R-901: a deleted customer's audit rows go 1 year after the deletion (hub, unreleased); ep0-copy removal job written, not installed (decision 181); both times in the privacy draft
gates / gates (push) Successful in 4m9s
gates / gates (push) Successful in 4m9s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -117,7 +117,7 @@ A központi rendszer (`hub.felhom.eu`) a Felhom saját szerverén fut (k3s fürt
|
||||
| Alkalmazásnaplókból kiszűrt hibaüzenetek, előtte-utána 5 sor, kitakarással | hibaelhárítás | az utolsó előfordulás után **30 nap** <!-- source: hub/internal/store/telemetry.go:35 (±5 redacted lines); hub/cmd/hub/main.go:1027 (PruneStaleIssues 30 days) --> |
|
||||
| Alkalmazásnapló-részlet, csak külön kérésre, kitakarással | hibaelhárítás | alkalmazásonként a **legutóbbi 2**, időkorlát nélkül; az ügyfél törlésekor törlődik <!-- source: felhom-controller/controller/internal/report/types.go:39-41 ("on-demand… Redacted + capped"); hub/internal/store/logtail.go:74-82 (keep newest 2 per customer+app); hub/internal/store/customer_delete.go:57-58 (purged at delete) --> |
|
||||
| Diagnosztikai naplócsomag, csak külön kérésre | hibaelhárítás | **72 óra** <!-- source: hub/internal/store/logbundle.go:28-29 (logBundleTTL = 72h), :234 --> |
|
||||
| Kiküldött értesítések naplója (esemény, szöveg, kézbesítés állapota) | elszámolhatóság | **nincs törlési idő; az ügyfél törlése után is megmarad** — lásd 11. pont <!-- source: hub/internal/store/store.go:147-156 (notification_log columns); no DELETE FROM notification_log anywhere in hub/internal/store (grep); hub/internal/store/customer_delete.go:23-25 ("deliberately SURVIVES … notification_log") --> |
|
||||
| Kiküldött értesítések naplója (esemény, szöveg, kézbesítés állapota) | elszámolhatóság | az ügyfél törlése után **1 évig**, majd törlődik (az eseményekkel együtt); amíg az ügyfél aktív: [[ELLENŐRIZNI — megőrzési idő nincs meghatározva]] <!-- source: operator ruling 2026-10-08 09:04, 09-update-architecture.md §3 decision 181; hub/internal/store/deleted_customer_audit.go (PruneDeletedCustomerAudit, daily in pruneAll; on hub main 2026-10-08, live from the next hub release) --> <!-- source: hub/internal/store/store.go:147-156 (notification_log columns); no DELETE FROM notification_log anywhere in hub/internal/store (grep); hub/internal/store/customer_delete.go:23-25 ("deliberately SURVIVES … notification_log") --> |
|
||||
| Az ügyfél-visszaállítás és a szervertörlés naplója | elszámolhatóság | **nincs törlési idő** <!-- source: hub/internal/store/store.go:734 ("NEVER pruned (audit outlives every lifecycle tier)"); customer_delete.go:25 --> |
|
||||
| **A mentés titkosító kulcsa, a háztartás helyreállító kódjával lezárva** („kulcsletét") | a mentés visszaállíthatósága gépcsere után | a szerver / ügyfél törléséig; a lecserélt régi kulcsok is megmaradnak, hogy a régi mentések nyithatók maradjanak <!-- source: hub/internal/store/store.go:400-411 (host_escrow: "OPAQUE … NEVER decrypts"), :413-446 (host_escrow_superseded; "NO pruning" at :418); store.go:4122 (PurgeSupersededEscrowForCustomer); documentation/architecture/00-capability-map.md:97 --> |
|
||||
| A szerver vészhelyzeti konzoljelszava, titkosítva tárolva | üzemeltetés, hibaelhárítás | a szerver törléséig <!-- source: hub/internal/store/store.go:552-564 (host_recovery, CREATE at :558); documentation/architecture/05-hub-architecture.md:441-443 (sealed AES-256-GCM) --> |
|
||||
@@ -149,7 +149,7 @@ nem tudja elolvasni (a kulcsot lásd az 5. pont „kulcsletét" sorában).
|
||||
|---|---|---|---|
|
||||
| Alkalmazásonkénti fájlmentés | **Hetzner Storage Box**, helyszínkód `fsn1`, ország: [[ELLENŐRIZNI]] | alkalmazásadatok, adatbázisok, megosztások | 7 napi, 4 heti, 6 havi példány; ügyfél-visszaállításkor (RESET) törlődik. A tárhely saját napi pillanatképeinek ideje: [[ELLENŐRIZNI]] |
|
||||
| Teljes szervermentés | **„ep0"** távoli mentőszerver, Hetzner Cloud, **Nürnberg (Németország)** | a teljes ügyfélkonténer | a legutóbbi 2 heti példány; az ügyfél törlésekor törlődik |
|
||||
| Az ep0 másolata | a Felhom saját szerverén, ország: [[ELLENŐRIZNI]] | a fenti, továbbra is titkosítva | 8 heti példány — **a törlés után is**, lásd 11. pont |
|
||||
| Az ep0 másolata | a Felhom saját szerverén, ország: [[ELLENŐRIZNI]] | a fenti, továbbra is titkosítva | 8 heti példány; az ügyfél törlése után **legfeljebb 30 napon belül** törlődik <!-- source: operator ruling 2026-10-08 09:04, 09 §3 decision 181; scripts/ep0-copy-gc/ (written 2026-10-08, NOT installed yet — until it runs this line is not true; runbooks/ep0-datastore-copy.md) --> |
|
||||
|
||||
<!-- source (row 1): documentation/architecture/07-backup-architecture.md:377 (Tier-3: Hetzner Storage Box over SFTP; --keep-daily 7 --keep-weekly 4 --keep-monthly 6); manifests/hub.yaml:224-226 (HETZNER_LOCATION "fsn1"); hub/cmd/hub/main.go:386 (default fsn1); documentation/audits/VALIDATION-offsite-provisioning-e2e-2026-07-09.md:6 (pool box BX11 fsn1); documentation/architecture/07-backup-architecture.md:258-266 (RESET purges the repository); hub/internal/monitor/offsite.go:300, :317 (daily Storage Box snapshots read-only) -->
|
||||
<!-- source (row 2): documentation/runbooks/RUNBOOK-ep0-datastore-volume-2026-07-27.md:6 ("Hetzner CX33 … Nuremberg"); documentation/architecture/07-backup-architecture.md:379 (keep-last 2, server-side prune on ep0); documentation/architecture/05-hub-architecture.md:296 (RESET / customer delete: deprovisioned — namespace, every backup group AND token) -->
|
||||
@@ -231,10 +231,11 @@ bírósági jogérvényesítés: [[ÜGYVÉD TÖLTI KI]].
|
||||
Resend, a Cloudflare és a Google adatfeldolgozóként kezeli. Javasolt új szöveg:
|
||||
`DRAFT-kapcsolat-hozzajarulas.md`.
|
||||
<!-- source: website/kapcsolat.html:122-128 -->
|
||||
5. **Törlés után megmaradó adatok.** A kiküldött értesítések naplója nem törlődik soha; a teljes
|
||||
szervermentés Felhom-oldali másolata a törlés után is megtartja az utolsó 8 heti példányt, és
|
||||
egyetlen dokumentum sem mondja, mikor törlődnek. Ezt a tájékoztató csak akkor ígérheti
|
||||
másképp, ha a rendszer változik.
|
||||
5. **Törlés után megmaradó adatok — DÖNTÉS 2026-10-08 (09:04):** az értesítési napló és az események a törlés után
|
||||
1 évig maradnak, majd törlődnek (a hub következő kiadásától); a teljes szervermentés Felhom-oldali másolata a
|
||||
törlés után legfeljebb 30 napon belül törlődik — **ez a feladat 2026-10-08-án csak meg van írva, nincs
|
||||
bekapcsolva**; a közzététel előtt ellenőrizni kell, hogy fut. Az aktív ügyfél értesítési naplójára továbbra sincs
|
||||
megőrzési idő.
|
||||
<!-- source: hub/internal/store/customer_delete.go:23-25; documentation/runbooks/ep0-datastore-copy.md:15-17 -->
|
||||
|
||||
## 12. Az ügyvédnek ellenőrizni (R-802) — és ahol a vázlat találgatott
|
||||
|
||||
@@ -77,6 +77,27 @@ Provision a new ep0 (06 §5), then on it add DooPlex as a remote and run
|
||||
|
||||
Do **not** prune the copy tighter than decision 71 (8 weekly copies); never tighter than ep0's own retention.
|
||||
|
||||
## Removing a deleted customer's copy (R-901, `09` §3 decision 181) — WRITTEN 2026-10-08, NOT INSTALLED
|
||||
|
||||
The sync keeps what ep0 removed (`remove-vanished false`), so a deleted customer's namespace stayed here for ever.
|
||||
Ruling: removed **within 30 days**. The job `scripts/ep0-copy-gc/felhom-ep0-copy-gc` (tests beside it) runs daily at
|
||||
08:00: a top-level namespace in the copy that ep0 no longer lists is remembered with the day it was first seen absent;
|
||||
after **7 days** absent it is deleted from the copy (`proxmox-backup-client namespace delete <ns> --delete-groups true`);
|
||||
one that reappears is forgotten; `operator` is never deleted. If ep0's list cannot be read, or reads empty, it does
|
||||
nothing. Without `--apply` it only prints. Worst case: ≤ 1 day to notice + 7 days grace + 1 day = inside 30 days.
|
||||
|
||||
**Not installed. To install (needs the operator's word — it is a change on DooPlex and it deletes data):**
|
||||
1. Two tokens, secrets in root-only files under `/etc/felhom/ep0-copy-gc/` (0600), never printed:
|
||||
- `ep0-reader.secret` — the existing ep0 read token `root@pam!dooplex-sync` (its secret is in `remote.cfg`, base64);
|
||||
`ep0.fingerprint` — ep0's pinned certificate fingerprint (also in `remote.cfg`).
|
||||
- `local-gc.secret` — a NEW local token: `proxmox-backup-manager user generate-token root@pam ep0-copy-gc`, then
|
||||
`proxmox-backup-manager acl update /datastore/ep0-copy DatastoreAdmin --auth-id 'root@pam!ep0-copy-gc'`.
|
||||
2. `install -m 755 scripts/ep0-copy-gc/felhom-ep0-copy-gc /usr/local/sbin/`; the `.service` and `.timer` into
|
||||
`/etc/systemd/system/`; `systemctl daemon-reload`.
|
||||
3. **First run by hand, DRY**: `sudo /usr/local/sbin/felhom-ep0-copy-gc` — read which namespaces it would remove; then
|
||||
`systemctl enable --now felhom-ep0-copy-gc.timer`.
|
||||
4. The chunks are freed by the Sunday 08:30 garbage collection.
|
||||
|
||||
## Remove
|
||||
|
||||
`sudo proxmox-backup-manager sync-job remove ep0-felhom-offsite; … verify-job remove verify-ep0-copy; … prune-job remove prune-ep0-copy;`
|
||||
|
||||
Reference in New Issue
Block a user