d2764bf78e
463 lines with 64 mentions of specific hosts, in a public repo: the primary and tunnel hosts by name, the registrar/DNS step, the tunnel resource wiring, shared token custody, per-machine flip dates, and a palace lineage naming three work machines. Now in the private fleet repo (fleet-ops 093fb65); this file becomes a moved-note in the shape docs/synlig-primary-runbook.md already established. Git history keeps the old text, so this limits future exposure rather than undoing it. Unlike the primary-host runbook, this file was MIXED — and the stub says so instead of quietly implying the toolkit still documents HTTP exposure. §1.1-§1.3 (why one shared fleet token rather than per-device proxy users, and the one place per-device identity does exist), §2 (the bind trap and the Host/Origin pin) and §3.7 (a client is flipped by three env vars that travel as a set) are reusable mechanism now published nowhere else. Named in the stub so the extraction is tracked debt rather than a silent loss, and named in the private copy too so whoever extracts it can delete the duplicate. Inbound references fixed rather than left pointing at content that moved: two §3.8 pointers in extensions/pi/README.md are replaced by the instruction they were pointing at (the palace path reported by mempalace_status must be the remote host's — a half-flipped client looks healthy while reporting a local path), and the bind-trap reference is replaced by the Host/Origin sentence itself, so the extension README no longer depends on the moved file. contrib also loses a hostname and a seeding date it did not need to make its point.
22 lines
1.1 KiB
Markdown
22 lines
1.1 KiB
Markdown
# (moved) primary-host runbook
|
|
|
|
This file used to contain the deployment runbook for one specific primary host —
|
|
its hostname, addresses, user, service wiring and rollback steps.
|
|
|
|
**That content now lives in a private repository**, because a host inventory is
|
|
operator data for one deployment, not part of the toolkit. This repository is
|
|
public and keeps only host-agnostic *mechanism*.
|
|
|
|
What lives where:
|
|
|
|
| Content | Home |
|
|
|---|---|
|
|
| How this deployment was exposed over HTTP (tunnel, DNS, token custody) | private fleet repository — see [`phase-1-exposure-runbook.md`](phase-1-exposure-runbook.md), also moved |
|
|
| Why a palace needs a special backup, and how to restore one | `docs/backup-and-recovery.md` (here) |
|
|
| Unit/timer/plist templates | `contrib/` (here) |
|
|
| Which machine is primary, its addresses, users, tunnels, offsite target | private fleet repository |
|
|
| Per-host feeder device names and schedules | private fleet repository |
|
|
|
|
If you are looking for the mechanism, the two runbooks above are the same
|
|
procedures with `<PRIMARY_HOST>` and `<USER>` in place of one site's specifics.
|