What is left: the rehearsal
The two sections this issue opened with are done or withdrawn. The firewall backup's off-host copy to oracle exists and was verified (2026-09-03). "Buy a spare ProDesk" was withdrawn by ADR-0034 — there is one ProDesk, trinity, the tier's host and the firewall's spare hardware — and it was bought and landed 2026-09-14 (#492). ADR-0034 and restore-the-firewall.md deliberately keep the rehearsal here and the build in #404: step 6 of the runbook hands the box to #404 afterwards.
restore-the-firewall.md: "Nobody has done this yet." The hypothesis sentence is still in the runbook, unresolved.
What it waits on
The I226 card on its M.2 adapter and the pfSense installer stick, both in transit (hardware.md). trinity's SSD is M.2 and the second M.2 slot is free (#474), so the card has a home.
Order of work
Done when
A restore from the oracle copy boots on trinity with the I226 card and serves the estate's VLANs on the bench, and the runbook no longer says nobody has done it.
Body as filed, superseded 2026-09-19
make backup-firewall exports and encrypts morpheus's config, and
restore-the-firewall.md
documents the restore. Two things are still missing, and they are the two that
matter.
The backup is on the machine it protects
backup-firewall.sh:125-126:
This is on the same host as everything else it protects. Copy it to the backup
target and offsite.
Nothing does that copy. A backup on the same shelf as the thing it protects is
not a backup.
The runbook has never been executed
restore-the-firewall.md:168:
Until that has been done once, this runbook is a hypothesis.
Doing it needs a spare, and the spare should be the same ProDesk model:
pfSense stores interface assignments by device name, so identical hardware
restores straight through and anything else drops you into the console
interface-assignment dialogue — at exactly the moment you least want to be
answering questions.
The two halves are one purchase apart. Buying the spare unblocks the rehearsal,
and the rehearsal is what turns the runbook into something you can rely on at
1am.
Where the spare goes — #110
It racks on the 1U shelf from
#110, beside the switch, and is
left powered off.
Powered off is the point, not an omission. A spare that is plugged in and on the
network is exposed to whatever took the primary — and the primary is the device
that terminates every VLAN, so "whatever took it" is the case this spare exists
for.
It cannot go beside morpheus: that sits at U5 in a purpose-built mount holding
exactly one ProDesk Mini, which was checked at the rack rather than assumed. The
1U shelf has room for the switch and a second small box; the U5 bracket by design
does not. So the shelf is not only where the spare can live, it is the only
place in the rack it does.
Order of operations, if both are bought together: the shelf goes in first (U4 is
the one free slot), then the spare has somewhere to land.
The other half is still unowned
Racking the spare does not address the first problem above. The encrypted export
still lands on prometheus and nothing copies it anywhere — not to the spare,
not offsite. That copy needs a destination decided;
#94 ("decide what oracle is
for") and #77 ("nothing schedules
any backup") are the two it most likely wants solving with.
Tracked in docs/roadmap.md; filed as an issue so it has a place to be discussed and closed.
What is left: the rehearsal
The two sections this issue opened with are done or withdrawn. The firewall backup's off-host copy to
oracleexists and was verified (2026-09-03). "Buy a spare ProDesk" was withdrawn by ADR-0034 — there is one ProDesk,trinity, the tier's host and the firewall's spare hardware — and it was bought and landed 2026-09-14 (#492). ADR-0034 andrestore-the-firewall.mddeliberately keep the rehearsal here and the build in #404: step 6 of the runbook hands the box to #404 afterwards.restore-the-firewall.md: "Nobody has done this yet." The hypothesis sentence is still in the runbook, unresolved.What it waits on
The I226 card on its M.2 adapter and the pfSense installer stick, both in transit (
hardware.md).trinity's SSD is M.2 and the second M.2 slot is free (#474), so the card has a home.Order of work
hardware.md;restore-the-firewall.mdcalls it "the only entry on this list with a deadline"). Shared with Build the sensitive-tier host on the ProDesk (ADR-0034) #404 step 0.restore-the-firewall.md§1–§5 on the bench.roadmap.mdunder this issue.Done when
A restore from the
oraclecopy boots ontrinitywith the I226 card and serves the estate's VLANs on the bench, and the runbook no longer says nobody has done it.Body as filed, superseded 2026-09-19
make backup-firewallexports and encryptsmorpheus's config, andrestore-the-firewall.mddocuments the restore. Two things are still missing, and they are the two that
matter.
The backup is on the machine it protects
backup-firewall.sh:125-126:Nothing does that copy. A backup on the same shelf as the thing it protects is
not a backup.
The runbook has never been executed
restore-the-firewall.md:168:Doing it needs a spare, and the spare should be the same ProDesk model:
pfSense stores interface assignments by device name, so identical hardware
restores straight through and anything else drops you into the console
interface-assignment dialogue — at exactly the moment you least want to be
answering questions.
The two halves are one purchase apart. Buying the spare unblocks the rehearsal,
and the rehearsal is what turns the runbook into something you can rely on at
1am.
Where the spare goes — #110
It racks on the 1U shelf from
#110, beside the switch, and is
left powered off.
Powered off is the point, not an omission. A spare that is plugged in and on the
network is exposed to whatever took the primary — and the primary is the device
that terminates every VLAN, so "whatever took it" is the case this spare exists
for.
It cannot go beside
morpheus: that sits at U5 in a purpose-built mount holdingexactly one ProDesk Mini, which was checked at the rack rather than assumed. The
1U shelf has room for the switch and a second small box; the U5 bracket by design
does not. So the shelf is not only where the spare can live, it is the only
place in the rack it does.
Order of operations, if both are bought together: the shelf goes in first (U4 is
the one free slot), then the spare has somewhere to land.
The other half is still unowned
Racking the spare does not address the first problem above. The encrypted export
still lands on
prometheusand nothing copies it anywhere — not to the spare,not offsite. That copy needs a destination decided;
#94 ("decide what
oracleisfor") and #77 ("nothing schedules
any backup") are the two it most likely wants solving with.
Tracked in
docs/roadmap.md; filed as an issue so it has a place to be discussed and closed.