R-923/R-924: total-loss-of-dooplex runbook (every recovery secret, where it lives, walked on paper), break-glass sheet (names only), Vaultwarden off-site proven (push, restore test, throwaway start); 'off DooPlex' claims corrected; R-924 filed
gates / gates (push) Successful in 5m41s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-09 12:13:41 +02:00
parent 30b932bb10
commit 4c388a398b
11 changed files with 244 additions and 7 deletions
@@ -109,7 +109,9 @@ only**: both keys sit on DooPlex at `/mnt/5_hdd/felhom.eu/felhom-op-operational`
2026-09-15 and were tightened the same day (R-533). **CC may sign `agent_update` ops with the
operational key until the first PAYING customer exists; testers do not count.** Every signature is
per box (the blob binds `host_id`), so one box moves at a time and a fenced box cannot be swept along.
Proven twice: `demo-hp-bb76ea` 2026-09-15, `demo-felhom-8363b5` 2026-09-16. **Revisit on the first
Proven twice: `demo-hp-bb76ea` 2026-09-15, `demo-felhom-8363b5` 2026-09-16. **Measured 2026-10-09 (R-924):** all three
key files open with an EMPTY passphrase, and `/mnt/5_hdd/felhom.eu` is in no backup — so today neither the "passphrase-
protected" nor the "kept offline" of §1 holds, and a loss of DooPlex loses both keys at once. **Revisit on the first
sale** — at that point the key belongs behind the operator (or a hardware key, §7), and a fleet
rollout step still has to be designed (R-530).