ks2: ks4 pull leg and its WireGuard tunnel move from nuc to nas
nuc-seed.md -> nas-seed.md. The leg was designed around nuc's USB pool, which is exactly the device it must not depend on. Target pool ks4backup now lives on tank; nas becomes WG peer 10.8.0.22 and nuc's tunnel retires once seeded — nuc no longer needs one at all, since transmission-bt (the only other user) moved to nas with its own in-container tunnel. ks4 needs no change: traffic arrives masqueraded as the wireguard container whichever peer sent it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
58dcaa5d41
commit
66c7bca28f
+8
-7
@@ -17,10 +17,11 @@ What remains on the box is **cold history**: instance replicas on pool
|
||||
`/backup/ns3061243` on pool `backup` (last refreshed 2026-08-28),
|
||||
snapshotted daily there (`zfs-auto-snapshot.sh`, 2-month expiry).
|
||||
|
||||
⚠️ While the nuc leg waits for FTTH, instances have no *fresh*
|
||||
⚠️ While the nas leg waits for FTTH, instances have no *fresh*
|
||||
off-site copy — the ks2 push is to be re-enabled as soon as the
|
||||
initial restic sync finishes (decided 2026-08-28), and retired again
|
||||
when nuc takes over.
|
||||
when nas takes over. (The leg moved from nuc to the new host `nas`
|
||||
on 2026-08-30 — see [nas-seed.md](nas-seed.md).)
|
||||
|
||||
## Inventory findings (2026-08-22)
|
||||
|
||||
@@ -51,8 +52,8 @@ when nuc takes over.
|
||||
| local, 2nd disk | `incus-copy.sh -p backup -s backup` → sdb5 pool | **live** (01:00) |
|
||||
| off-site, S3 (data+DB) | **restic** → bucket `restic-data` ([restic-backup.md](../ks4/restic-backup.md)) | **live** (05:00) |
|
||||
| off-site, S3 (instances) | restic over `incus file mount` of the `backup`-project replicas | **shelved** 2026-08-28 (replication covers instances) |
|
||||
| off-site, nuc | nuc pulls `ks4:*` → pool `ks4backup` over WG ([nuc-seed.md](nuc-seed.md)) | waiting FTTH (< Sep 30) |
|
||||
| off-site, ks2 (interim) | `incus-copy.sh -d ks2 -m push` at 02:00 until the nuc leg seeds | to re-enable once the restic seed finishes |
|
||||
| off-site, nas | **nas** pulls `ks4:*` → pool `ks4backup` over WG ([nas-seed.md](nas-seed.md)) | waiting FTTH (< Sep 30); moved off nuc 2026-08-30 |
|
||||
| off-site, ks2 (interim) | `incus-copy.sh -d ks2 -m push` at 02:00 until the nas leg seeds | to re-enable once the restic seed finishes |
|
||||
|
||||
## Actions (backup work documented in [`../ks4/`](../ks4/), ks2-only tasks here)
|
||||
|
||||
@@ -65,9 +66,9 @@ when nuc takes over.
|
||||
([restic-backup.md](../ks4/restic-backup.md), live 2026-08-28; the
|
||||
predecessor's doc is kept as reference)
|
||||
4. ~~instance leg to S3~~ — **shelved 2026-08-28**: instances are
|
||||
protected by replication (sdb + nuc/ks2), their data and configs by
|
||||
protected by replication (sdb + nas/ks2), their data and configs by
|
||||
`restic-data`
|
||||
5. [nuc-seed.md](nuc-seed.md) — **prepared**; after FTTH: seed nuc
|
||||
5. [nas-seed.md](nas-seed.md) — **prepared**; after FTTH: seed the nas
|
||||
pull leg, verify all instances, test-restore one
|
||||
6. [decommission.md](decommission.md) — **prepared**; cut flows,
|
||||
final diff of `/backup/ns3061243`, wipe pools, terminate at OVH
|
||||
@@ -77,7 +78,7 @@ when nuc takes over.
|
||||
- [x] biwiki + spot consciously abandoned (2026-08-22)
|
||||
- [x] local leg cron running since 2026-08-22, **18/18 instances**
|
||||
replicated (verified 2026-08-28)
|
||||
- [ ] nuc leg fully seeded **and** one instance test-restored
|
||||
- [ ] **nas** leg fully seeded **and** one instance test-restored
|
||||
- [x] restic S3 backups live (05:00) **and** restore drill passed
|
||||
2026-08-28: tree restored byte-identical to live, dump restored
|
||||
and loaded into a scratch MariaDB (12/12 tables)
|
||||
|
||||
Reference in New Issue
Block a user