make backup-firewall exports and encrypts morpheus's config, and
restore-the-firewall.md
documents the restore. Two things are still missing, and they are the two that
matter.
The backup is on the machine it protects
backup-firewall.sh:125-126:
This is on the same host as everything else it protects. Copy it to the backup
target and offsite.
Nothing does that copy. A backup on the same shelf as the thing it protects is
not a backup.
The runbook has never been executed
restore-the-firewall.md:168:
Until that has been done once, this runbook is a hypothesis.
Doing it needs a spare, and the spare should be the same ProDesk model:
pfSense stores interface assignments by device name, so identical hardware
restores straight through and anything else drops you into the console
interface-assignment dialogue — at exactly the moment you least want to be
answering questions.
The two halves are one purchase apart. Buying the spare unblocks the rehearsal,
and the rehearsal is what turns the runbook into something you can rely on at
1am.
Where the spare goes — #110
It racks on the 1U shelf from
#110, beside the switch, and is
left powered off.
Powered off is the point, not an omission. A spare that is plugged in and on the
network is exposed to whatever took the primary — and the primary is the device
that terminates every VLAN, so "whatever took it" is the case this spare exists
for.
It cannot go beside morpheus: that sits at U5 in a purpose-built mount holding
exactly one ProDesk Mini, which was checked at the rack rather than assumed. The
1U shelf has room for the switch and a second small box; the U5 bracket by design
does not. So the shelf is not only where the spare can live, it is the only
place in the rack it does.
Order of operations, if both are bought together: the shelf goes in first (U4 is
the one free slot), then the spare has somewhere to land.
The other half is still unowned
Racking the spare does not address the first problem above. The encrypted export
still lands on prometheus and nothing copies it anywhere — not to the spare,
not offsite. That copy needs a destination decided;
#94 ("decide what oracle is
for") and #77 ("nothing schedules
any backup") are the two it most likely wants solving with.
Tracked in docs/roadmap.md; filed as an issue so it has a place to be discussed and closed.
make backup-firewallexports and encryptsmorpheus's config, andrestore-the-firewall.mddocuments the restore. Two things are still missing, and they are the two that
matter.
The backup is on the machine it protects
backup-firewall.sh:125-126:Nothing does that copy. A backup on the same shelf as the thing it protects is
not a backup.
The runbook has never been executed
restore-the-firewall.md:168:Doing it needs a spare, and the spare should be the same ProDesk model:
pfSense stores interface assignments by device name, so identical hardware
restores straight through and anything else drops you into the console
interface-assignment dialogue — at exactly the moment you least want to be
answering questions.
The two halves are one purchase apart. Buying the spare unblocks the rehearsal,
and the rehearsal is what turns the runbook into something you can rely on at
1am.
Where the spare goes — #110
It racks on the 1U shelf from
#110, beside the switch, and is
left powered off.
Powered off is the point, not an omission. A spare that is plugged in and on the
network is exposed to whatever took the primary — and the primary is the device
that terminates every VLAN, so "whatever took it" is the case this spare exists
for.
It cannot go beside
morpheus: that sits at U5 in a purpose-built mount holdingexactly one ProDesk Mini, which was checked at the rack rather than assumed. The
1U shelf has room for the switch and a second small box; the U5 bracket by design
does not. So the shelf is not only where the spare can live, it is the only
place in the rack it does.
Order of operations, if both are bought together: the shelf goes in first (U4 is
the one free slot), then the spare has somewhere to land.
The other half is still unowned
Racking the spare does not address the first problem above. The encrypted export
still lands on
prometheusand nothing copies it anywhere — not to the spare,not offsite. That copy needs a destination decided;
#94 ("decide what
oracleisfor") and #77 ("nothing schedules
any backup") are the two it most likely wants solving with.
Tracked in
docs/roadmap.md; filed as an issue so it has a place to be discussed and closed.