Decisions 68-70 recorded before the work: weekly hub-opened prune window (option 2 rejected), hub = key registrar + password encrypted at rest, ep0 -> DooPlex nightly PBS pull-sync
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -16,6 +16,8 @@
|
|||||||
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
|
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
|
||||||
|
|
||||||
|
|
||||||
|
> **Rulings 2026-10-03 (afternoon) — recorded before the work (off-site lock build).** `09` §3 decisions **68** (the box prunes only inside a weekly hub-opened window; option 2 rejected; no box-side retention in the interim), **69** (the hub is the key registrar; the box never receives the sub-account password; the hub stores it encrypted with a key outside the database; daily `authorized_keys` check) and **70** (nightly PBS pull-sync of ep0's `felhom-offsite` to DooPlex; the fence opens for that brief's Part F acts only).
|
||||||
|
|
||||||
> **Operator request 2026-10-03 — recorded before the work (backlog triage).** (1) Four roadmap items: box OS security
|
> **Operator request 2026-10-03 — recorded before the work (backlog triage).** (1) Four roadmap items: box OS security
|
||||||
> updates (R-808, finding R-812), legal pages and business papers (R-809, finding R-813), independence — "if the household
|
> updates (R-808, finding R-812), legal pages and business papers (R-809, finding R-813), independence — "if the household
|
||||||
> leaves Felhom, or Felhom stops" (R-810, spike), a second login step for the dashboard (R-811). (2) Finished rows leave
|
> leaves Felhom, or Felhom stops" (R-810, spike), a second login step for the dashboard (R-811). (2) Finished rows leave
|
||||||
|
|||||||
@@ -180,6 +180,10 @@ production endpoint exists.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
### 3.6 The ep0 datastore has a second copy — decision 70 (2026-10-03)
|
||||||
|
|
||||||
|
**[DESIGN]** A nightly PBS pull-sync copies `felhom-offsite` from ep0 to DooPlex's PBS over a read-only token. ep0's server snapshot never covered this volume and Hetzner has no volume snapshots (R-342). The copy is ciphertext per customer. Built per the 2026-10-03 lock brief Part F; the restore route lives in `runbooks/`.
|
||||||
|
|
||||||
## 4. Robustness (production details beyond the spike)
|
## 4. Robustness (production details beyond the spike)
|
||||||
|
|
||||||
- **4.1 Customer IP change = free, and explicitly NOT a DynDNS dependency.** The box dials out;
|
- **4.1 Customer IP change = free, and explicitly NOT a DynDNS dependency.** The box dials out;
|
||||||
|
|||||||
@@ -222,6 +222,8 @@ It carries guest sizing, `pve_storage[]`, and an app half with per-app `storage_
|
|||||||
the identity bundle's shape is `{tunnel_token, pbs_token, wg_private_key, restic_repo_password}`
|
the identity bundle's shape is `{tunnel_token, pbs_token, wg_private_key, restic_repo_password}`
|
||||||
(`felhom-agent/internal/escrow/identity.go:26-39`).
|
(`felhom-agent/internal/escrow/identity.go:26-39`).
|
||||||
|
|
||||||
|
**[DESIGN] Off-site deletion custody (decisions 68–69, 2026-10-03).** The restic repository password stays on the box only. The box's off-site key is append-only (pinned in `authorized_keys`, written by the hub — the key registrar); the box never receives the sub-account password, which the hub stores encrypted at rest. Old snapshots are pruned by the box itself, only in a weekly window the hub opens, behind a fake-snapshot guard (R-822); until that ships nothing prunes. A Felhom-side pruner holding repository passwords is rejected.
|
||||||
|
|
||||||
**[FACT] Three parts of the Recipe are empty or wrong on the live fleet**, and they are exactly the
|
**[FACT] Three parts of the Recipe are empty or wrong on the live fleet**, and they are exactly the
|
||||||
parts a host-loss recovery would read (INV Part D2.3): `hosts.dr_record_json` is `{}` on all three
|
parts a host-loss recovery would read (INV Part D2.3): `hosts.dr_record_json` is `{}` on all three
|
||||||
hosts; `host_escrow.directive_json` is `{}` on both escrowed hosts; `dr_recipe.host_half.drives` is
|
hosts; `host_escrow.directive_json` is `{}` on both escrowed hosts; `dr_recipe.host_half.drives` is
|
||||||
|
|||||||
@@ -712,6 +712,22 @@ its length, and both fixes cost something the household would notice — operato
|
|||||||
and name the folder. What "with data" deletes is the app's own data: its volumes, `${HDD_PATH}/appdata/<app>` and its
|
and name the folder. What "with data" deletes is the app's own data: its volumes, `${HDD_PATH}/appdata/<app>` and its
|
||||||
backups — *operator ruling 2026-10-02 (afternoon).* **Why:** userdata is the household's, browsable and often shared
|
backups — *operator ruling 2026-10-02 (afternoon).* **Why:** userdata is the household's, browsable and often shared
|
||||||
(`media/`); a remove must never take it, but it must never be silent about leaving it either. Recorded in `07` §6.5.
|
(`media/`); a remove must never take it, but it must never be silent about leaving it either. Recorded in `07` §6.5.
|
||||||
|
68. **Off-site clean-up: the box prunes its own repository, only inside a short weekly window the hub opens (R-95,
|
||||||
|
`DESIGN.md` option 1).** The restic repository password never leaves the box — custody unchanged. Until the window
|
||||||
|
ships, no box deletes off-site history at all (option 3 as the interim; quotas 50–100 GB against <1 GB used). Option
|
||||||
|
2 — a Felhom machine holding every repository password — is REJECTED: it would let one Felhom machine read every
|
||||||
|
household's backups. *Operator ruling 2026-10-03 (afternoon).* `audits/offsite-append-only-2026-10-03/DESIGN.md`.
|
||||||
|
69. **The hub is the off-site key registrar; the box never receives the sub-account password; the hub keeps it
|
||||||
|
encrypted at rest (R-820, R-821).** The box sends only its PUBLIC key; the hub writes it into the sub-account's
|
||||||
|
`authorized_keys` pinned to `command="rclone serve restic --stdio --append-only <repo>",restrict`, and reads every
|
||||||
|
`authorized_keys` daily, alarming on any unpinned line outside an open window. The password is stored encrypted with
|
||||||
|
a key that is not in the database. *Operator ruling 2026-10-03 (afternoon).* **Why:** a pinned key protects nothing
|
||||||
|
while the password can rewrite the key file (measured, R-436).
|
||||||
|
70. **ep0's datastore is copied to DooPlex every night (R-342, `PART-D-ep0-safeguard.md` option A):** a PBS pull-
|
||||||
|
sync of `felhom-offsite` from ep0 to DooPlex's PBS with a read-only token on ep0. The copy is ciphertext (per-
|
||||||
|
customer `encryption-key`). **This opens the protected-machine fence for exactly the acts of that brief's Part F** —
|
||||||
|
one read-only token on ep0; on DooPlex a remote, a datastore, a pull-sync and a verify job — and nothing else.
|
||||||
|
*Operator ruling 2026-10-03 (afternoon).*
|
||||||
|
|
||||||
### 2026-09-30 (day) — operator notes, recorded before the work
|
### 2026-09-30 (day) — operator notes, recorded before the work
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user