R-173 option A in force (hub DB nightly to ep0, restore-tested, alarmed); R-519 proven live on 9202 and closed; R-173/R-232 narrowed; R-882..R-885 opened (332 -> 335); runbook §3 tested; hubdb-check
gates / gates (push) Successful in 59s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 16:14:13 +02:00
parent cea8502f0b
commit afba622fb6
27 changed files with 611 additions and 44 deletions
+12
View File
@@ -1,3 +1,15 @@
## hub-db-backup 1.0 — the hub database leaves DooPlex every night, encrypted, and is restore-tested weekly (R-173) (2026-10-05)
New, in `scripts/hub-db-backup/` (versioned from day one, R-231): `felhom-hub-db-backup` (02:30 — copy the hub's newest
nightly snapshot out of the pod, refuse a snapshot >26 h old, a size mismatch, a failed `integrity_check` or no hosts;
push it to ep0's PBS ns `operator`, `--crypt-mode encrypt`, write-only token; write the success timestamp only after the
push), `felhom-hub-db-restore-test` (Sun 04:30 — restore the newest copy with the read-only token, refuse a copy >50 h
old, a failed integrity check, no hosts, or any console password stored readable), four systemd units, `install.sh`
(does not enable the timers). `test_hub_db_backup.py`: 15 tests with fake `kubectl` / `proxmox-backup-client` (nothing
reaches the hub, PBS or ep0); red-proofs P1–P9 (`documentation/audits/hub-db-offsite-2026-10-05/partC/red-proof.txt` —
P4 and P5 needed a stricter test first). Installed on DooPlex 2026-10-05; timers enabled after the first manual run.
Runbook: `documentation/runbooks/RUNBOOK-hub-db-offsite-backup.md`.
## felhom-host-install.sh 1.31.0 — the root-owned files come from the agent's config bundle (R-840) (2026-10-04)
Needs a vouched agent ≥ 0.143.0 for the bundle (hub ≥ 0.133.0 serves its sha); an older vouched agent: the per-file