provider questions: arm them against the Storage Box / Storage Share conflation (operator-found)
gates / gates (push) Successful in 18s

The operator noticed the "can I restore specific files from within a backup?" FAQ lives under
storage-share, not storage-box, and asked which product it covers. It is Storage SHARE only —
a managed Nextcloud — and it never mentions Storage Box. Its own text gives it away: Nextcloud's
data cache, a database dump, the konsoleH web interface.

The two products document OPPOSITE answers:
  Storage BOX   (ours) "You can download individual files or entire directories as usual"
  Storage SHARE (not)  "we only support restores for the full backup ZFS snapshot"

That matters because a web search for the obvious phrasing surfaces the SHARE page and it reads
like a definitive NO — so a support agent could answer Question 1 from the wrong page and push
R-95 to the top of the register for no reason. Question 1 now names the product, quotes the
Storage Box line, and states up front that we know what the Share FAQ says. A warning block at
the head of the file tells the reader to check which product any full-snapshot-only answer is
about before acting on it.

Verified by grep: nothing in this repository ever leaned on the Share claim. The only vendor
line cited anywhere is the Storage Box one.

R-436 strengthened from the same source the operator supplied: the rclone-over-SSH restic
backend is OFFICIALLY DOCUMENTED, not merely advertised in a shell banner --
"we support the restic backend, which is provided by Rclone over SSH". And the same page settles
that the docs cannot answer the caveat: neither its Rclone nor its Restic section mentions
append-only at all, so nobody need re-read the documentation hoping for it. Unlooked-for
corroboration: that page's port-23 command table matches, item for item, the help output
measured live on our own sub-account.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LB8FmJaGd2cyjvy6dbEjpM
This commit is contained in:
2026-09-01 18:59:37 +02:00
parent f380c6d43c
commit 1d59353df4
2 changed files with 43 additions and 4 deletions
@@ -16,6 +16,29 @@ one answered and the other dropped.
---
## ⚠ READ THIS BEFORE YOU SEND, AND BEFORE YOU BELIEVE AN ANSWER: two Hetzner products, opposite answers
**Hetzner has two similarly-named storage products and their documentation says OPPOSITE things about
restoring a single file. We are a Storage BOX. The answer that says "no" belongs to the other one.**
| | **Storage Box** — *what we have* | **Storage Share** — *not us* |
|---|---|---|
| what it is | plain SFTP/SSH storage, sub-accounts, `u629488` | a managed **Nextcloud** instance |
| single file out of a snapshot | *"You can download individual files or entire directories as usual"* — `docs.hetzner.com/storage/storage-box/snapshots/` | *"Currently, we only support restores for the full backup ZFS snapshot to a specific point in time"* — `docs.hetzner.com/storage/storage-share/faq/backup-snapshot/` |
**How to tell the Storage Share page apart at a glance:** it talks about *Nextcloud's data cache*, a
*database dump*, and the *konsoleH* web interface, and it never mentions Storage Box.
**Why this is load-bearing rather than trivia.** A search for "Hetzner restore individual files from
snapshot" surfaces the Storage **Share** FAQ, and it reads like a definitive "no". **A support agent
answering Question 1 could reasonably reply from that page and give us a wrong answer** — one that
would send R-95 to the top of the register for no reason. Question 1 below therefore names the
product, quotes the Storage Box line, and asks about the **main account** specifically.
**If an answer comes back citing full-snapshot-only, check which product it is about before acting on
it.** Caught 2026-09-01 by the operator noticing the URL said `storage-share`.
---
## Question 1 — can the MAIN account retrieve individual files from a snapshot?
**Why it matters, in one line:** if it cannot, the only route back is a whole-box rollback that hits
@@ -31,11 +54,19 @@ almost nobody in practice. **This is the question that decides how urgent R-95 i
> We can reach `/.zfs/snapshot` from a sub-account, but it lists as empty, and no snapshot name we
> try can be entered. We understand sub-accounts may be restricted here.
>
> Your Storage Box documentation says, under Snapshots: *"You can download individual files or
> entire directories as usual."*
>
> Our question is about the **main account**: from the main account, over SSH or SFTP on port 23,
> can we **read or download individual files and directories out of a specific snapshot** — for
> example a single directory under one sub-account's home — **without** performing a snapshot
> restore of the whole Storage Box?
>
> To be clear, this question is about a **Storage Box**, not about Storage Share. We are aware the
> Storage Share FAQ says only full-snapshot restores are supported; we are asking whether that also
> applies to Storage Box, because the Storage Box snapshot documentation appears to say the
> opposite.
>
> If yes, please tell us the exact path we should use and how the snapshot directory is named.
>
> If no, please confirm that the only way to get data out of a snapshot is the full "restore
@@ -63,7 +94,9 @@ disappear.**
>
> Hello,
>
> The restricted SSH shell on Storage Box `u629488` (port 23) lists `rclone serve restic --stdio`
> Your Storage Box documentation states: *"Restic is natively supported with the SFTP backend. As
> another option, we support the restic backend, which is provided by Rclone over SSH."* The
> restricted SSH shell on Storage Box `u629488` (port 23) also lists `rclone serve restic --stdio`
> among the available server-side backends.
>
> Our question is about how that command is run on your side: **is `--append-only` enforced by you,
@@ -97,5 +130,11 @@ disappear.**
and `/.zfs` are different filesystems and `/home/.zfs` does not exist. Question 1 exists because
that measurement can only speak for a sub-account.
* **R-436** — the `rclone serve restic --stdio` backend and restic's `rclone:` support, both
measured. Question 2 is the one caveat that decides whether the lead is real.
measured, and since **confirmed as officially supported** by the vendor's own Storage Box access
page (*"we support the restic backend, which is provided by Rclone over SSH"*). **That page says
nothing at all about append-only**, in either its Rclone or its Restic section — so Question 2 is
genuinely unanswered by the documentation and is not a question the docs could have saved us.
* **The two-product trap** above, caught 2026-09-01. The Storage Box command table on that same
access page also matches, item for item, the `help` output measured live on our own sub-account —
independent corroboration that we were reading the right product's surface.
* Evidence for both: `documentation/audits/evidence-drill-r95-recovery-2026-09-01/`.