R-32 (decision 167): RESET purges the off-site folder through the sub-account's own login before deleting it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-07 10:07:50 +02:00
parent aeca52ea54
commit e03b18ea21
10 changed files with 259 additions and 5 deletions
+7 -2
View File
@@ -378,6 +378,7 @@ func main() {
// a heal that cannot actually restage must never run (it would emit a restaged event for a
// silent no-op: ReissueOffsiteForCustomer returns nil when offsite is unconfigured).
var offsiteHealReissuer monitor.OffsiteReissuer
var offsiteProv *offsite.Provisioner // R-32: the key service wires its purge into RESET's Deprovision below
if tok := os.Getenv("HETZNER_TOKEN"); tok != "" {
poolBoxID, _ := strconv.ParseInt(os.Getenv("HETZNER_POOL_BOX_ID"), 10, 64)
location := os.Getenv("HETZNER_LOCATION")
@@ -385,9 +386,10 @@ func main() {
location = "fsn1"
}
client := hetznerapi.NewClient(func() string { return os.Getenv("HETZNER_TOKEN") })
webServer.SetOffsiteProvisioner(&offsite.Provisioner{
offsiteProv = &offsite.Provisioner{
API: client, Store: dataStore, Scanner: offsite.SSHHostKeyScanner{}, PoolBoxID: poolBoxID, Location: location, Logger: logger,
})
}
webServer.SetOffsiteProvisioner(offsiteProv)
logger.Printf("[INFO] Offsite provisioning enabled (pool_box=%d, location=%s)", poolBoxID, location)
offsiteHealReissuer = webServer // R-71c heal armed (provisioner present)
// R-5 (v0.64.0): the pool-box aggregate checker shares the SAME client + pool box id (GET-only).
@@ -542,6 +544,9 @@ func main() {
}
}
apiHandler.SetOffsiteKeyService(keySvc)
if offsiteProv != nil {
offsiteProv.PurgeShared = keySvc.PurgeRepos // R-32: RESET purges the folder through the sub-account's own login
}
runKeyAudit := func(ctx context.Context) any {
start := time.Now()
out := keySvc.AuditAll(ctx, dataStore.OffsiteWindowOpen)