ccnet-WI: review credential storage backup coverage #28
Labels
No labels
blocked
borg-backup
ceph
forgejo
in-progress
infra
netdata
nextcloud
p:high
p:low
p:medium
searxng
service-onboard
swarm-nodes
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
copper/ccnet-prod-devops#28
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The ccnet-WI site's credentials (SSH host keys, WireGuard tunnel keys/PSK, ccnet-wi-pbs's sync-job auth to the main site's PBS, etc.) were set up/discovered across the 2026-07-13/14 site audit, but it's unclear whether any of them are backed up anywhere beyond the single machine each lives on.
Scope: audit what credentials exist for this site and confirm each has a durable backup/recovery path, following the pattern ccnet-swarm-nodes-runbook/ and ccnet-borg-backup/ already use (Ansible Vault-encrypted values checked into this repo) rather than a credential existing in exactly one place with no recovery path if that device is lost.
Related: docs/ccnet-wi-site.md.