# Quick pickup (last updated 2026-08-25) Read this first. `AGENT.md` has the full history/design rationale if you need depth on any specific decision below. ## What this project is Two things, in one working tree: 1. `~/code/experiments/hpe/` (this dir) -- a Python reference implementation (`extractors/`, `actions/`) for scraping/writing an HP ProCurve/OfficeConnect 1810 (J9450A) switch's web UI at `192.168.2.10`, no password. 2. `~/code/experiments/hpe/terraform-provider-hpe1810/` -- the **real deliverable**: a Go/OpenTofu Terraform Plugin Framework provider that does the same thing properly. Example usage lives in `~/code/experiments/hpe/terraform/`. The Python side is essentially done and frozen as a reference; almost all active work now is in the Go provider. ## Current state (2026-08-25) Provider builds clean. `tofu plan` in `~/code/experiments/hpe/terraform/` shows **zero drift** -- state matches the real switch exactly. **13 data sources** (all read-only pages) -- done. **10 write resources** -- all built, all verified live on real hardware: `hpe1810_locator`, `hpe1810_green_features`, `hpe1810_port` (for_each over `var.ports`), `hpe1810_system_description`, `hpe1810_time_zone`, `hpe1810_lldp_configuration` (Global Mode only), `hpe1810_daylight_saving_time` (Disable/Recurring only), `hpe1810_flow_control`, `hpe1810_port_mirroring` (global settings only), `hpe1810_trunk` (create/delete LAGs + membership). Plus: `save_running_config` provider flag (only saves to flash if something actually changed this run) and `admin_port` provider flag (default **24** -- `hpe1810_port` and `hpe1810_trunk` both hard-refuse to write to it, guard verified live). ## Still on TODO.md as wanted ("y") but not built Loop Protection Cfg (`LoopProtectionCfg.html`), Advanced Security (`security.html`), Secure Connection (`SSLCfg.html`), LLDP Local/Remote Device (read-only summary pages). Check `TODO.md`'s "Want it?" column before picking a next target -- don't assume the risk triage in `AGENT.md` is the same as what's actually wanted (learned this the hard way once already this session). Also explicitly deferred (not on the TODO list, just noted as future work if ever wanted): per-port tables on `LLDPConfig.html` (Interface Mode) and `FDBConfig.html` (per-source-port Direction) -- same complexity class as `resource_port.go`/`resource_trunk.go`. ## Things to remember before touching the switch again - **Proxy**: always `NO_PROXY=192.168.2.10 no_proxy=192.168.2.10` before any curl/tofu command, or requests silently go through `fproxy.tutus.se:8080` and hang/502. - **Single session limit**: the switch allows exactly one active web session. A stray browser tab or leftover curl cookie jar session will lock out the next login. The Go provider logs itself out at process exit (`Client.Logout()` via `Shutdown()` in `main.go`) so back-to-back `tofu` runs are fine now -- but manual curl testing sessions (like `/tmp/*.txt` cookie jars used during dev) need an explicit `curl ".../index.html?logout=1"` when you're done, or wait out the ~5 min timeout. - **Rebuild after any Go change**: `cd terraform-provider-hpe1810 && go build -o terraform-provider-hpe1810 .` -- `~/.tofurc` dev_overrides picks it up automatically, no `tofu init` needed/possible. - **Port 24 is the only real uplink right now.** Never write to it directly; the `admin_port` guard covers `hpe1810_port`/`hpe1810_trunk`, but there's no such guard on any other resource (nor should there need to be, since nothing else targets a specific interface). - This firmware has repeatedly needed **live experimentation** to find the real write protocol -- static HTML snapshots in `page_snapshots/` are useful for structure but have been wrong or incomplete more than once (`FILTER_MISSING` on omitted hidden fields; `TrunkMembership.html`'s real form is JS-rendered, not in the static HTML at all; DST's duplicate field labels). Budget time for a probe-with-curl step before writing Go for any new write target. ## How to pick up 1. Ask the user (or check `TODO.md`) what's next. 2. If it's a new write page: fetch it live with curl (logged in via the pattern used throughout this session -- GET `/` then POST `/hp_login.html` with empty `pwd`), check `page_snapshots/.html.html` for structure, but verify writes live with curl before writing any Go. 3. Follow the established resource shape: `client/.go` (or a new method on `client.Client`) for the HTTP protocol, `resource_.go` for the Terraform side, register in `provider.go`'s `Resources()`, add example usage to `~/code/experiments/hpe/terraform/main.tf`, verify live (Create/Update/Delete round-trip confirmed against the real switch, not just "no error"), update `TODO.md` and `AGENT.md`.