Decisions 68-70 recorded before the work: weekly hub-opened prune window (option 2 rejected), hub = key registrar + password encrypted at rest, ep0 -> DooPlex nightly PBS pull-sync
gates / gates (push) Successful in 29s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 16:03:03 +02:00
parent 9268d9933b
commit 5188dbdb44
4 changed files with 24 additions and 0 deletions
+2
View File
@@ -16,6 +16,8 @@
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below. > and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
> **Rulings 2026-10-03 (afternoon) — recorded before the work (off-site lock build).** `09` §3 decisions **68** (the box prunes only inside a weekly hub-opened window; option 2 rejected; no box-side retention in the interim), **69** (the hub is the key registrar; the box never receives the sub-account password; the hub stores it encrypted with a key outside the database; daily `authorized_keys` check) and **70** (nightly PBS pull-sync of ep0's `felhom-offsite` to DooPlex; the fence opens for that brief's Part F acts only).
> **Operator request 2026-10-03 — recorded before the work (backlog triage).** (1) Four roadmap items: box OS security > **Operator request 2026-10-03 — recorded before the work (backlog triage).** (1) Four roadmap items: box OS security
> updates (R-808, finding R-812), legal pages and business papers (R-809, finding R-813), independence — "if the household > updates (R-808, finding R-812), legal pages and business papers (R-809, finding R-813), independence — "if the household
> leaves Felhom, or Felhom stops" (R-810, spike), a second login step for the dashboard (R-811). (2) Finished rows leave > leaves Felhom, or Felhom stops" (R-810, spike), a second login step for the dashboard (R-811). (2) Finished rows leave
@@ -180,6 +180,10 @@ production endpoint exists.
--- ---
### 3.6 The ep0 datastore has a second copy — decision 70 (2026-10-03)
**[DESIGN]** A nightly PBS pull-sync copies `felhom-offsite` from ep0 to DooPlex's PBS over a read-only token. ep0's server snapshot never covered this volume and Hetzner has no volume snapshots (R-342). The copy is ciphertext per customer. Built per the 2026-10-03 lock brief Part F; the restore route lives in `runbooks/`.
## 4. Robustness (production details beyond the spike) ## 4. Robustness (production details beyond the spike)
- **4.1 Customer IP change = free, and explicitly NOT a DynDNS dependency.** The box dials out; - **4.1 Customer IP change = free, and explicitly NOT a DynDNS dependency.** The box dials out;
@@ -222,6 +222,8 @@ It carries guest sizing, `pve_storage[]`, and an app half with per-app `storage_
the identity bundle's shape is `{tunnel_token, pbs_token, wg_private_key, restic_repo_password}` the identity bundle's shape is `{tunnel_token, pbs_token, wg_private_key, restic_repo_password}`
(`felhom-agent/internal/escrow/identity.go:26-39`). (`felhom-agent/internal/escrow/identity.go:26-39`).
**[DESIGN] Off-site deletion custody (decisions 68–69, 2026-10-03).** The restic repository password stays on the box only. The box's off-site key is append-only (pinned in `authorized_keys`, written by the hub — the key registrar); the box never receives the sub-account password, which the hub stores encrypted at rest. Old snapshots are pruned by the box itself, only in a weekly window the hub opens, behind a fake-snapshot guard (R-822); until that ships nothing prunes. A Felhom-side pruner holding repository passwords is rejected.
**[FACT] Three parts of the Recipe are empty or wrong on the live fleet**, and they are exactly the **[FACT] Three parts of the Recipe are empty or wrong on the live fleet**, and they are exactly the
parts a host-loss recovery would read (INV Part D2.3): `hosts.dr_record_json` is `{}` on all three parts a host-loss recovery would read (INV Part D2.3): `hosts.dr_record_json` is `{}` on all three
hosts; `host_escrow.directive_json` is `{}` on both escrowed hosts; `dr_recipe.host_half.drives` is hosts; `host_escrow.directive_json` is `{}` on both escrowed hosts; `dr_recipe.host_half.drives` is
@@ -712,6 +712,22 @@ its length, and both fixes cost something the household would notice — operato
and name the folder. What "with data" deletes is the app's own data: its volumes, `${HDD_PATH}/appdata/<app>` and its and name the folder. What "with data" deletes is the app's own data: its volumes, `${HDD_PATH}/appdata/<app>` and its
backups — *operator ruling 2026-10-02 (afternoon).* **Why:** userdata is the household's, browsable and often shared backups — *operator ruling 2026-10-02 (afternoon).* **Why:** userdata is the household's, browsable and often shared
(`media/`); a remove must never take it, but it must never be silent about leaving it either. Recorded in `07` §6.5. (`media/`); a remove must never take it, but it must never be silent about leaving it either. Recorded in `07` §6.5.
68. **Off-site clean-up: the box prunes its own repository, only inside a short weekly window the hub opens (R-95,
`DESIGN.md` option 1).** The restic repository password never leaves the box — custody unchanged. Until the window
ships, no box deletes off-site history at all (option 3 as the interim; quotas 50–100 GB against <1 GB used). Option
2 — a Felhom machine holding every repository password — is REJECTED: it would let one Felhom machine read every
household's backups. *Operator ruling 2026-10-03 (afternoon).* `audits/offsite-append-only-2026-10-03/DESIGN.md`.
69. **The hub is the off-site key registrar; the box never receives the sub-account password; the hub keeps it
encrypted at rest (R-820, R-821).** The box sends only its PUBLIC key; the hub writes it into the sub-account's
`authorized_keys` pinned to `command="rclone serve restic --stdio --append-only <repo>",restrict`, and reads every
`authorized_keys` daily, alarming on any unpinned line outside an open window. The password is stored encrypted with
a key that is not in the database. *Operator ruling 2026-10-03 (afternoon).* **Why:** a pinned key protects nothing
while the password can rewrite the key file (measured, R-436).
70. **ep0's datastore is copied to DooPlex every night (R-342, `PART-D-ep0-safeguard.md` option A):** a PBS pull-
sync of `felhom-offsite` from ep0 to DooPlex's PBS with a read-only token on ep0. The copy is ciphertext (per-
customer `encryption-key`). **This opens the protected-machine fence for exactly the acts of that brief's Part F** —
one read-only token on ep0; on DooPlex a remote, a datastore, a pull-sync and a verify job — and nothing else.
*Operator ruling 2026-10-03 (afternoon).*
### 2026-09-30 (day) — operator notes, recorded before the work ### 2026-09-30 (day) — operator notes, recorded before the work