4c388a398b
gates / gates (push) Successful in 5m41s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
63 lines
4.6 KiB
Markdown
63 lines
4.6 KiB
Markdown
# Break-glass sheet — the keys that must exist outside DooPlex (R-923)
|
|
|
|
> **A template. It holds NO key value, and none may ever be written into this file, a commit, a log or a chat.**
|
|
> Print this page, then write or stick each value onto the paper copy only. Keep the paper away from home (DooPlex is
|
|
> at home: a fire takes both). Why each key is here and what it opens: `total-loss-of-dooplex.md`.
|
|
>
|
|
> **A key in the password manager is not enough:** Vaultwarden runs on DooPlex (operator ruling, 2026-10-09).
|
|
|
|
## How to print a key without it landing anywhere
|
|
|
|
Run these from your **own workstation** (not through Claude Code, not through `!`). Each command writes one file on
|
|
the workstation; open it, print it, then destroy the file. Nothing is stored on DooPlex or in any log.
|
|
|
|
```bash
|
|
D=kisfenyo@192.168.0.180 # DooPlex
|
|
# S1 and S2 — PBS keys: Proxmox's own paper form (text + QR code)
|
|
ssh -t $D 'sudo proxmox-backup-client key paperkey /etc/felhom-dooplex-offsite/enc.key --output-format html --subject "S1 DooPlex off-site key"' > s1.html
|
|
ssh -t $D 'sudo proxmox-backup-client key paperkey /etc/felhom-hub-backup/enc.key --output-format html --subject "S2 Hub-DB off-site key"' > s2.html
|
|
# S4, S5, S7 — one line each
|
|
ssh -t $D 'sudo kubectl -n felhom-system get secret offsite-secret-key -o jsonpath="{.data.OFFSITE_SECRET_KEY}" | base64 -d' > s4.txt
|
|
ssh -t $D 'sudo cat /etc/backup/restic-password' > s5.txt
|
|
ssh -t $D 'sudo cat /etc/felhom-hub-backup/token-restore' > s7.txt
|
|
# S6 — the signing keys (OpenSSH text, ~7 lines each)
|
|
ssh $D 'cat /mnt/5_hdd/felhom.eu/felhom-rec-recovery' > s6-recovery.txt
|
|
ssh $D 'cat /mnt/5_hdd/felhom.eu/felhom-op-operational' > s6-operational.txt
|
|
# open each, print, check the print is readable, then:
|
|
shred -u s1.html s2.html s4.txt s5.txt s7.txt s6-recovery.txt s6-operational.txt
|
|
```
|
|
|
|
On Windows without `shred`: delete the files and empty the recycle bin. The `-t` adds a carriage return to the
|
|
captured line on some systems; strip it when typing the value back.
|
|
|
|
**Check a print later without exposing it:** for S1/S2 the only reliable check is one restore with a key file rebuilt
|
|
from the printed `data` field (hub-DB runbook Step 0 note) — `key show` cannot check a rebuilt key.
|
|
|
|
---
|
|
|
|
## The sheet (print from here)
|
|
|
|
**FELHOM — break-glass keys.** Printed on: ____________ Stored at: ______________________________
|
|
|
|
| # | Key | Public fingerprint (to match the right key) | Value — write or stick here |
|
|
|---|---|---|---|
|
|
| S1 | DooPlex off-site key — opens Gitea, the password manager, the k8s Secrets export (ep0 `operator`, `host/dooplex-gitea`) | PBS key `93:03:bf:d7:1f:4c:9e:fe…` | `data`: ______________________________________________ |
|
|
| S2 | Hub-DB off-site key — opens the hub database (ep0 `operator`, `host/dooplex-hub`) | PBS key `b2:19:bf:36:3b:97:3d:6c…` | `data`: ______________________________________________ |
|
|
| S4 | Hub seal key `OFFSITE_SECRET_KEY` (64 hex) | — | ______________________________________________________ |
|
|
| S5 | DooPlex restic / Secrets-export passphrase | — | ______________________________________________________ |
|
|
| S6a | Signing RECOVERY key `felhom-rec-recovery` | `SHA256:/ixgTesZqykAGJpFUUd4kLAiHFgKOkYFLNC3AQXWP+k` | (staple the printout) |
|
|
| S6b | Signing OPERATIONAL key `felhom-op-operational` | `SHA256:7YqN4rXO08yixTeOO+UtQ8jHyIGycICuctQgRYVGnWw` | (staple the printout) |
|
|
| S7 | ep0 read-only token `dooplex-hub@pbs!restore` | — | ______________________________________________________ |
|
|
| S8 | Hetzner account: login e-mail · password · two-factor recovery codes | — | ______________________________________________________ |
|
|
| S11 | Cloudflare account: login · password · two-factor recovery codes | — | ______________________________________________________ |
|
|
| S12 | Gmail `felhom.eu@gmail.com`: password · two-factor recovery codes | — | ______________________________________________________ |
|
|
| S3 | Vaultwarden master password — **in your head**; write it here only if you decide to | — | ______________________________________________________ |
|
|
|
|
**Not secret, needed with the keys:**
|
|
- ep0: `167.233.158.164` (Hetzner, `felhom-hetzner`); PBS datastore `felhom-offsite`, namespace `operator`;
|
|
its certificate fingerprint `c6:07:28:3f:5b:7b:5a:41:90:28:d7:ca:4f:37:14:70:56:39:2e:2f:0b:71:e8:06:ca:60:4a:d5:56:5f:3c:fd`.
|
|
- Restore order: `total-loss-of-dooplex.md` (in the restored Gitea, repo `felhom.eu`, `documentation/runbooks/`).
|
|
**Print that page too** — the runbook itself is inside the copy it explains how to open.
|
|
|
|
**Re-print when** a key above is rotated, and once a year.
|