R-105 (decision 169): retire the never-built slim DR record fields (no writer, no reader); 05 §9/§11, 06 §3.5 corrected
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -57,7 +57,8 @@ A customer's deployment is one **Host** (its agent) plus one-or-more **Guests**
|
||||
`retrieval_password`, status, config_json. Unchanged role.
|
||||
- **`hosts`** (new) — `host_id PK, customer_id, api_key` (the agent's hub key), `agent_version`,
|
||||
desired-state intent (storage manifest + policies + golden-image version, as JSON), a per-host
|
||||
**`desired_generation`** counter, the slim DR record (§9), timestamps.
|
||||
**`desired_generation`** counter, timestamps. (The "slim DR record" column `dr_record_json` exists but is
|
||||
RETIRED — never written, never read; §9, R-105.)
|
||||
- **`guests`** (new) — `guest_id PK, customer_id, host_id, api_key` (the controller's hub key),
|
||||
`display_name, controller_version`, per-guest **`desired_spec_json`** (CPU/mem/disk, versions),
|
||||
timestamps.
|
||||
@@ -211,18 +212,22 @@ What remains:
|
||||
pruned by age);
|
||||
- the agent **escrows the recovery-code-wrapped PBS key** to the hub (the one artifact only the box
|
||||
can produce — zero-knowledge: the hub stores it, cannot open it);
|
||||
- a **slim DR record** on the `hosts` row (PBS namespace + repo fingerprint + the wrapped escrow key).
|
||||
These last two are *box-reported* columns on an otherwise operator-intent row — labelled as such so
|
||||
the §1 two-driver split stays legible per column.
|
||||
- ~~a **slim DR record** on the `hosts` row (PBS namespace + repo fingerprint + the wrapped escrow key)~~ —
|
||||
**[FACT, RETIRED 2026-10-07, R-105, `09` §3 decision 169]: never built.** `hosts.dr_record_json` had no writer and
|
||||
no reader; `host_escrow.directive_json` was written only by a by-hand selftest flag and read by nothing. Both are
|
||||
retired in code (the hub and agent releases after 2026-10-07); the columns stay, unread. **Where each fact really lives:** the
|
||||
PBS repo and namespace in the **DR recipe** (`dr_recipe`, reported every cycle — R-106 fixed it to match the
|
||||
backup); the endpoint's PBS fingerprint in **tenantsync** (`hub/internal/tenantsync`); the wrapped key in
|
||||
**`host_escrow.blob`** (and the identity blob beside it).
|
||||
|
||||
Both existing infra-backup tables retire — `infra_backup_versions` (the current/live one, all readers
|
||||
hit it) **and** `infra_backups` (the deprecated legacy mirror). The slim DR record folds onto `hosts`
|
||||
instead. The **controller's infra-backup push is removed** (it's de-privileged).
|
||||
hit it) **and** `infra_backups` (the deprecated legacy mirror). (The planned slim DR record on `hosts` was never
|
||||
built — retired 2026-10-07, see above.) The **controller's infra-backup push is removed** (it's de-privileged).
|
||||
|
||||
**Recovery (host loss):** the new agent re-enrolls in **restore mode**; the hub hands it the durable
|
||||
record — and DR reads from the **durable sources, not the prunable report mirror**: operator intent
|
||||
(desired-state on `hosts`/`guests` — identity, tunnel token, storage manifest), the slim DR record
|
||||
(PBS namespace + repo fingerprint), the **wrapped escrow key**, and **PBS's own snapshot enumeration**
|
||||
(desired-state on `hosts`/`guests` — identity, tunnel token, storage manifest), the **DR recipe** (PBS
|
||||
namespace + repo) with tenantsync's endpoint fingerprint, the **wrapped escrow key**, and **PBS's own snapshot enumeration**
|
||||
(the agent lists snapshots once it has the namespace + unwrapped key). Guest inventory + app data come
|
||||
from **inside the PBS guest snapshots**, not from a retained `host_report`, so recovery doesn't degrade
|
||||
when the last report has aged out. The **customer provides their recovery code at the agent**, which
|
||||
@@ -248,7 +253,7 @@ customer instead of a single controller.
|
||||
- **ADD** desired-state JSON + `desired_generation` to `hosts`; `desired_spec_json` to `guests`; the
|
||||
slim DR record (PBS namespace + repo fingerprint + wrapped escrow key) onto `hosts`.
|
||||
- **DROP both** `infra_backup_versions` (current/live) **and** `infra_backups` (legacy mirror) — the DR
|
||||
record replaces them on `hosts`.
|
||||
recipe, tenantsync and the escrow blob replace them (R-105).
|
||||
- **KEEP** `customer_configs`, `events`, `customer_notifications`, `notification_log`,
|
||||
`app_telemetry`, `app_log_issues`.
|
||||
- **Authz cleanup the cutover enables:** several endpoints today use global-or-any-customer-key auth
|
||||
|
||||
@@ -162,7 +162,11 @@ needed.
|
||||
offsite client key K + the auto-injected WG private key + the offsite PBS token under it, and
|
||||
uploaded the opaque blobs to the hub. Independently verified in `host_escrow` (host `demo-felhom-01`:
|
||||
`key_fingerprint` = the offsite key `b0:fe:2a…`, identity blob 499 B, directive with the non-secret
|
||||
DR coords, `created_at` = now) — all with **zero knowledge of R**. `tunnel_token` intentionally empty
|
||||
DR coords, `created_at` = now) — all with **zero knowledge of R**. **[FACT, 2026-10-07 — R-105, `09` §3 decision
|
||||
169] The directive is RETIRED:** it was written only by this by-hand `-directive` flag (the customer's escrow wizard
|
||||
never sent one, so every wizard escrow stored `{}` over it), and nothing read it. The flag is gone (the agent release after 2026-10-07)
|
||||
and the hub no longer stores it; the re-enroll routes serve `{}`. The DR coordinates live in the DR
|
||||
recipe and tenantsync. `tunnel_token` intentionally empty
|
||||
(the Cloudflare edge lives in the guest/controller, re-provisioned separately in DR). **S5 (DR
|
||||
consume) is now UNBLOCKED:** R + the hub-stored blobs reconstruct K + the WG key (+ the offsite PBS
|
||||
token). Note: `host_escrow` is one slot per host (last-write-wins) — the offsite escrow is the one
|
||||
|
||||
Reference in New Issue
Block a user