Skip to content

Runbooks

Step-by-step procedures for fleet events: key and certificate rotations, CA bootstrap, OpenBao operations, factory resets, identity failover. Each runbook was verified against the systems repo when it migrated in (2026-09) and is maintained as a living document — if a runbook contradicts the repo, the repo wins; fix the runbook.

Two conventions to know:

  • Verify-values are generalized. Runbooks say “the host’s fleet.yaml IP” rather than hard-coding addresses that drift.
  • Some steps are deliberately operator-only. Where a procedure touches key custody or credential locations, the published copy points at the operator’s source note, which preserves the specifics.