Decisions 68-70 recorded before the work: weekly hub-opened prune window (option 2 rejected), hub = key registrar + password encrypted at rest, ep0 -> DooPlex nightly PBS pull-sync
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -180,6 +180,10 @@ production endpoint exists.
|
||||
|
||||
---
|
||||
|
||||
### 3.6 The ep0 datastore has a second copy — decision 70 (2026-10-03)
|
||||
|
||||
**[DESIGN]** A nightly PBS pull-sync copies `felhom-offsite` from ep0 to DooPlex's PBS over a read-only token. ep0's server snapshot never covered this volume and Hetzner has no volume snapshots (R-342). The copy is ciphertext per customer. Built per the 2026-10-03 lock brief Part F; the restore route lives in `runbooks/`.
|
||||
|
||||
## 4. Robustness (production details beyond the spike)
|
||||
|
||||
- **4.1 Customer IP change = free, and explicitly NOT a DynDNS dependency.** The box dials out;
|
||||
|
||||
@@ -222,6 +222,8 @@ It carries guest sizing, `pve_storage[]`, and an app half with per-app `storage_
|
||||
the identity bundle's shape is `{tunnel_token, pbs_token, wg_private_key, restic_repo_password}`
|
||||
(`felhom-agent/internal/escrow/identity.go:26-39`).
|
||||
|
||||
**[DESIGN] Off-site deletion custody (decisions 68–69, 2026-10-03).** The restic repository password stays on the box only. The box's off-site key is append-only (pinned in `authorized_keys`, written by the hub — the key registrar); the box never receives the sub-account password, which the hub stores encrypted at rest. Old snapshots are pruned by the box itself, only in a weekly window the hub opens, behind a fake-snapshot guard (R-822); until that ships nothing prunes. A Felhom-side pruner holding repository passwords is rejected.
|
||||
|
||||
**[FACT] Three parts of the Recipe are empty or wrong on the live fleet**, and they are exactly the
|
||||
parts a host-loss recovery would read (INV Part D2.3): `hosts.dr_record_json` is `{}` on all three
|
||||
hosts; `host_escrow.directive_json` is `{}` on both escrowed hosts; `dr_recipe.host_half.drives` is
|
||||
|
||||
@@ -712,6 +712,22 @@ its length, and both fixes cost something the household would notice — operato
|
||||
and name the folder. What "with data" deletes is the app's own data: its volumes, `${HDD_PATH}/appdata/<app>` and its
|
||||
backups — *operator ruling 2026-10-02 (afternoon).* **Why:** userdata is the household's, browsable and often shared
|
||||
(`media/`); a remove must never take it, but it must never be silent about leaving it either. Recorded in `07` §6.5.
|
||||
68. **Off-site clean-up: the box prunes its own repository, only inside a short weekly window the hub opens (R-95,
|
||||
`DESIGN.md` option 1).** The restic repository password never leaves the box — custody unchanged. Until the window
|
||||
ships, no box deletes off-site history at all (option 3 as the interim; quotas 50–100 GB against <1 GB used). Option
|
||||
2 — a Felhom machine holding every repository password — is REJECTED: it would let one Felhom machine read every
|
||||
household's backups. *Operator ruling 2026-10-03 (afternoon).* `audits/offsite-append-only-2026-10-03/DESIGN.md`.
|
||||
69. **The hub is the off-site key registrar; the box never receives the sub-account password; the hub keeps it
|
||||
encrypted at rest (R-820, R-821).** The box sends only its PUBLIC key; the hub writes it into the sub-account's
|
||||
`authorized_keys` pinned to `command="rclone serve restic --stdio --append-only <repo>",restrict`, and reads every
|
||||
`authorized_keys` daily, alarming on any unpinned line outside an open window. The password is stored encrypted with
|
||||
a key that is not in the database. *Operator ruling 2026-10-03 (afternoon).* **Why:** a pinned key protects nothing
|
||||
while the password can rewrite the key file (measured, R-436).
|
||||
70. **ep0's datastore is copied to DooPlex every night (R-342, `PART-D-ep0-safeguard.md` option A):** a PBS pull-
|
||||
sync of `felhom-offsite` from ep0 to DooPlex's PBS with a read-only token on ep0. The copy is ciphertext (per-
|
||||
customer `encryption-key`). **This opens the protected-machine fence for exactly the acts of that brief's Part F** —
|
||||
one read-only token on ep0; on DooPlex a remote, a datastore, a pull-sync and a verify job — and nothing else.
|
||||
*Operator ruling 2026-10-03 (afternoon).*
|
||||
|
||||
### 2026-09-30 (day) — operator notes, recorded before the work
|
||||
|
||||
|
||||
Reference in New Issue
Block a user