fix(restic): vm-esh-nas off env-file too; infra-ops now provisioned there
Prime bootstrapped infra-ops on vm-esh-nas with playbooks/bootstrap-infra-ops-user.yaml. It got the fleet-pinned uid/gid 850, NOPASSWD sudo with log_output, the docker group and a 0700 home. That let playbooks/restic-repository-file.yaml migrate the last restic host: the live profile matched the repo's pre-change sha, its units no longer carry the URL, its secrets are vaulted, and the live and repo profiles now match (a5ea75ea). All eight restic hosts are clean. The staged helper script is gone, both from Prime's home on the host and from the repo. The docs that described vm-esh-nas as lkraven-only are updated.
This commit is contained in:
@@ -34,8 +34,8 @@ Started by hand, then **fixed the same day**: `hosts/nh3-dev.yaml` no longer bin
|
||||
the NAS shares and `BESZEL_EXTRA_FS` is empty. Their capacity is nh3-nas's own
|
||||
volume, which nh3-nas's agent reports.
|
||||
|
||||
Use `infra-ops@<ip>` with passwordless sudo, except vm-esh-nas:
|
||||
`lkraven@10.0.50.154` has Docker access. Irvine's hub address is
|
||||
Use `infra-ops@<ip>` with passwordless sudo. vm-esh-nas has it too since 2026-09-27.
|
||||
Before that date only `lkraven@10.0.50.154`, with Docker access, worked there. Irvine's hub address is
|
||||
`100.64.0.6`; its retired `10.100.79.3` address caused silent loss of monitoring.
|
||||
|
||||
## Filesystems and deployment
|
||||
|
||||
Reference in New Issue
Block a user