94a236328b
Empirical PBS validation before the slice-6 Phase B spec. Records: PBS install on Debian-13 DooPlex (trixie key ships in proxmox-archive-keyring, no standalone .gpg), datastore + cert fingerprint, the PBS privsep gotcha (grant role on user AND token), the encrypted pbs storage + key location (/etc/pve/priv/storage/<id>.enc), the snapshot volid format + native fields (→ PBSSnapshot shape), restore-from-PBS works unchanged, the verify mechanism (server-side; agent drives it remotely via the PBS API, result read from snapshot verification.state), no operator-token privilege gap, and zero-knowledge confirmed (server can't decrypt without the client key). PBS+datastore+storage left up for Phase B; no secrets committed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>