The only hosts in the sandbox vlan are the RIPE Atlas anchors. Most of them VMs in the "old" Ganeti clusters, one (codfw) still a physical box.
Now that we're migrating Ganeti to routed Ganeti, we need to be able to have routed Anchors and decom the old sandbox vlan, re-using their IP spaces.
- Update prefixes in Netbox, delete old vlan
- Update Ganeti to handle the sandbox vlan - https://gerrit.wikimedia.org/r/c/operations/puppet/+/1180143
- Add the sandbox ranges to the switches prefix-list - https://gerrit.wikimedia.org/r/c/operations/homer/public/+/1180150
- Add a nftables ACL to prevent the sandbox VMs from reaching private ranges
- Re-create a RIPE Atlas VM