make snapshot and make state-backup: the pre-flight and post-flight gates #32

Closed
opened 2026-10-06 15:01:14 +00:00 by pit · 0 comments
Owner

Parent

#27

What to build

make snapshot takes a PBS snapshot of the Prod Guest, scripted rather than left as a printed reminder, using the Proxmox Ansible collection already installed. make state-backup copies both Stacks' state into one timestamped tarball outside the repo, encrypted symmetrically with the operator's existing Vault password. The encryption recipe is documented and a restore from a fresh backup is performed once, because the command that produced the existing artifacts was never recorded.

Acceptance criteria

  • make snapshot creates a timestamped snapshot of the Prod Guest and can be re-run without harm.
  • make state-backup produces one timestamped encrypted tarball holding both Stacks' state, outside the repo, named to the existing convention.
  • A restore from a fresh backup is verified once, and the recipe — including the shared-secret trade-off of reusing the Vault password — is recorded in the runbook.
  • The runbook documents both Targets.

Blocked by

  • ##29 — the Makefile scaffold and its apply gate.
## Parent #27 ## What to build `make snapshot` takes a PBS snapshot of the Prod Guest, scripted rather than left as a printed reminder, using the Proxmox Ansible collection already installed. `make state-backup` copies both Stacks' state into one timestamped tarball outside the repo, encrypted symmetrically with the operator's existing Vault password. The encryption recipe is documented and a restore from a fresh backup is performed once, because the command that produced the existing artifacts was never recorded. ## Acceptance criteria - [ ] `make snapshot` creates a timestamped snapshot of the Prod Guest and can be re-run without harm. - [ ] `make state-backup` produces one timestamped encrypted tarball holding both Stacks' state, outside the repo, named to the existing convention. - [ ] A restore from a fresh backup is verified once, and the recipe — including the shared-secret trade-off of reusing the Vault password — is recorded in the runbook. - [ ] The runbook documents both Targets. ## Blocked by - ##29 — the Makefile scaffold and its apply gate.
pit closed this issue 2026-10-06 16:03:55 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
olympus/infra-forge#32
No description provided.