R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed, authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820, R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions. Register 326 -> 327. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -2,9 +2,22 @@
|
||||
|
||||
**Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).**
|
||||
|
||||
**Updated 2026-10-03 (the to-do list put in order). Versions unchanged since 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New
|
||||
**Updated 2026-10-03 (off-site backup safety, step 1: measured on Hetzner). Versions unchanged since 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New
|
||||
installs get golden 0.288.0 with agent 0.138.0.**
|
||||
|
||||
## Today (2026-10-03, later): off-site backup safety, step 1 — measured, nothing built
|
||||
|
||||
- **The "add only" lock works.** I tested it on tester-1's storage account (your choice; no box uses it now).
|
||||
New backups go in. Restore works. Every delete is refused. I put the account back exactly as it was.
|
||||
- **But the lock alone does not protect us yet.** A broken-into box can ask the hub for the storage password.
|
||||
With that password it can log in and remove the lock. First the box must stop getting the password.
|
||||
- **A second trap:** with "add only", an attacker can add fake backups dated in the future. The normal
|
||||
clean-up rule then deletes all the real backups. Any clean-up must check for this.
|
||||
- **The hub keeps every storage password in plain form.** Anyone who reads the hub database can delete
|
||||
every household's off-site backups. New row.
|
||||
- **ep0:** Hetzner cannot snapshot the extra disk at all. One of the three old ideas does not exist.
|
||||
- **Rows:** 2 closed, 3 opened. The list went from 326 to 327 rows. The dated check for 6 October is done.
|
||||
|
||||
## Today (2026-10-03): the to-do list is in order — paperwork only, no machine touched
|
||||
|
||||
- **Finished items left the open list.** It went from 442 rows to 326. Nothing was deleted; each moved row names
|
||||
@@ -55,10 +68,23 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne
|
||||
|
||||
## What needs you
|
||||
|
||||
0. **Pick the next theme.** **A — off-site backup safety** (recommended): a dated check on it turns red on
|
||||
6 October and then refuses every push until it is done; it guards the household's own files. **B — box system
|
||||
security updates**: nothing patches a box today; a test on a throwaway box comes first. **If you say nothing:**
|
||||
the next session starts A. 18 rows wait on you; the list is in the triage recommendation.
|
||||
0. **Who may delete old off-site backups, once boxes can only add?** (Details: the design in the
|
||||
2026-10-03 off-site audit folder.)
|
||||
- **A — the box, in a short weekly window the hub opens** (recommended). The backup password stays only on
|
||||
the box, as we promise today. Cost: during the window a broken-into box could delete; the hub checks the
|
||||
count before and after.
|
||||
- **B — a Felhom machine does it for every box.** Cost: that machine must hold every household's backup
|
||||
password, so it could read every household's backups. That changes a promise to the customer, and adds a
|
||||
new always-on machine.
|
||||
- **If you say nothing:** nothing is built. Boxes keep the key that can delete (today's risk stays).
|
||||
- Either way, first: the hub installs the box's key, so the box never gets the storage password.
|
||||
0b. **ep0's backup disk has no copy of its own. Which safeguard?**
|
||||
- **A — DooPlex copies it every night** (recommended). €0 a month, about 1–2 hours to set up. Protects against
|
||||
losing the disk and losing Hetzner. The copy is encrypted per household, so DooPlex cannot read it. Cost: a
|
||||
new job on DooPlex.
|
||||
- **B — accept the risk in writing,** and copy the disk off by hand before any risky work on ep0.
|
||||
- **If you say nothing:** the disk stays unprotected; a bad day on ep0 loses every household's whole-box
|
||||
off-site copy.
|
||||
1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say
|
||||
nothing:** it stays hidden; nothing runs it.
|
||||
2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list).
|
||||
|
||||
Reference in New Issue
Block a user