R-85 Phase 4: docs — the UNATTENDED path is documented as unproven

- ROADMAP: R-85 row. Code SHIPPED; rotation NOT YET OBSERVED LIVE, stated as
  such rather than written as done.
- Capability map: a new row for UNATTENDED restore-proof, IMPLEMENTED not
  PROVEN-LIVE, kept distinct from the R-82 row that a MANUAL selftest earned.
  That distinction is the same one the activation-vs-arrival split made.
- 03-host-agent §8: the scheduler covers every tier, oldest-proven first; the
  spec is per-run; a restore-test joins the one-heavy-op gate. The safety
  properties that must not be re-derived are listed.
- 07: restore-proof recorded as a per-tier property. Doc still NOT ratified.
- 06: corrects S4.1's 'the offsite restore-test now runs unattended' — it
  silently stopped being true when local_backup_target was retargeted to 'local',
  the SECOND time in that doc that a correct mechanism was broken by its input
  changing underneath it.
- CONTEXT + REUSE.

Hub gate green (17 packages, rc=0).
This commit is contained in:
Claude Code
2026-07-27 07:33:40 +02:00
parent b802a9e7de
commit 57ba3c7c8c
7 changed files with 67 additions and 1 deletions
@@ -82,6 +82,15 @@ the Task 1 lesson). Resolution to absolute paths happens at capture time against
| **Manual `.fab`** | v0.130.0 full-root capture | locked-in (not deselectable) | checkbox, **pre-selected** | opt-in, behind the two-number size warning + FileBrowser pointer | download / chosen drive | tar, **exclusion-scoped** root (SQ5 verdict; manifest v1 unchanged) | existing import (old controllers import new bundles correctly) |
| **PBS** whole-guest (R-82) | rootfs + `/var/lib/docker` + `/mnt/sys_drive`; bind mounts (`/mnt/felhom-drives`, `/etc/felhom-bootstrap`) out of reach | *unchanged* | | | **`felhom-pbs` → datastore `felhom-offsite` on ep0 (Hetzner), per-customer namespace, reached over `wg-felhom`** — NOT "PBS on DooPlex" (that was the 2026-07 spike store) | vzdump, **WEEKLY** (`cadence_seconds: 604800`), retention **keep_last=2** (two weeks, operator ruling 2026-07-26) | whole-guest restore |
**Restore-proof per tier (R-85, 2026-07-27).** A tier is not proven by having archives; it is proven
by one of them restoring into a bootable, mount-complete guest. Both tiers are now restore-tested
**unattended**, rotating oldest-proven-first at the restore-test cadence, and each tier's last
successful proof is reported. The hub raises two DISTINCT operator signals: `restore_test_failed`
(a run did not pass — broken now) and `restore_test_stale` (not proven within ~7 days — *unverified*,
which is not the same claim). Before this the scheduler could only ever see the primary tier, so the
PBS row above was scheduled-but-never-verified. See `03-host-agent.md` §8.
Row-level decisions folded in:
1. **Classified apps' tier-2 appdata leg becomes fully class-driven** — per-bind paths, not the