Skip to content

Build the sensitive-tier host on the ProDesk (ADR-0034) #404

Description

@Gerrrt

Where this stands, 2026-09-19

The box is in hand since 2026-09-14 (#492), opened 2026-09-15, named trinity, and its 512 GB SSD is an M.2 stick with the second M.2 slot free (#474) — which is where the I226 card goes. Still in transit: the I226 card on its M.2 adapter and the pfSense installer stick; between them, the whole of what the rehearsal waits on. The stack is authored: seven of ADR-0008's nine services are merged and CI-validated in stacks/sensitive/ (#129#135), the tier's CA is decided (ADR-0037) and its runbook written, the restore runbook has been run once on the monitoring host.

Three things the body as filed says are gone: the "second drive for the photo library" (the 2 TB USB drive is on hand); the "USB NIC" (morpheus has none — the spare needs the I226 card, restore-the-firewall.md); and the Zigbee/Z-Wave coordinator (ADR-0035: no radio, nothing on Skids needs one). Both "not decided here" items are decided: the 99 → 20 rule is one host to one device on two ports (ADR-0035), and the forwarder change is forward-dns-to-adguard.md. ADR-0037 and ADR-0043 keep the CA off this host: the tier root is cold on prometheus; trinity receives a bundle with the root key removed.

Order of work

  1. Before 2026-10-08, the return window (hardware.md): read the i5-8500T, the 32 GB, the 512 GB, the serial and product number off the case, and that it has the onboard NIC alone. The only step here not waiting on a package. Owned jointly with Rehearse the firewall restore on trinity #92.
  2. The firewall restore rehearsal — owned by Rehearse the firewall restore on trinity #92; this issue receives the box afterwards, per restore-the-firewall.md step 6.
  3. Wipe, and decide disk encryption at build time (ADR-0022 needs the answer before the first real item).
  4. Static address, Kea reservation, network.md and hardware.md Compute row.
  5. make secrets-init STACK=sensitive; the tier's own age recipient on this host.
  6. Mint and install the tier CA per build-the-tier-ca.md; the root key never travels.
  7. Format the USB disk ext4 for IMMICH_UPLOAD_LOCATION.
  8. Kea reservation for bifrost, then the 99 → 20 pass with the TerminalSegmentReachedInternalNetwork cannot fire — the firewall logs blocks only #223 tripwire read immediately after; host overrides on morpheus.
  9. Deploy the stack. The deploy checklist is stacks/sensitive/README.mdWhat make validate still does not prove — and it is the acceptance list for Sensitive tier: Caddy as the reverse proxy and the only published port #129Sensitive tier: AdGuard Home, as a forwarder behind Unbound and not a client-facing resolver #135.
  10. A timer for make backup STACK=sensitive and a copy off the host (README, restore-the-sensitive-tier.md); then Nothing converges stacks/sensitive: the tier with the real data is the only one deployed by hand #533 for converging it.
  11. The Immich database-before-first-start restore rehearsal (README) before the first real photo; TOTP enrolments; the ADR-0022 and ADR-0023 records.

Done when

The nine services serve from trinity over leaves from the tier's CA, the backup timer runs and copies off-host, and the return window has passed with the spec read. #129#135 close on step 8; this closes on step 10.


Body as filed, superseded 2026-09-19

The host for ADR-0008's sensitive tier. Sixteen open issues (#129#137,
#142#148) say "the mini PC in #102"; #102 closed on 2026-09-04 by splitting
into them, and the machine itself lost its tracker that day. This is the
tracker.

The machine

ADR-0034 decides it: the HP ProDesk 600 G4 bought on 2026-09-08 — i5-8500T,
32 GB, 512 GB SSD, the same model as morpheus. It was bought as the cold
spare for #92 because that was the only ProDesk anyone had been told to buy;
the ADR records why it is a better fit for this tier than the "N100-class"
box the docs assumed, and why the cold spare is deferred rather than bought
twice. In a disaster it is the spare hardware: same model, so a pfSense
restore onto it goes straight through, at the cost of the tier being down
until a replacement arrives — a cost ADR-0023 already accepts.

Order of work — each step is testable only after the one before it

  1. Rehearse the firewall restore on it first, on the bench, exactly as
    restore-the-firewall.md §Rehearse
    the restore on the spare
    says. That closes the rehearsal half of Rehearse the firewall restore on trinity #92 on
    this hardware, before the box holds anything, and answers the questions §3
    of that runbook cannot: what the fresh install assigns to the onboard NIC,
    whether a USB NIC comes back under the same name, how long it takes. Needs
    the pfSense installer stick and a USB NIC.
  2. Wipe it, and decide disk encryption at build time (ADR-0022 requires
    the decision, not an answer). The choice for a headless box: a TPM-sealed
    key that unlocks unattended, or a box that stays locked after a power cut
    until someone types a passphrase. ADR-0023 makes the second acceptable —
    the tier is allowed to be down — so pick it deliberately.
  3. Address and place it. A static on Winterfell below the DHCP range, a
    Kea reservation, network.md and hardware.md rows. Where it physically
    sits is decided here too: Sensitive tier: Home Assistant, and the 99→20 rule it exists to use #134 notes a USB Zigbee/Z-Wave coordinator has
    to be on this box, and a rack in a closet is a poor place for a radio.
  4. stacks/sensitive/ (name to settle), in the ADR-0004 shape: Caddy as
    the only published port (Sensitive tier: Caddy as the reverse proxy and the only published port #129), step-ca (Sensitive tier: step-ca, so issuing a certificate is an API call rather than a runbook #130), then the services — empty.
    scripts/stacks.sh makes a third stack cost nothing in tooling (Every validator is pinned to stacks/observability — a second stack would be checked by nothing #263).
  5. Prove the backup and restore path with nothing in it. ADR-0023's
    off-estate encrypted copy, keyed to the second recipient Add a second age recipient so decryption does not depend on one person #294 named. A
    restore that has never been run is a hypothesis, and this box will hold
    the data whose loss actually hurts.
  6. TOTP enrolled at first login on Vaultwarden, Paperless-ngx and Home
    Assistant, and security.md naming Immich and AdGuard as unable to carry
    a factor — ADR-0022's floor.
  7. Then the first real photo. ADR-0022's trigger fires on it; everything
    above has to exist before it arrives.

Purchases this still needs

  • A second drive for the photo library, sized when the library's size is
    known — the G4 has a free bay. 512 GB is fine for everything but Immich.
  • A USB NIC for step 1, ideally the same chipset as morpheus's.
  • Not a second ProDesk, unless the tier holding real data makes an hour
    of firewall downtime unacceptable — that is ADR-0034's reopen condition.

Not decided here

The width of the 99 → 20 rule for Home Assistant (#134), and ADR-0010's
forwarding change for AdGuard (#135). Both are the roadmap's #102 paragraph
and belong to their issues.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsensitivestacks/sensitive on trinity (VLAN 99)seq/2Step 2 within its milestone; same number = can run in parallel

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions