fix(restic): vm-esh-nas off env-file too; infra-ops now provisioned there
Prime bootstrapped infra-ops on vm-esh-nas with playbooks/bootstrap-infra-ops-user.yaml. It got the fleet-pinned uid/gid 850, NOPASSWD sudo with log_output, the docker group and a 0700 home. That let playbooks/restic-repository-file.yaml migrate the last restic host: the live profile matched the repo's pre-change sha, its units no longer carry the URL, its secrets are vaulted, and the live and repo profiles now match (a5ea75ea). All eight restic hosts are clean. The staged helper script is gone, both from Prime's home on the host and from the repo. The docs that described vm-esh-nas as lkraven-only are updated.
This commit is contained in:
@@ -178,7 +178,7 @@ the stop→umount→rm-ghost→remount→start variant.
|
||||
|
||||
## Known gaps / TODO
|
||||
|
||||
### ✅ `resticprofile schedule` published the repo credential (found and fixed 2026-09-27, except vm-esh-nas)
|
||||
### ✅ `resticprofile schedule` published the repo credential (found and fixed on all eight hosts, 2026-09-27)
|
||||
|
||||
On a host whose profile loads `RESTIC_REPOSITORY` from `env-file:
|
||||
/etc/restic/restic.env`, `resticprofile schedule` copies that value, **including
|
||||
@@ -200,11 +200,9 @@ containing `rest:http`. nh3-docker's scheduled unit then ran a real backup (snap
|
||||
`a29b889d`). All seven hosts' URLs and passphrases are now vaulted as
|
||||
`<host>/etc/restic/{repository,password}`.
|
||||
|
||||
**Still open: vm-esh-nas.** infra-ops has no account there, so its unit still
|
||||
leaks. The migration script is staged at `~lkraven/restic-repofile-migrate.sh`
|
||||
(repo copy `configs/restic/vm-esh-nas/migrate-repository-file.sh`), and Prime runs
|
||||
it with `ssh -t vm-esh-nas 'sudo bash ~/restic-repofile-migrate.sh'`. Its secrets are
|
||||
not vaulted yet, because that needs root there.
|
||||
**vm-esh-nas followed the same day.** Prime bootstrapped infra-ops there
|
||||
(`playbooks/bootstrap-infra-ops-user.yaml`), and the same playbook then migrated it.
|
||||
Its secrets are vaulted too. **Zero restic hosts now leak.**
|
||||
|
||||
The passwords themselves were readable until the move, so the **rotation below is
|
||||
still the real fix**. On rotation, update the vault, `restic.env` and `repository`
|
||||
|
||||
Reference in New Issue
Block a user