Runbooks
Step-by-step procedures for fleet events: key and certificate rotations, CA bootstrap, OpenBao operations, factory resets, identity failover. Each runbook was verified against the systems repo when it migrated in (2026-09) and is maintained as a living document — if a runbook contradicts the repo, the repo wins; fix the runbook.
Two conventions to know:
- Verify-values are generalized. Runbooks say “the host’s
fleet.yamlIP” rather than hard-coding addresses that drift. - Some steps are deliberately operator-only. Where a procedure touches key custody or credential locations, the published copy points at the operator’s source note, which preserves the specifics.