Disaster Recovery Checklist
# Global Architecture and Request Flow
Purpose
##This Purposechecklist provides a concise response plan for major Bytek homelab failures.
The Bytekobjective homelabis providesto privatelyrestore hostedcore identity,infrastructure collaboration,before documentation, monitoring, and project-managementapplication services.
TheAvoid environmentmaking several unrelated configuration changes simultaneously.
Initial Assessment
Before changing configuration:
Do not rely only on browser errors.
Test direct IPs and backend ports where possible.
Complete Proxmox Host Failure
pveproxy.
Confirm TCP 8006.
Use root@pam.
If the system NVMe failed:
user-data.
Remount pve-backup.
Restore VMs and LXCs.
Verify local authentication.
Restore the Authentik Proxmox realm.
Test OIDC only after local access works.
Pi-hole Failure
192.168.2.254.
Confirm the Pi-hole LXC is 192.168.2.65.
Confirm TCP port 53.
Confirm UDP port 53.
Confirm local DNS records.
Confirm public upstream resolution.
Review Pi-hole logs.
Restore from backup if necessary.
During the outage, access services using private IP addresses where supported.
Do not make Pi-hole recovery depend on Proxmox VE and follows these design principles:Authentik.
-
WireGuard majorFailure
192.168.2.64.
Confirm the WireGuard interface.
Confirm the VPS If the keys are lost or compromised, rotate the affected peer key pair and update the opposite peer.
Public VPS Failure
38.29.213.101.
Confirm SSH service.
Confirm firewall rules.
Confirm WireGuard.
Confirm TCP 443.
Confirm forwarding to the home LAN access policies.-should continue through Pi-hole providesand LANTraefik DNS,while splitthe DNS,VPS is unavailable.
Traefik Failure
192.168.2.182.
Confirm Docker.
Confirm the Traefik container.
Confirm TCP 443.
Confirm container DNS.
Review Traefik logs.
Check recently changed dynamic YAML.
Search for tabs.
Test the direct application backend.
Restore the previous dynamic file if necessary.
Confirm certificate state.
Do not delete acme.json.
If all applications fail simultaneously but direct backends work, prioritize Traefik, Pi-hole, and DHCPcertificates.
Authentik applicationsFailure
root@pam.
Confirm the Authentik VM owns 192.168.2.162.
Confirm Docker.
Confirm PostgreSQL.
Confirm Redis.
Confirm Authentik server.
Confirm Authentik worker.
Test direct readiness.
Test routed readiness.
Review Authentik logs.
Review Traefik.
Restore Authentik from backup if necessary.
Use application break-glass access during recovery:
root@pam
Nextcloud
Local administrator
BookStack
Switch to standard authentication
Uptime Kuma
Restore local authentication
Traefik
Basic Auth or restore known-good route
Nextcloud Failure
192.168.2.100.
Confirm the 500 GB data disk.
Confirm /mnt/nextcloud-data.
Confirm free disk space.
Confirm Docker.
Open AIO management by private IP.
Confirm PostgreSQL.
Confirm Redis.
Confirm Nextcloud.
Confirm Apache.
Confirm TCP 11000.
Confirm Traefik.
Use the local administrator if OIDC fails.
Restore both virtual disks if recovery is required.
Do not start normal Nextcloud operation if the data mount is missing.
Vikunja Failure
192.168.2.121.
Confirm Docker.
Confirm PostgreSQL.
Confirm the Vikunja container.
Confirm TCP 3456.
Test /health.
Run the Vikunja doctor command.
Check attachment permissions.
Check Traefik.
Check Authentik after application health is restored.
BookStack Failure
APP_URL.
Confirm the application key.
Confirm Traefik.
Switch to standard authentication if OIDC blocks access.
Restore the VM if application data is damaged.
The application key and database must be restored together.
Uptime Kuma Failure
192.168.2.115.
Confirm Docker.
Confirm the Uptime Kuma container.
Confirm persistent data.
Confirm embedded database health.
Confirm container DNS.
Test TCP 3001.
Confirm Traefik.
Confirm Authentik Proxy Provider.
Restore local authentication if proxy access fails.
The absence of monitoring does not necessarily mean every monitored system is down.
Backup HDD Failure
/dev/sda.
Confirm /dev/sda1.
Confirm filesystem UUID.
Confirm /etc/fstab.
Confirm /mnt/pve/pve-backup.
Confirm Proxmox storage state.
Review SMART health.
Stop scheduled backups if the filesystem is unsafe.
Replace the backup HDD if necessary.
Create a Do not allow backups areto write into an unmounted directory on the root filesystem.
User-Data NVMe Failure
Expected impact includes Nextcloud user data and any other data disks stored on user-data.
Response:
lvm1 volume group.
Confirm the data thin pool.
Identify the latest valid backups.
Replace the failed storage if required.
Recreate the user-data storage.
Restore affected data disks.
Validate guests offline.
Return services to production.
Authentication Lockout
Proxmox
Use root@pam.
Nextcloud
Use the local administrator and direct local-login path.
BookStack
Set AUTH_METHOD to standard, recreate the BookStack container, and use the local administrator.
Uptime Kuma
Restore the direct Traefik route, allow temporary private access, and re-enable local authentication.
Traefik Dashboard
Restore the previous dashboard YAML or use retained Basic Auth.
Authentik
Use the local Authentik administrator or restore Authentik from backup.
Restore Validation
Before replacing production with a dedicatedrestored guest:
Emergency Credentials
The password manager must contain:
root@pam password.
Authentik administrator credentials.
Nextcloud local administrator credentials.
BookStack break-glass administrator credentials.
Uptime Kuma administrator credentials.
Traefik Basic Auth credentials.
VPS SSH private key.
Home-infrastructure SSH keys.
WireGuard configuration and recovery keys.
WHC cPanel credentials.
SMTP credentials.
Database recovery credentials where required.
Do not store the actual credential values in BookStack.
BookStack should record only the credential purpose and storage location.
Recovery Priority
Restore services in this order:
Incident Record
After a significant incident, record:
Do not include passwords, tokens, private keys, or session cookies.
Final Recovery Checklist
Document Control
---
##VE
```textInternetstorage:
pve-backup
Backup mount:
/mnt/pve/pve-backup
Not configured
Last verified:
Last disaster-recovery
exercise: YYYY-MM-DD
restore test:
authentication-recovery test:
YYYY-MM-DD Last
backup-HDD review:
YYYY-MM-DD Known
One Proxmox
one local
backup disk,
offsite recovery