Back up and restore-test the DNS-collector PKI #19

Open
opened 2026-08-23 17:07:55 +00:00 by stanta · 0 comments
Owner

Outcome

Keep an encrypted external backup of the ignored DNS-collector PKI and prove that it can be restored.

Current state

The controller PKI directory is ignored by Git. No repository task verifies its external backup.

Work

  • Confirm backup ownership and destination.
  • Back up the PKI without printing key material.
  • Restore it into a protected temporary target.
  • Verify file names, modes, certificate relationships, and expiry.
  • Record the rotation alternative if restoration fails.

Validation

  • A protected restore completes.
  • DNS-collector client and receiver certificate relationships validate.
  • No private key appears in logs or Git.

References

  • iac/MAGHOST.md
  • iac/ansible/.dns-secrets/dnscollector-pki
  • iac/ansible/roles/knot_authoritative/
## Outcome Keep an encrypted external backup of the ignored DNS-collector PKI and prove that it can be restored. ## Current state The controller PKI directory is ignored by Git. No repository task verifies its external backup. ## Work - [ ] Confirm backup ownership and destination. - [ ] Back up the PKI without printing key material. - [ ] Restore it into a protected temporary target. - [ ] Verify file names, modes, certificate relationships, and expiry. - [ ] Record the rotation alternative if restoration fails. ## Validation - [ ] A protected restore completes. - [ ] DNS-collector client and receiver certificate relationships validate. - [ ] No private key appears in logs or Git. ## References - `iac/MAGHOST.md` - `iac/ansible/.dns-secrets/dnscollector-pki` - `iac/ansible/roles/knot_authoritative/`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
stanta/homelab#19
No description provided.