Incident response
Incident entry
Section titled “Incident entry”- Stop non-essential deployments.
- Capture status and drift before any changes.
- Check whether tunnel health checks are failing in active namespace set.
- If policy is incorrect, keep configuration changes in a branch and do not deploy.
Fast safe response
Section titled “Fast safe response”hubctl status --state-dir /var/lib/vpn-hubhubctl validate --config /etc/vpn-hub/hub.yaml- If a bad deploy is active, use confirm timeout to let rollback trigger or apply rollback command.
SSH recovery
Section titled “SSH recovery”When bot is unavailable, SSH recovery still supports:
- restart agent
- inspect logs and unit status
- apply known-good config through staging directory and re-run install
Do not change private keys and tunnel private components manually.