Off-site lock live: Parts D/E/F evidence, ep0 copy runbook, 06/07 facts, register (R-820/R-821/R-342 closed, R-825 opened+closed, R-95/R-822 narrowed, R-823/R-824/R-826/R-827/R-828/R-830 opened; 327 -> 330); hub window-sweep test (test-only)
gates / gates (push) Successful in 41s
gates / gates (push) Successful in 41s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -26,6 +26,19 @@
|
||||
|
||||
---
|
||||
|
||||
## 2026-10-03 (evening) — the off-site lock built (hub v0.127.0, controller v0.289.0/0.289.1, decisions 68–70)
|
||||
|
||||
> Evidence: `audits/offsite-lock-build-2026-10-03/`.
|
||||
|
||||
| Row | What | Closed | Evidence |
|
||||
|---|---|---|---|
|
||||
| **R-820** | **A box could obtain its sub-account password at will (the hub's self-heal re-armed it; the box consumed it) — and that password removes any append-only pin.** Fixed: the box sends only its PUBLIC key; the hub (key registrar) writes it pinned; `consume-password` answers 410. Measured live: demo-hp's own API key gets `410 gone`, no password. **Reasoning kept: a pinned key protects nothing while any route can rewrite `authorized_keys` — the hub is now that file's only writer, and it reads every file daily.** | CLOSED 2026-10-03 — FIXED hub v0.127.0 + controller v0.289.0/0.289.1, proven live on both demo boxes | `partD/no-password-for-box.txt`, `partB/red-proofs-hub.txt`; hub `internal/offsitekeys` |
|
||||
| **R-821** | **The hub DB held every sub-account password in the clear.** Fixed: AES-256-GCM at rest under `OFFSITE_SECRET_KEY` (Secret/offsite-secret-key, out of git); the 4 legacy rows sealed at start-up (raw rows read back `enc:v1:`); no key → the hub refuses to store or use one. **Reasoning kept: the running hub still holds the key and can open the passwords — a hub compromise remains an off-site compromise; this closes the database-copy route only.** | CLOSED 2026-10-03 — FIXED hub v0.127.0, verified on the live DB | `partB/hub-rollout.txt`; `TestOffsiteSecret_*` |
|
||||
| **R-342** | **ep0's server snapshot never covered `/mnt/pbs-datastore`.** Built (decision 70): nightly PBS pull-sync to DooPlex (`ep0-copy`), `remove-vanished false`, weekly verify, failures mailed (test mail received). First pull 201 s / 12 GB / 4 of 4 snapshots, matching ep0. ep0 changed by one read-only token only; reached through an SSH forward from DooPlex (operator ruling). **Reasoning kept: Hetzner cannot snapshot a Volume — the copy is the only safeguard; never prune it tighter than ep0.** | CLOSED 2026-10-03 — BUILT; restore route unwalked (R-830), growth unbounded (R-828) | `partF/`; `runbooks/ep0-datastore-copy.md` |
|
||||
| **R-825** | **Controller v0.289.0 reported 0 off-site snapshots as MEASURED over a store holding 12 (demo-felhom), and the hub mailed `offsite_snapshots_dropped` 11→0 — a false alarm.** Cause: the provider's rclone prints a NOTICE line that restic forwards into the combined output; every `--json` parse failed. Fixed in v0.289.1 within 15 minutes: the notice is stripped, and an unreadable count is never a measured zero (keeps the last value, `stats_known=false`). **Reasoning kept: a failed measurement must never be written as a measurement (R-331) — the detector that caught it is the one it would have blinded.** | CLOSED 2026-10-03 — FIXED controller v0.289.1 (red-proved), found and fixed in-session | operator mail 2026-10-03 17:17 CEST; `partC/red-proofs-controller.txt` RPC4 |
|
||||
|
||||
---
|
||||
|
||||
## 2026-10-03 — off-site append-only, measured on the provider (R-436, R-430)
|
||||
|
||||
> Spike, no product change. Evidence and design: `audits/offsite-append-only-2026-10-03/`.
|
||||
|
||||
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user