R-729 + R-545: the household can remove its own off-site target („Távoli mentési cél törlése")
POST /backup/offbox/clear (reveal-then-confirm) forgets the target and deletes ssh_key + known_hosts; nothing on the target is touched. repo_password is kept whenever anything could depend on it (hub sealed package — the R-241 rule; escrowed; a successful run; snapshots) and deleted only otherwise. Refused for the Felhom tier (rclone-pinned), while the single-flight is held, and while an abandonment countdown runs. i18n parity fixtures of backups_remote gain the additive block only. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -161,6 +161,11 @@ backups, monitoring and notifications. All Proxmox/disk operations are delegated
|
||||
restic `rclone:` over ssh port 23 (`settings.OffboxTarget.Transport = "rclone-pinned"`); the household's own SFTP NAS
|
||||
is unchanged. Retention runs only inside a hub-opened weekly window, behind the fake-snapshot guard
|
||||
(`backup/offbox_window.go`; v0.290.0: a young snapshot superseded the same day is skipped, not refused); the orphan move-aside is the hub's; a due abandonment is handed to the hub, which deletes the set-aside copy after a 7-day wait unless cancelled (decision 74).
|
||||
**The household can remove its own target (R-729/R-545):** „Távoli mentési cél törlése" on /backups/remote
|
||||
(`/backup/offbox/clear`, reveal-then-confirm, `backup/offbox_clear.go`) forgets the target and deletes `ssh_key` +
|
||||
`known_hosts`; nothing on the target is touched. `repo_password` is deleted only when nothing depends on it (no hub
|
||||
sealed package, not escrowed, no successful run, no snapshots). Refused for the Felhom tier (`rclone-pinned`), while a
|
||||
backup operation holds the single-flight, and while an abandonment countdown runs.
|
||||
**Apps go off-site by themselves (v0.283.0, decision 50):** a fresh install on a box whose customer has off-site
|
||||
switches the app's off-site copy ON (`settings.DefaultOffboxOnForNewApp`, deploy-done hook); an earlier choice is
|
||||
kept. Older apps: one press on both backup pages (`/backup/offbox/enable-all`, „Nem most" dismisses). The size
|
||||
|
||||
Reference in New Issue
Block a user