docs: PBS deployment runbook (ANA primary + NH3 DR mirror)

End-to-end runbook for standing up Proxmox Backup Server across the
fleet. Path A architecture: single primary at ANA, one-way sync to NH3
for disaster recovery. All 5 hypervisors (pfi-pve, nh3-pve, esh-pve,
esh-pve-nas, sfsrv-ana) migrate from local-dump vzdump to PBS-ANA.

Key decisions captured in the runbook:
  - PBS in a Debian VM (not LXC) for clean capability model.
  - PBS-ANA on pfi-pve, datastore via NFS from 10.250.50.50 —
    separates backup data from hypervisor boot disk.
  - PBS-NH3 on nh3-pve with local storage (independent failure
    domain from ANA).
  - Dedicated fleet-vzdump API token; read-only sync token for
    PBS-NH3's pull job.
  - sfsrv-ana specifically goes from zero backup coverage to full
    vzdump coverage in Phase 3.

9 phases, each self-contained with a done-state and rollback
posture. User can stop between phases without leaving the fleet in a
bad state.

STATUS.md: added item 6b tracking this deployment. Original item 6
(cross-site rsync) now scoped to restic-only since PBS handles the
VM-image cross-site redundancy directly.
This commit is contained in:
vh
2026-04-21 17:14:46 -07:00
parent 76a0768fdb
commit 0368ab732a
2 changed files with 491 additions and 0 deletions
+15
View File
@@ -91,6 +91,21 @@ significant work lands — don't let it drift quietly.
(`/mnt/backup/restic/repo/ana/`) and NH3 Synology data dir. Planned
since initial rest-server setup; not built. Needs Synology SSH
access first (item 8). ~20 min once access is there.
- Note: cross-site mirroring for the VM-image layer is being
addressed by the PBS deployment (item 6b) — this rsync is now
scoped to restic repos only.
6b. **PBS deployment across the fleet.** Runbook lives at
`docs/runbooks/pbs-deployment.md`. Primary at ANA (VM on pfi-pve,
NFS datastore on Debian NAS), DR mirror at NH3 (VM on nh3-pve,
local datastore). One-way sync from ANA → NH3 nightly. All 5
hypervisors (pfi-pve, nh3-pve, esh-pve, esh-pve-nas, sfsrv-ana)
migrate off local-dump vzdump jobs onto PBS.
- Closes: SureFire's zero-coverage gap (currently no vzdump at all on sfsrv-ana)
- Closes: "cross-site redundancy for VM images" scope item
- Provides: cross-fleet block-level dedupe, dirty-bitmap incrementals,
real safe-prune retention, per-host encryption keys
- Est. 4–6h spread across sittings. 9 phases in the runbook.
7. **SureFire tenant backup plan decision.** Three options documented in
`servers/sfsrv-ana/README.md`: