Off-site lock live: Parts D/E/F evidence, ep0 copy runbook, 06/07 facts, register (R-820/R-821/R-342 closed, R-825 opened+closed, R-95/R-822 narrowed, R-823/R-824/R-826/R-827/R-828/R-830 opened; 327 -> 330); hub window-sweep test (test-only)
gates / gates (push) Successful in 41s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 21:21:04 +02:00
parent cdfcc47b15
commit 207ad19746
22 changed files with 370 additions and 15 deletions
@@ -182,7 +182,7 @@ production endpoint exists.
### 3.6 The ep0 datastore has a second copy — decision 70 (2026-10-03)
**[DESIGN]** A nightly PBS pull-sync copies `felhom-offsite` from ep0 to DooPlex's PBS over a read-only token. ep0's server snapshot never covered this volume and Hetzner has no volume snapshots (R-342). The copy is ciphertext per customer. Built per the 2026-10-03 lock brief Part F; the restore route lives in `runbooks/`.
**[DESIGN]** A nightly PBS pull-sync copies `felhom-offsite` from ep0 to DooPlex's PBS over a read-only token. ep0's server snapshot never covered this volume and Hetzner has no volume snapshots (R-342). The copy is ciphertext per customer. **`[FACT]` BUILT 2026-10-03:** ep0 token `root@pam!dooplex-sync` (`DatastoreReader` only — the one change on ep0); ep0's PBS listens on `wg0` only, so DooPlex reaches it through an SSH forward (`felhom-ep0-pbs-tunnel.service`, operator ruling the same day); DooPlex datastore `ep0-copy`, sync daily 05:00 with `remove-vanished false`, verify Saturdays, failures mailed via Resend. First pull 201 s / 12 GB / 4 of 4 snapshots. Restore route: `runbooks/ep0-datastore-copy.md`. Evidence `audits/offsite-lock-build-2026-10-03/partF/`.
## 4. Robustness (production details beyond the spike)
File diff suppressed because one or more lines are too long