected panel to panel, and one bank looks like phone lines rather than data, though that's still a guess.

One full panel answered a question that had been open since the site survey began. It's Strymon's in-room TV wiring, home-run all the way back to the main rack instead of ending in Strymon's own rack as I'd assumed, and it lands on a core switch there. Hermus's uplink resolved the same way: the patch-panel port labelled for Hermus lands on one of the two core switches, which says where that brown copper cable from Hermus's rack goes. It's a label match only, not yet confirmed with a toner or a link light, so it's still a lead. The two core switches are joined by a single link, and the building's firewall connects to both, more to one than the other. The hotel switch in the third rack is still untraced until I photograph its ports. Later that night the whole trace went into a spreadsheet with a cable schedule, a sheet per switch and patch panel, the rack elevation, and a tab of open questions for the next visit.

A login that wasn't a login

I'd found that the SSH path already used for the IPTV switch, through the on-site travel router, also reaches the headend server's web admin and its SSH port from the lab. I created a login in the password manager and scoped a narrow permission to a single wrapper script for it. The SSH attempt got refused anyway. The account existed only in the web admin, and a web-app login isn't a Linux login, which also explains why earlier guesses never worked. The vendor made the same point later in writing when they refused shell access outright: it's for their own developers.

By evening the Dolby audio problem on the HD channels was sorted anyway, through the settings PIN and HDMI passthrough. Three bench set-top boxes also got baselined over adb, with time zone and locale confirmed to survive a reboot.

Two rounds with the vendor

The vendor answered the questions I'd sent the night before. The HD channels lose sound because the set-top box chip can't decode Dolby AC-3, and fixing it server-side needs an extra AC3-to-AAC converter box. No setting does it. The other answer was worse: the STB settings PIN is the same across their entire fleet and can't be changed from the server. That's a guest-tampering risk worth raising before handover.

A second round went out the same day. On HDMI passthrough they said to try the box settings, since they're on a Chinese holiday. SSH came back refused. For backups they offered to annotate screenshots, until I found the admin UI already has a backup button that downloads a config file straight to the PC. Delivery mode was the sharper answer: the system runs all-HLS or all-UDP with no mix, so testing multicast on site means switching the whole system over, not one channel. I decided to hold the invoice's support and warranty terms in reserve instead of raising them now, as leverage if things stall later. Along the way I learned that multicast is UDP or RTP sent to a group address, while HLS, RTMP, and SRT are different delivery methods entirely.

The manual had a step nobody wrote

The main event of the afternoon was catching a mistake in our own documentation, and the vendor had nothing to do with it. Claude cited the vendor manual as saying installers log in to the server's OS as part of a setup procedure. I checked the actual manual and it says nothing of the kind. Our transcription of that section had invented a nine-step procedure that isn't in the source anywhere.

That triggered a full re-verification. Every section of the manual was pulled fresh from the vendor's live content API and checked line by line against what we'd written down. A few smaller inventions turned up in the same pass, including video durations that had been read off a PDF player and never confirmed in the source. All of it got fixed. The pass also produced a project-scoped skill that makes the verified manual the first thing checked for any IPTV procedure question, with a hard rule attached: cite a section number, or say the answer isn't documented.

The vendor messages had gone out without a humanizer pass, so I added a vault-wide rule that anything written for someone other than me runs through that skill first.