Skip to content

ADR-001: Ginnungagap Connectivity

Project: Ginnungagap — Offsite Backup & Disaster Recovery

Decision status: Accepted

Implementation status: Deferred

Original design: VLAN 700, superseded before deployment

OnyxNet requires a future offsite backup solution that can protect two categories of data:

  • TrueNAS SCALE datasets
  • Proxmox virtual machine and LXC backups

The intended destination is a dedicated backup NAS hosted at a geographically separate location.

An early design considered dedicated site-to-site networking infrastructure, including:

  • VLAN 700, named Ginnungagap
  • A proposed 10.0.10.0/31 transit subnet
  • Additional remote routing and switching equipment
  • Encrypted connectivity between sites

VLAN 700 was a proposed network segment, not a VPN by itself. The original concept also required a method of establishing cross-site connectivity.

Establish a routed connection between the two locations using dedicated networking infrastructure and an encrypted site-to-site tunnel.

Advantages

  • Greater control over routing and network boundaries
  • Opportunity to explore site-to-site network engineering
  • Flexibility for future cross-site services

Disadvantages

  • Additional equipment expenses under the original plan
  • More remote components to configure and maintain
  • Greater operational complexity
  • More potential failure points

Option B: Host-to-host Tailscale connectivity

Section titled “Option B: Host-to-host Tailscale connectivity”

Use Tailscale on the backup endpoints to establish encrypted connectivity over the existing Internet connections.

Advantages

  • No additional dedicated remote routing equipment required for the intended backup use case
  • Simplified deployment and ongoing management
  • NAT traversal capabilities
  • Access can be restricted to designated backup hosts and services

Trade-offs

  • Reliance on Tailscale’s coordination infrastructure
  • Direct connectivity is not guaranteed in every network environment; relaying may sometimes be necessary
  • Endpoint identity, authentication, access control, and availability still require careful management

Use Tailscale as the connectivity method for the future Ginnungagap offsite backup system.

The original VLAN 700 and point-to-point transit design will not be implemented.

The backup NAS is planned to run TrueNAS SCALE and support:

  1. ZFS snapshot replication for TrueNAS datasets.
  2. A suitable Proxmox backup replication mechanism, potentially involving a remote Proxmox Backup Server virtual machine.

Detailed implementation and validation are deferred.

The primary requirement is secure, maintainable connectivity between designated backup endpoints.

A more elaborate routed network offered flexibility but also added cost and operational complexity beyond the current requirements.

Tailscale was selected because it better fits the project’s limited budget and intended scope.

  • VLAN 700 remains documented but is not deployed.
  • The six existing operational VLANs are unchanged.
  • The backup appliance can eventually use existing Internet infrastructure at the remote site.
  • Future implementation must validate data security, access restrictions, backup integrity, connectivity, monitoring, and successful restoration.
  • The project remains deferred until funding permits.

A technically sophisticated solution is not necessarily the most appropriate solution.

Good architecture involves selecting the design that satisfies real requirements while balancing security, cost, complexity, maintainability, and operational risk.