v0.105.0: fork-4 offsite password custody — hand-off + atomicity gate + DR inject + coord
Pairs with agent v0.77.0. StageEscrowSecret pushes the repo password to the agent (POST /escrow/stage-secret) at offsite-enable → EscrowState="pending". Atomicity gate: RunOffboxBackup (scheduler + handler) refuses until EscrowState="escrowed" (operator POST /backup/offbox/confirm-escrow after the escrow ceremony) — no un-recoverable offsite ciphertext can exist. DR: POST /backup/offbox/inject-password pre-places a recovered 64-hex password 0600 (honored by WriteOffboxSecrets' IsNotExist guard; refuses clobber without force). DR recipe gains non-secret offsite_restic coords (DRResticCoord); SFTP key regenerated at DR, not escrowed. New settings.OffboxTarget.EscrowState. Tests + atomicity & inject companion red-proofs green; UI gates pass. NOT yet live-validated (supervised ceremony). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
@@ -36,6 +36,19 @@ type DRRecipeAppHalf struct {
|
||||
RecipeVersion int `json:"recipe_version"`
|
||||
Customer DRCustomer `json:"customer"`
|
||||
Apps []AppRecipe `json:"apps"`
|
||||
// OffsiteRestic (fork-4) is the non-secret location of the offsite restic repo, so DR knows WHERE to
|
||||
// recover from. nil when offsite is not configured. Coordinates ONLY — see DRResticCoord.
|
||||
OffsiteRestic *DRResticCoord `json:"offsite_restic,omitempty"`
|
||||
}
|
||||
|
||||
// DRResticCoord is the offsite restic repo's non-secret coordinates. The repo PASSWORD rides the R-escrow
|
||||
// (IdentityBundle.ResticRepoPassword); the SFTP access key is regenerated at DR (a fresh sub-account key) —
|
||||
// so NEITHER appears here. All field names deliberately clear the _NoSecrets regex (no password/key/token).
|
||||
type DRResticCoord struct {
|
||||
Host string `json:"host"`
|
||||
User string `json:"user"`
|
||||
Port int `json:"port"`
|
||||
RepoPath string `json:"repo_path"`
|
||||
}
|
||||
|
||||
// DRCustomer is the customer identity — public identifiers only.
|
||||
|
||||
Reference in New Issue
Block a user