R-901: a deleted customer's audit rows go 1 year after the deletion (hub, unreleased); ep0-copy removal job written, not installed (decision 181); both times in the privacy draft
gates / gates (push) Successful in 4m9s
gates / gates (push) Successful in 4m9s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -77,6 +77,27 @@ Provision a new ep0 (06 §5), then on it add DooPlex as a remote and run
|
||||
|
||||
Do **not** prune the copy tighter than decision 71 (8 weekly copies); never tighter than ep0's own retention.
|
||||
|
||||
## Removing a deleted customer's copy (R-901, `09` §3 decision 181) — WRITTEN 2026-10-08, NOT INSTALLED
|
||||
|
||||
The sync keeps what ep0 removed (`remove-vanished false`), so a deleted customer's namespace stayed here for ever.
|
||||
Ruling: removed **within 30 days**. The job `scripts/ep0-copy-gc/felhom-ep0-copy-gc` (tests beside it) runs daily at
|
||||
08:00: a top-level namespace in the copy that ep0 no longer lists is remembered with the day it was first seen absent;
|
||||
after **7 days** absent it is deleted from the copy (`proxmox-backup-client namespace delete <ns> --delete-groups true`);
|
||||
one that reappears is forgotten; `operator` is never deleted. If ep0's list cannot be read, or reads empty, it does
|
||||
nothing. Without `--apply` it only prints. Worst case: ≤ 1 day to notice + 7 days grace + 1 day = inside 30 days.
|
||||
|
||||
**Not installed. To install (needs the operator's word — it is a change on DooPlex and it deletes data):**
|
||||
1. Two tokens, secrets in root-only files under `/etc/felhom/ep0-copy-gc/` (0600), never printed:
|
||||
- `ep0-reader.secret` — the existing ep0 read token `root@pam!dooplex-sync` (its secret is in `remote.cfg`, base64);
|
||||
`ep0.fingerprint` — ep0's pinned certificate fingerprint (also in `remote.cfg`).
|
||||
- `local-gc.secret` — a NEW local token: `proxmox-backup-manager user generate-token root@pam ep0-copy-gc`, then
|
||||
`proxmox-backup-manager acl update /datastore/ep0-copy DatastoreAdmin --auth-id 'root@pam!ep0-copy-gc'`.
|
||||
2. `install -m 755 scripts/ep0-copy-gc/felhom-ep0-copy-gc /usr/local/sbin/`; the `.service` and `.timer` into
|
||||
`/etc/systemd/system/`; `systemctl daemon-reload`.
|
||||
3. **First run by hand, DRY**: `sudo /usr/local/sbin/felhom-ep0-copy-gc` — read which namespaces it would remove; then
|
||||
`systemctl enable --now felhom-ep0-copy-gc.timer`.
|
||||
4. The chunks are freed by the Sunday 08:30 garbage collection.
|
||||
|
||||
## Remove
|
||||
|
||||
`sudo proxmox-backup-manager sync-job remove ep0-felhom-offsite; … verify-job remove verify-ep0-copy; … prune-job remove prune-ep0-copy;`
|
||||
|
||||
Reference in New Issue
Block a user