R-85 Phase 4: docs — the UNATTENDED path is documented as unproven
- ROADMAP: R-85 row. Code SHIPPED; rotation NOT YET OBSERVED LIVE, stated as such rather than written as done. - Capability map: a new row for UNATTENDED restore-proof, IMPLEMENTED not PROVEN-LIVE, kept distinct from the R-82 row that a MANUAL selftest earned. That distinction is the same one the activation-vs-arrival split made. - 03-host-agent §8: the scheduler covers every tier, oldest-proven first; the spec is per-run; a restore-test joins the one-heavy-op gate. The safety properties that must not be re-derived are listed. - 07: restore-proof recorded as a per-tier property. Doc still NOT ratified. - 06: corrects S4.1's 'the offsite restore-test now runs unattended' — it silently stopped being true when local_backup_target was retargeted to 'local', the SECOND time in that doc that a correct mechanism was broken by its input changing underneath it. - CONTEXT + REUSE. Hub gate green (17 packages, rc=0).
This commit is contained in:
@@ -82,6 +82,15 @@ the Task 1 lesson). Resolution to absolute paths happens at capture time against
|
||||
| **Manual `.fab`** | v0.130.0 full-root capture | locked-in (not deselectable) | checkbox, **pre-selected** | opt-in, behind the two-number size warning + FileBrowser pointer | download / chosen drive | tar, **exclusion-scoped** root (SQ5 verdict; manifest v1 unchanged) | existing import (old controllers import new bundles correctly) |
|
||||
| **PBS** whole-guest (R-82) | rootfs + `/var/lib/docker` + `/mnt/sys_drive`; bind mounts (`/mnt/felhom-drives`, `/etc/felhom-bootstrap`) out of reach | *unchanged* | | | **`felhom-pbs` → datastore `felhom-offsite` on ep0 (Hetzner), per-customer namespace, reached over `wg-felhom`** — NOT "PBS on DooPlex" (that was the 2026-07 spike store) | vzdump, **WEEKLY** (`cadence_seconds: 604800`), retention **keep_last=2** (two weeks, operator ruling 2026-07-26) | whole-guest restore |
|
||||
|
||||
**Restore-proof per tier (R-85, 2026-07-27).** A tier is not proven by having archives; it is proven
|
||||
by one of them restoring into a bootable, mount-complete guest. Both tiers are now restore-tested
|
||||
**unattended**, rotating oldest-proven-first at the restore-test cadence, and each tier's last
|
||||
successful proof is reported. The hub raises two DISTINCT operator signals: `restore_test_failed`
|
||||
(a run did not pass — broken now) and `restore_test_stale` (not proven within ~7 days — *unverified*,
|
||||
which is not the same claim). Before this the scheduler could only ever see the primary tier, so the
|
||||
PBS row above was scheduled-but-never-verified. See `03-host-agent.md` §8.
|
||||
|
||||
|
||||
Row-level decisions folded in:
|
||||
|
||||
1. **Classified apps' tier-2 appdata leg becomes fully class-driven** — per-bind paths, not the
|
||||
|
||||
Reference in New Issue
Block a user