# Tier 0/1 recovery card

Print this. Keep one copy near but not inside the equipment area and one secure copy outside the house.

## Direct access

- Router model and local IP:
- Router recovery credential reference:
- Primary switch and port map:
- Primary Wi-Fi node, power location, and local access:
- DNS resolver IPs:
- Mac control-host direct IP:
- Mac local recovery account reference:
- Mac Screen Sharing/SSH path:
- Server direct IPs and console paths:
- Overlay/VPN recovery path:
- Labeled Ethernet adapter/cable location:

### Direct-link static-address procedure

- Control-Mac adapter/interface and MAC:
- Control-Mac recovery IPv4/prefix:
- Server recovery interface and MAC:
- Server recovery IPv4/prefix:
- Reserved collision-free recovery subnet:
- Gateway: **none**
- DNS: **none**
- Server firewall source/address rule:
- SSH host-key fingerprint:
- Exact macOS Manual TCP/IP steps:
- Exact server configuration reference:
- Test with router, switch, Wi-Fi, DHCP, DNS, WAN, and VPN unavailable:
- Last tested date:
- Test outcome:
- Evidence reference:
- Steps to restore the Mac adapter to ordinary DHCP afterward:

## Power

- UPS location/model:
- UPS USB/network controller:
- UPS/PDU outlet map:
- ONT/modem outlet:
- Router outlet:
- Required switch outlet:
- Required access-point outlet:
- DNS outlet:
- Mac control-host outlet:
- Storage outlet:
- Broadband provider/support reference:

## Fault order

1. Wi-Fi works but names fail: use direct IP and diagnose DNS.
2. Wi-Fi or DHCP fails: cable to the documented device or use the direct-link path.
3. WAN fails: keep Tier 0 local; inspect ONT/modem, router, switch, AP in order.
4. Remote entry fails: distinguish vendor/control-plane failure from the home path; use the independent route or local helper.
5. Mac is off: follow the tested cold-boot/FileVault procedure.
6. Storage is unhealthy: stop writes. Do not repair or replace anything until the disk is identified by serial and bay and backup state is known.

Never print an unprotected passphrase or recovery key on this card. If the owner's physical threat model permits a sealed physical secret copy, store that copy separately. On the ordinary card, print only protected references the owner can resolve without the failed homelab.
