--- schema_version: 1 id: home-server.operations type: reference scope: [jupiter, mercury, design-decisions, monitoring, recovery] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "RAID/media tradeoff, CGNAT/public IPv4 rationale, no alerting and running monitoring/log containers, 2026-10-06" - kind: owner-report reference: "Outages over one day catastrophic; no independent credentials except restic key, recovery evidence, host-config archive or operational rules, 2026-10-06" related: [home-server.reference, home-server.host, home-server.mercury, home-server.networking, home-server.storage, home-server.backups, home-server.deployment] update_triggers: [data-priority-change, architecture-change, alerting-change, recovery-test] unknowns: - acceptable-data-loss-and-recovery-order-by-service - data-criticality-outside-the-four-backed-up-directories - tested-full-host-recovery-order - monitoring-review-frequency --- # Operations / decisions ## Owner decisions | Decision | Reason / accepted tradeoff | | --- | --- | | RAID 0 for HDD data | Capacity prioritized over disk redundancy; downloaded media can be reacquired | | Back up important state | Four application directories covered; media redundancy is not the objective | | Mercury public edge | Static public IPv4; home ISP uses CGNAT | | No residential public ingress | Owner preference to avoid exposing the home IP | RAID 0 still stores important state alongside media: either HDD failure loses the array; recovery depends on working backups. Owner intent is not evidence that every important dataset is covered. ## Observability | Facility | Current configuration | | --- | --- | | Host/container monitoring | Beszel hub and host-network agent present | | Container logs | Dozzle with Docker socket proxy present | | Automatic alerting | None configured | Monitoring does not imply notification delivery. Backup-hook failures, stopped services and storage failures require manual detection. ## Recovery status | Item | Current status | | --- | --- | | Jupiter outage tolerance | At most 24 hours; longer is catastrophic to the owner | | Recovery time | Not measured; 24-hour objective is not demonstrated | | Acceptable data loss / RPO | Not defined | | Independent recovery secrets | Restic encryption key only | | Backup/integrity evidence | None supplied | | Restore exercise | Never performed | | Independent host-config archive | Not maintained | | Operational rules / rollback policy | Not established | Backup scope is documented in [Backups](backups.md). The four-directory plan does not establish OS, host-configuration or named-volume recovery. ## Proposed recovery storage Not implemented: - Private Git repository: sanitized host configuration and bootstrap instructions. - Encrypted off-host/offline archive: required credentials and secret-bearing configuration. - Independent access instructions: account recovery, archive location and decryption. Access/decryption must work without Jupiter or Portainer. A private Git repository is not a substitute for protecting secret values. Restic key custody alone does not provide Google Drive access.