R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
gates / gates (push) Successful in 29s

Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed,
authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820,
R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions.
Register 326 -> 327.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 13:40:35 +02:00
parent f4c5466c39
commit 9268d9933b
21 changed files with 1200 additions and 12 deletions
+31 -5
View File
@@ -2,9 +2,22 @@
**Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).**
**Updated 2026-10-03 (the to-do list put in order). Versions unchanged since 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New
**Updated 2026-10-03 (off-site backup safety, step 1: measured on Hetzner). Versions unchanged since 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New
installs get golden 0.288.0 with agent 0.138.0.**
## Today (2026-10-03, later): off-site backup safety, step 1 — measured, nothing built
- **The "add only" lock works.** I tested it on tester-1's storage account (your choice; no box uses it now).
New backups go in. Restore works. Every delete is refused. I put the account back exactly as it was.
- **But the lock alone does not protect us yet.** A broken-into box can ask the hub for the storage password.
With that password it can log in and remove the lock. First the box must stop getting the password.
- **A second trap:** with "add only", an attacker can add fake backups dated in the future. The normal
clean-up rule then deletes all the real backups. Any clean-up must check for this.
- **The hub keeps every storage password in plain form.** Anyone who reads the hub database can delete
every household's off-site backups. New row.
- **ep0:** Hetzner cannot snapshot the extra disk at all. One of the three old ideas does not exist.
- **Rows:** 2 closed, 3 opened. The list went from 326 to 327 rows. The dated check for 6 October is done.
## Today (2026-10-03): the to-do list is in order — paperwork only, no machine touched
- **Finished items left the open list.** It went from 442 rows to 326. Nothing was deleted; each moved row names
@@ -55,10 +68,23 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne
## What needs you
0. **Pick the next theme.** **A — off-site backup safety** (recommended): a dated check on it turns red on
6 October and then refuses every push until it is done; it guards the household's own files. **B — box system
security updates**: nothing patches a box today; a test on a throwaway box comes first. **If you say nothing:**
the next session starts A. 18 rows wait on you; the list is in the triage recommendation.
0. **Who may delete old off-site backups, once boxes can only add?** (Details: the design in the
2026-10-03 off-site audit folder.)
- **A — the box, in a short weekly window the hub opens** (recommended). The backup password stays only on
the box, as we promise today. Cost: during the window a broken-into box could delete; the hub checks the
count before and after.
- **B — a Felhom machine does it for every box.** Cost: that machine must hold every household's backup
password, so it could read every household's backups. That changes a promise to the customer, and adds a
new always-on machine.
- **If you say nothing:** nothing is built. Boxes keep the key that can delete (today's risk stays).
- Either way, first: the hub installs the box's key, so the box never gets the storage password.
0b. **ep0's backup disk has no copy of its own. Which safeguard?**
- **A — DooPlex copies it every night** (recommended). €0 a month, about 1–2 hours to set up. Protects against
losing the disk and losing Hetzner. The copy is encrypted per household, so DooPlex cannot read it. Cost: a
new job on DooPlex.
- **B — accept the risk in writing,** and copy the disk off by hand before any risky work on ep0.
- **If you say nothing:** the disk stays unprotected; a bad day on ep0 loses every household's whole-box
off-site copy.
1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say
nothing:** it stays hidden; nothing runs it.
2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list).