Skip to content

Buy a spare ProDesk and rehearse the firewall restore #92

Description

@Gerrrt

make backup-firewall exports and encrypts morpheus's config, and
restore-the-firewall.md
documents the restore. Two things are still missing, and they are the two that
matter.

The backup is on the machine it protects

backup-firewall.sh:125-126:

This is on the same host as everything else it protects. Copy it to the backup
target and offsite.

Nothing does that copy. A backup on the same shelf as the thing it protects is
not a backup.

The runbook has never been executed

restore-the-firewall.md:168:

Until that has been done once, this runbook is a hypothesis.

Doing it needs a spare, and the spare should be the same ProDesk model:
pfSense stores interface assignments by device name, so identical hardware
restores straight through and anything else drops you into the console
interface-assignment dialogue — at exactly the moment you least want to be
answering questions.

The two halves are one purchase apart. Buying the spare unblocks the rehearsal,
and the rehearsal is what turns the runbook into something you can rely on at
1am.

Where the spare goes — #110

It racks on the 1U shelf from
#110, beside the switch, and is
left powered off.

Powered off is the point, not an omission. A spare that is plugged in and on the
network is exposed to whatever took the primary — and the primary is the device
that terminates every VLAN, so "whatever took it" is the case this spare exists
for.

It cannot go beside morpheus: that sits at U5 in a purpose-built mount holding
exactly one ProDesk Mini, which was checked at the rack rather than assumed. The
1U shelf has room for the switch and a second small box; the U5 bracket by design
does not. So the shelf is not only where the spare can live, it is the only
place in the rack it does.

Order of operations, if both are bought together: the shelf goes in first (U4 is
the one free slot), then the spare has somewhere to land.

The other half is still unowned

Racking the spare does not address the first problem above. The encrypted export
still lands on prometheus and nothing copies it anywhere — not to the spare,
not offsite. That copy needs a destination decided;
#94 ("decide what oracle is
for") and #77 ("nothing schedules
any backup") are the two it most likely wants solving with.

Tracked in docs/roadmap.md; filed as an issue so it has a place to be discussed and closed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions