Files
felhom.eu/REPORT.md
T

2.8 KiB

felhom.eu — task reports

Overwrite this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in hub/CHANGELOG.md; the scripts history lives in scripts/CHANGELOG.md.

Offsite continuity Part B — superseded-escrow retention (hub v0.60.0) — 2026-07-17

Baseline: hub v0.59.0 → v0.60.0 (LIVE on prod, ArgoCD Synced/Healthy). Closes the data-loss half of the reinstall-orphaned-repo incident (documentation/audits/DIAGNOSE-offbox-repo-orphaned-2026-07-17.md): the destructive SaveHostEscrow ON CONFLICT overwrite meant a new escrow blob DESTROYED the old passphrase's only copy (18 snapshots unrecoverable). Viktor's ruling — data protection first — is now enforced. Pairs with controller v0.142.0 (Part A). Green: go build ./... && go vet ./... && go test ./....

Schema decision: history table (not a flag)

host_escrow_superseded — an append-only, one-row-per-superseded-blob table. A flag couldn't hold N retained blobs, and Viktor's ruling is to keep ALL (no pruning); a history table is the only shape that does. SaveHostEscrow now, in one tx: reads the current row; if it seals a DIFFERENT restic_pw_sha256, COPIES it into the history table BEFORE the current row is overwritten; then upserts the new row. Same-sha re-upload (idempotent re-ceremony) → refresh only, no supersede row. Returns superseded bool.

What ships (retention only — the guided-recovery flow is R-26, NOT built)

  • SaveHostEscrow rewrite + CountSupersededEscrow / ListSupersededEscrow (the latter seeds R-26). The hub still never decrypts; the ACK + restore-serving read the CURRENT row (GetHostEscrow) — unchanged. DeleteHost(deleteEscrow=true) also drops the retained rows.
  • Upload handler: escrow_superseded hub-internal audit event (tied to the owning customer) + a log line with the retained count. Operator host-detail DR/Backup panel shows "N superseded escrow blob(s) retained". Registered the controller-pushed offbox_repo_orphaned / offbox_repo_reset in allowedEventTypes + customerMessages.
  • Red-proof TestSaveHostEscrow_RetainsSuperseded (pre-fix destructive overwrite → old blob gone → FAIL; fixed → retained + retrievable via ListSupersededEscrow; same-sha idempotent = no supersede).

Deploy

Built felhom-hub:0.60.0, bumped manifests/hub.yaml, ArgoCD Synced/Healthy, rollout complete (:0.60.0). The CREATE TABLE IF NOT EXISTS host_escrow_superseded migration runs at startup (idempotent). ACK semantics unaffected (current-row reads only).

NOT done (registered as R-26)

The guided "recover old history with the old recovery code" flow — Part B ships retention + visibility only; R-26 registers the recovery flow that consumes the retained blobs.