v0.289.0: off-site key cannot delete — append-only rclone transport, box sends only its public key (hub registrar), retention only inside a hub window behind the fake-snapshot guard (decisions 68-69, R-820, R-822)
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -155,6 +155,12 @@ backups, monitoring and notifications. All Proxmox/disk operations are delegated
|
||||
action block right; used by the dashboard installed-apps list, the Távoli mentés toggle list
|
||||
and the Visszaállítás restore-to-verify/.fab lists; the backups-apps expander header is
|
||||
ALIGNED to the same grammar (own markup — it carries the toggle). Protected infra stacks
|
||||
**The off-site key cannot delete (v0.289.0, decisions 68–69):** the hub-provisioned tier is reached through an
|
||||
APPEND-ONLY key the hub's registrar pins in the Storage Box sub-account (`rclone serve restic --stdio --append-only`);
|
||||
the box sends only its public key (`offsiteapply.HubRegistrar`) and never sees the sub-account password. Transport is
|
||||
restic `rclone:` over ssh port 23 (`settings.OffboxTarget.Transport = "rclone-pinned"`); the household's own SFTP NAS
|
||||
is unchanged. Retention runs only inside a hub-opened weekly window, behind the fake-snapshot guard
|
||||
(`backup/offbox_window.go`); the orphan move-aside is the hub's; a due abandonment is deferred to the operator.
|
||||
**Apps go off-site by themselves (v0.283.0, decision 50):** a fresh install on a box whose customer has off-site
|
||||
switches the app's off-site copy ON (`settings.DefaultOffboxOnForNewApp`, deploy-done hook); an earlier choice is
|
||||
kept. Older apps: one press on both backup pages (`/backup/offbox/enable-all`, „Nem most" dismisses). The size
|
||||
|
||||
Reference in New Issue
Block a user