Record operator approval and implement P1–P4: 4G swapfile, journald vacuum, apt upgrade, and UFW lockdown of k3s API/flannel world-open rules. k3s node Ready post-change; residual risk is still tight RAM.
10 lines
730 B
Markdown
10 lines
730 B
Markdown
# Outstanding risks — eng-coulomb-railiance01-ho-001
|
|
|
|
| Risk | Severity | Mitigation / owner | Status |
|
|
|------|----------|--------------------|--------|
|
|
| RAM still 3.8G; swap heavily used (~1.9G/4G) | High | Provider RAM upgrade | open |
|
|
| Load still elevated (~6 on 2 cores) | Medium | Reduce concurrent workloads; capacity | open |
|
|
| Stale user sessions after apt upgrade | Low | Re-login SSH | open |
|
|
| UFW 6443 allowlist may miss new admin IPs | Medium | Add `ufw allow from <ip> to any port 6443 proto tcp` | open |
|
|
| 8472 closed externally | Low | Re-open if multi-node flannel peers appear | accepted (single-node) |
|
|
| fwupd.service failed restart during upgrade | Low | Investigate if firmware tooling needed | open |
|