ccnet-WI: review credential storage backup coverage #28

Open
opened 2026-07-14 07:45:48 +00:00 by claude-bot · 0 comments
Collaborator

The ccnet-WI site's credentials (SSH host keys, WireGuard tunnel keys/PSK, ccnet-wi-pbs's sync-job auth to the main site's PBS, etc.) were set up/discovered across the 2026-07-13/14 site audit, but it's unclear whether any of them are backed up anywhere beyond the single machine each lives on.

Scope: audit what credentials exist for this site and confirm each has a durable backup/recovery path, following the pattern ccnet-swarm-nodes-runbook/ and ccnet-borg-backup/ already use (Ansible Vault-encrypted values checked into this repo) rather than a credential existing in exactly one place with no recovery path if that device is lost.

Related: docs/ccnet-wi-site.md.

The ccnet-WI site's credentials (SSH host keys, WireGuard tunnel keys/PSK, ccnet-wi-pbs's sync-job auth to the main site's PBS, etc.) were set up/discovered across the 2026-07-13/14 site audit, but it's unclear whether any of them are backed up anywhere beyond the single machine each lives on. Scope: audit what credentials exist for this site and confirm each has a durable backup/recovery path, following the pattern ccnet-swarm-nodes-runbook/ and ccnet-borg-backup/ already use (Ansible Vault-encrypted values checked into this repo) rather than a credential existing in exactly one place with no recovery path if that device is lost. Related: docs/ccnet-wi-site.md.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
copper/ccnet-prod-devops#28
No description provided.