2.8 KiB
felhom.eu — task reports
Overwrite this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in hub/CHANGELOG.md; the scripts history lives in scripts/CHANGELOG.md.
Offsite continuity Part B — superseded-escrow retention (hub v0.60.0) — 2026-07-17
Baseline: hub v0.59.0 → v0.60.0 (LIVE on prod, ArgoCD Synced/Healthy). Closes the data-loss
half of the reinstall-orphaned-repo incident
(documentation/audits/DIAGNOSE-offbox-repo-orphaned-2026-07-17.md): the destructive
SaveHostEscrow ON CONFLICT overwrite meant a new escrow blob DESTROYED the old passphrase's only
copy (18 snapshots unrecoverable). Viktor's ruling — data protection first — is now enforced. Pairs
with controller v0.142.0 (Part A). Green: go build ./... && go vet ./... && go test ./....
Schema decision: history table (not a flag)
host_escrow_superseded — an append-only, one-row-per-superseded-blob table. A flag couldn't hold N
retained blobs, and Viktor's ruling is to keep ALL (no pruning); a history table is the only shape
that does. SaveHostEscrow now, in one tx: reads the current row; if it seals a DIFFERENT
restic_pw_sha256, COPIES it into the history table BEFORE the current row is overwritten; then upserts
the new row. Same-sha re-upload (idempotent re-ceremony) → refresh only, no supersede row. Returns
superseded bool.
What ships (retention only — the guided-recovery flow is R-26, NOT built)
SaveHostEscrowrewrite +CountSupersededEscrow/ListSupersededEscrow(the latter seeds R-26). The hub still never decrypts; the ACK + restore-serving read the CURRENT row (GetHostEscrow) — unchanged.DeleteHost(deleteEscrow=true)also drops the retained rows.- Upload handler:
escrow_supersededhub-internal audit event (tied to the owning customer) + a log line with the retained count. Operator host-detail DR/Backup panel shows "N superseded escrow blob(s) retained". Registered the controller-pushedoffbox_repo_orphaned/offbox_repo_resetinallowedEventTypes+customerMessages. - Red-proof
TestSaveHostEscrow_RetainsSuperseded(pre-fix destructive overwrite → old blob gone → FAIL; fixed → retained + retrievable viaListSupersededEscrow; same-sha idempotent = no supersede).
Deploy
Built felhom-hub:0.60.0, bumped manifests/hub.yaml, ArgoCD Synced/Healthy, rollout complete
(:0.60.0). The CREATE TABLE IF NOT EXISTS host_escrow_superseded migration runs at startup
(idempotent). ACK semantics unaffected (current-row reads only).
NOT done (registered as R-26)
The guided "recover old history with the old recovery code" flow — Part B ships retention + visibility only; R-26 registers the recovery flow that consumes the retained blobs.