RMU build — Gen-1.5
Process for building a new Remote Management Unit to convert a Gen-1 site into a Gen-1.5 site — the staged path that adds remote access and tooling to the original Genesis hardware.
This guide describes the process for building a new Remote Management Unit (RMU) that converts a Gen-1 site into a Gen-1.5 site. It mirrors how DFINITY monitors its own ICR sites using equipment that is already standard in most Gen-1.a installations.
This page is the table of contents. The detailed procedures live in the linked sub-runbooks below — start with Prerequisites and work through each section in order. Completing everything up through V. Best Practices gives you remote access to the RMU and the ability to add additional services via Teleport. The Best Practices section adds services that significantly improve the operator experience, such as updating firmware on every server remotely.
[!WARNING] This guide provides only the foundational steps for setting up a Gen-1.5 RMU. It does not encompass comprehensive security hardening, nor does it address ongoing system maintenance. Responsibility for a secure and well-maintained environment rests with each node provider.
I. Prerequisites
Cover the prerequisites before any of the build steps below — see RMU Build: Prerequisites.
II. Proxmox
Once Proxmox is installed and reachable (step II.A), the rest can be done remotely. See RMU Build: Proxmox Setup.
- A. Install Proxmox
- B. Update Proxmox
- C. Download CT templates
- D. Download ISO images
- E. Add LAN network device
III. Teleport
This service provides secure remote access to all of the services installed on your RMU. See RMU Build: Teleport Setup.
- A. Create Teleport CT
- B. Install Teleport software
- C. Share RMU services via Teleport
- D. Teleport notes
IV. MaaS (Metal as a Service)
- A. Create Proxmox CT
- B. Install MaaS software via APT
- C. Share services via Teleport
- D. Initial configuration of MaaS server
- E. Configure DHCP subnet on MaaS
V. Best Practices
See RMU Build: Best Practices and Reference.
- Recommended — A. Proxmox security
- Optional — B. Install RACADM tool on RMU (Dell nodes)
- Recommended — C. Dell OpenManage Enterprise (OME) (Dell nodes)
- Recommended — D. Update firmware on SuperMicro nodes
- Recommended — E. Enable remote access to server console (Dell nodes)
- Recommended — F. Enable GUI access to OPNsense devices
VI. Reference information
These reference tables live alongside the best-practices runbook.
Related
- Node Provider Documentation — the parent index for the role.
- Node Provider Machine Hardware Guide — the hardware that lives behind the RMU.
- Node Deployment Guide (Gen-1, with HSM) — the IC-OS install path for the Gen-1 fleet this RMU manages.