Files

75 lines
3.1 KiB
Markdown

---
schema_version: 1
id: home-server.operations
type: reference
scope: [jupiter, mercury, design-decisions, monitoring, recovery]
sensitivity: private-infrastructure
last_reviewed: "2026-10-06"
sources:
- kind: owner-report
reference: "RAID/media tradeoff, CGNAT/public IPv4 rationale, no alerting and running monitoring/log containers, 2026-10-06"
- kind: owner-report
reference: "Outages over one day catastrophic; no independent credentials except restic key, recovery evidence, host-config archive or operational rules, 2026-10-06"
related: [home-server.reference, home-server.host, home-server.mercury, home-server.networking, home-server.storage, home-server.backups, home-server.deployment]
update_triggers: [data-priority-change, architecture-change, alerting-change, recovery-test]
unknowns:
- acceptable-data-loss-and-recovery-order-by-service
- data-criticality-outside-the-four-backed-up-directories
- tested-full-host-recovery-order
- monitoring-review-frequency
---
# Operations / decisions
## Owner decisions
| Decision | Reason / accepted tradeoff |
| --- | --- |
| RAID 0 for HDD data | Capacity prioritized over disk redundancy; downloaded media can be reacquired |
| Back up important state | Four application directories covered; media redundancy is not the objective |
| Mercury public edge | Static public IPv4; home ISP uses CGNAT |
| No residential public ingress | Owner preference to avoid exposing the home IP |
RAID 0 still stores important state alongside media: either HDD failure loses
the array; recovery depends on working backups. Owner intent is not evidence
that every important dataset is covered.
## Observability
| Facility | Current configuration |
| --- | --- |
| Host/container monitoring | Beszel hub and host-network agent present |
| Container logs | Dozzle with Docker socket proxy present |
| Automatic alerting | None configured |
Monitoring does not imply notification delivery. Backup-hook failures,
stopped services and storage failures require manual detection.
## Recovery status
| Item | Current status |
| --- | --- |
| Jupiter outage tolerance | At most 24 hours; longer is catastrophic to the owner |
| Recovery time | Not measured; 24-hour objective is not demonstrated |
| Acceptable data loss / RPO | Not defined |
| Independent recovery secrets | Restic encryption key only |
| Backup/integrity evidence | None supplied |
| Restore exercise | Never performed |
| Independent host-config archive | Not maintained |
| Operational rules / rollback policy | Not established |
Backup scope is documented in [Backups](backups.md). The four-directory plan
does not establish OS, host-configuration or named-volume recovery.
## Proposed recovery storage
Not implemented:
- Private Git repository: sanitized host configuration and bootstrap instructions.
- Encrypted off-host/offline archive: required credentials and secret-bearing configuration.
- Independent access instructions: account recovery, archive location and decryption.
Access/decryption must work without Jupiter or Portainer. A private Git
repository is not a substitute for protecting secret values. Restic key custody
alone does not provide Google Drive access.