provider questions: arm them against the Storage Box / Storage Share conflation (operator-found)
gates / gates (push) Successful in 18s
gates / gates (push) Successful in 18s
The operator noticed the "can I restore specific files from within a backup?" FAQ lives under storage-share, not storage-box, and asked which product it covers. It is Storage SHARE only — a managed Nextcloud — and it never mentions Storage Box. Its own text gives it away: Nextcloud's data cache, a database dump, the konsoleH web interface. The two products document OPPOSITE answers: Storage BOX (ours) "You can download individual files or entire directories as usual" Storage SHARE (not) "we only support restores for the full backup ZFS snapshot" That matters because a web search for the obvious phrasing surfaces the SHARE page and it reads like a definitive NO — so a support agent could answer Question 1 from the wrong page and push R-95 to the top of the register for no reason. Question 1 now names the product, quotes the Storage Box line, and states up front that we know what the Share FAQ says. A warning block at the head of the file tells the reader to check which product any full-snapshot-only answer is about before acting on it. Verified by grep: nothing in this repository ever leaned on the Share claim. The only vendor line cited anywhere is the Storage Box one. R-436 strengthened from the same source the operator supplied: the rclone-over-SSH restic backend is OFFICIALLY DOCUMENTED, not merely advertised in a shell banner -- "we support the restic backend, which is provided by Rclone over SSH". And the same page settles that the docs cannot answer the caveat: neither its Rclone nor its Restic section mentions append-only at all, so nobody need re-read the documentation hoping for it. Unlooked-for corroboration: that page's port-23 command table matches, item for item, the help output measured live on our own sub-account. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LB8FmJaGd2cyjvy6dbEjpM
This commit is contained in:
@@ -16,6 +16,29 @@ one answered and the other dropped.
|
||||
|
||||
---
|
||||
|
||||
## ⚠ READ THIS BEFORE YOU SEND, AND BEFORE YOU BELIEVE AN ANSWER: two Hetzner products, opposite answers
|
||||
|
||||
**Hetzner has two similarly-named storage products and their documentation says OPPOSITE things about
|
||||
restoring a single file. We are a Storage BOX. The answer that says "no" belongs to the other one.**
|
||||
|
||||
| | **Storage Box** — *what we have* | **Storage Share** — *not us* |
|
||||
|---|---|---|
|
||||
| what it is | plain SFTP/SSH storage, sub-accounts, `u629488` | a managed **Nextcloud** instance |
|
||||
| single file out of a snapshot | *"You can download individual files or entire directories as usual"* — `docs.hetzner.com/storage/storage-box/snapshots/` | *"Currently, we only support restores for the full backup ZFS snapshot to a specific point in time"* — `docs.hetzner.com/storage/storage-share/faq/backup-snapshot/` |
|
||||
|
||||
**How to tell the Storage Share page apart at a glance:** it talks about *Nextcloud's data cache*, a
|
||||
*database dump*, and the *konsoleH* web interface, and it never mentions Storage Box.
|
||||
|
||||
**Why this is load-bearing rather than trivia.** A search for "Hetzner restore individual files from
|
||||
snapshot" surfaces the Storage **Share** FAQ, and it reads like a definitive "no". **A support agent
|
||||
answering Question 1 could reasonably reply from that page and give us a wrong answer** — one that
|
||||
would send R-95 to the top of the register for no reason. Question 1 below therefore names the
|
||||
product, quotes the Storage Box line, and asks about the **main account** specifically.
|
||||
**If an answer comes back citing full-snapshot-only, check which product it is about before acting on
|
||||
it.** Caught 2026-09-01 by the operator noticing the URL said `storage-share`.
|
||||
|
||||
---
|
||||
|
||||
## Question 1 — can the MAIN account retrieve individual files from a snapshot?
|
||||
|
||||
**Why it matters, in one line:** if it cannot, the only route back is a whole-box rollback that hits
|
||||
@@ -31,11 +54,19 @@ almost nobody in practice. **This is the question that decides how urgent R-95 i
|
||||
> We can reach `/.zfs/snapshot` from a sub-account, but it lists as empty, and no snapshot name we
|
||||
> try can be entered. We understand sub-accounts may be restricted here.
|
||||
>
|
||||
> Your Storage Box documentation says, under Snapshots: *"You can download individual files or
|
||||
> entire directories as usual."*
|
||||
>
|
||||
> Our question is about the **main account**: from the main account, over SSH or SFTP on port 23,
|
||||
> can we **read or download individual files and directories out of a specific snapshot** — for
|
||||
> example a single directory under one sub-account's home — **without** performing a snapshot
|
||||
> restore of the whole Storage Box?
|
||||
>
|
||||
> To be clear, this question is about a **Storage Box**, not about Storage Share. We are aware the
|
||||
> Storage Share FAQ says only full-snapshot restores are supported; we are asking whether that also
|
||||
> applies to Storage Box, because the Storage Box snapshot documentation appears to say the
|
||||
> opposite.
|
||||
>
|
||||
> If yes, please tell us the exact path we should use and how the snapshot directory is named.
|
||||
>
|
||||
> If no, please confirm that the only way to get data out of a snapshot is the full "restore
|
||||
@@ -63,7 +94,9 @@ disappear.**
|
||||
>
|
||||
> Hello,
|
||||
>
|
||||
> The restricted SSH shell on Storage Box `u629488` (port 23) lists `rclone serve restic --stdio`
|
||||
> Your Storage Box documentation states: *"Restic is natively supported with the SFTP backend. As
|
||||
> another option, we support the restic backend, which is provided by Rclone over SSH."* The
|
||||
> restricted SSH shell on Storage Box `u629488` (port 23) also lists `rclone serve restic --stdio`
|
||||
> among the available server-side backends.
|
||||
>
|
||||
> Our question is about how that command is run on your side: **is `--append-only` enforced by you,
|
||||
@@ -97,5 +130,11 @@ disappear.**
|
||||
and `/.zfs` are different filesystems and `/home/.zfs` does not exist. Question 1 exists because
|
||||
that measurement can only speak for a sub-account.
|
||||
* **R-436** — the `rclone serve restic --stdio` backend and restic's `rclone:` support, both
|
||||
measured. Question 2 is the one caveat that decides whether the lead is real.
|
||||
measured, and since **confirmed as officially supported** by the vendor's own Storage Box access
|
||||
page (*"we support the restic backend, which is provided by Rclone over SSH"*). **That page says
|
||||
nothing at all about append-only**, in either its Rclone or its Restic section — so Question 2 is
|
||||
genuinely unanswered by the documentation and is not a question the docs could have saved us.
|
||||
* **The two-product trap** above, caught 2026-09-01. The Storage Box command table on that same
|
||||
access page also matches, item for item, the `help` output measured live on our own sub-account —
|
||||
independent corroboration that we were reading the right product's surface.
|
||||
* Evidence for both: `documentation/audits/evidence-drill-r95-recovery-2026-09-01/`.
|
||||
|
||||
Reference in New Issue
Block a user