Just after midnight I started full package upgrades across the Proxmox cluster, one node at a time.
Twenty-three minutes with no network
pve02 and pve03 went first. Each got a detached apt full-upgrade of about 114 packages including a kernel bump, then a reboot, one node at a time so the cluster kept quorum. The HA-managed guests got set to ignored first, because they're on local storage and the cluster's migrate policy would otherwise try to move them, then set back to started once each node was up. pve02 came back inside 90 seconds and pve03 inside 66. pve02 needed one manual fix. The kernel headers had landed in a separate apt run from the kernel itself, so the DKMS build for its network driver got skipped, and the driver had to be rebuilt by hand once the mismatch showed up.
pve01 got its packages staged the same way with no reboot yet. I waited for the nightly backup job to clear on all three nodes, then gave the go-ahead a little after half past two. The new kernel came up fine and the network didn't. Both halves of the node's bond were missing: the onboard NIC showed no link light and stayed that way, and the kernel hadn't detected the USB network adapter that backs it up at all. The node sat off the LAN for 23 minutes until the USB adapter finally enumerated and the bond came back over it. Quorum held the whole time, because the cluster's heartbeat runs over its own separate link, not the LAN bond, so nothing fenced. Two services crash-looped in the gap, a metrics exporter and one that fetches its own secrets at startup, and both came back with a restart. I still don't know whether the adapter's late appearance was a loose connector or just a slow boot.
Around four in the morning a Discord alert said the nightly update job had skipped itself: 30 packages pending, and the script that judges them had returned nothing usable. I noted it and left it for another day.
A cabling standard with nothing invented
In the morning I dropped in a licensed PDF of a cabling-administration standard and asked for it to go to the two other AI CLIs I have installed, to split into per-section Markdown files. Neither result held up. One paraphrased its way into a measurement that isn't in the source, and the other garbled the text extraction and filed sections in the wrong places. Both got thrown out.
What worked was Claude's own agents doing the conversion, then three rounds of review and edits until all 114 pages checked out, verified against the source in both directions so nothing was dropped and nothing was added. After midnight that verified copy became a skill, so a photo of a rack, a patch panel or a label can be checked against the actual standard. It's also on hand for future cabling design work.
Building a source of truth, one rack at a time
Most of the day went to NetBox. Early in the morning I asked which node could host it, and it went on pve02 as an unprivileged container: Postgres, Redis and gunicorn, self-signed HTTPS added after the first plain-HTTP build, credentials pushed in from the password manager instead of typed anywhere, and a monitor on the uptime dashboard. I had the plaintext fallback in the secrets script removed, since the password manager is the only place secrets come from here. The official docs got mirrored locally and turned into their own lookup skill too.
My own rack went in first: two patch panels, the switch above them and the three cluster nodes below, worked out port by port from photos with the network skill checking the wiring, and each node's backup network link recorded as its own cable. After that the hotel client's rack elevations went in the same way, followed by audit passes that checked the import against what I'd asked for and fixed what didn't match. That ran three rounds before I stopped it with "this being the final run is enough."
New names for the hotel job
In the evening I asked for a list of Greek mythological names to use as project codenames, and got around sixty back, sorted by what kind of project each would suit. The hotel job needed its own set, because its buildings had been sitting under a placeholder scheme that had to go before more of this landed in documents. The first choice for the client didn't last: it was too easy to mistype. The replacement gave every building a name from the same family. One of those names was already taken in NetBox by another client, so it needed a second pick, and near the end of the day another building got renamed because it read too close to the name picked for a shared function space. I also settled that the client doesn't get named anywhere public, under any name.
Two smaller threads
Just after midnight, before the upgrades, a short session looked at how to document a network for the hotel job in a spreadsheet alongside NetBox. It researched ten methods and cut them to three, covering device inventory, cable mapping, address blocks and resource tracking. The sheet itself isn't built yet.
Late in the evening I asked about buying a cheap managed switch that could copy the main IPTV switch's config for every server room the system touches. The answer was that I don't need one. The heavier config only matters where the multicast source sits. Downstream switches need IGMP snooping and a rule to drop unregistered multicast, so a later move to multicast delivery doesn't mean replacing anything. The enterprise switches already in those rooms can carry that on a dedicated VLAN over the same uplinks as the venue's own network, as long as only one point on that VLAN acts as the multicast querier.