Files
obsidian-vault/200 projects/220 Web Host Migration/Migration Work Log.md

3.6 KiB

created, modified, type, client, project, status, priority, tags, aliases, id
created modified type client project status priority tags aliases id
2026-08-28 2026-08-28 log sam web-host-migration active 1
migration
log
migration-work-log
work-log
1848129023-LOG

Migration Work Log

Central log of what has been done across the migration phases. Update this as work completes. Each entry: date · phase · what · evidence.

Phase legend

  • P0 Pre-flight · P1 AWS offsite · P2 Email · P3 Local infra · P4 CMS (separate) · P5 Decommission

2026-08-28

Phase What was done Notes/Evidence
P0 Verified no AWS CLI / rclone / creds on .13 (clean slate) command -v aws empty; rclone empty on .13
P0 Verified existing backup stack on .13 Borg 1.4.3 in backup.nix (services.borgbackup.jobs.*, timers 04:00/05:00/06:00, BORG_RSH wrapper for SSH to .35)
P0 Verified .13 containers wherewoof-admin(:3031), wherewoof-minio(:9010), wherewoof-db(:5434), Garage(:3900/3902)+portal(:8500)
P0 Confirmed external exposure static IP port-forward 80/443 → Caddy .35; where-woof.com→192.168.20.13:3020
P1 Decision: AWS-only, S3→Glacier DA, ap-southeast-2 (Sydney), IAM least-privilege Awaiting AWS account signup to proceed
— Created per-phase plan notes (P0, P1, P2, P3, P5) + this log Obsidian 220 Web Host Migration/

2026-08-28 (Phase 1 — build begun)

Phase What was done Evidence
P0 Machine confirmation — assistant runs on .27 (sam-4screen-desktop); .13 reachable via sam@192.168.20.13 hostname sam-4screen-desktop = .27
P1 AWS account ready; IAM user backup-offsite created (programmatic, least-priv) —
P1 Credentials verified via AWS STS (get-caller-identity) Account 648879824522, user backup-offsite, region ap-southeast-2
P1 Credentials stored local-only (aws-credentials.local 0600, .27) + copied to .13 (~/.aws-credentials.local.new 0600). Not in Obsidian. —
P1 Verified .13 has no aws-cli/rclone; will use one-off nix-shell awscli2 for imperative steps until backup.nix updated verified
P1 STS key check OK (Account 648879824522, user backup-offsite); created env-helper ~/.aws-offsite-env.sh on .13 (0600, sources creds from file, no secrets echoed) verified
P1 MFA: root MFA enabled in console; Ente Auth as authenticator (phone). Ente recovery keyphrase stored in local aws-credentials.local (0600), NOT Obsidian —
P1 Blocked on expanded IAM policy attach (bucket-mgmt + object actions scoped to sam-offsite-backup) before bucket+lifecycle can be created awaiting user
P1 Bucket sam-offsite-backup created (ap-southeast-2, ACLs disabled, all public-access blocked, versioning enabled) — created via console as root; IAM backup-offsite kept object-only created
P1 Object pipeline verified on .13: PUT/LIST/GET/DELETE probe to s3://sam-offsite-backup/test/ all succeeded via backup-offsite probe-write, content readback OK
P1 TODO: add lifecycle rule (S3→Glacier Flexible@30d→Glacier Deep Archive@90d) — IAM backup-offsite lacks lifecycle perm, so rule will be created via console (root) pending

Pending next action

  • Build: create bucket sam-offsite-backup + lifecycle (S3→Glacier Flexible@30d→Glacier DA@90d), then wire local Borg/rclone→S3 on .13, seed, test restore.
  • Security: enable root MFA; consider rotating access key after seeding (it was pasted in chat).

Linked from Migration Plan — InMotion to Local + AWS Offsite.