Files
felhom.eu/documentation/audits/offsite-lock-build-2026-10-03/partA/EXIT-TEST.md
T
admin f417cdede1
gates / gates (push) Successful in 29s
hub v0.127.0: off-site key registrar (box never gets the storage password), password sealed at rest, daily key check, clean-up window (shipped off) — decisions 68-69, R-820/R-821/R-822
Part A evidence (migration spike, sftp-written repo through the pinned rclone key) and the hub
red-proofs under documentation/audits/offsite-lock-build-2026-10-03/. Manifest bump follows after
the image is built and Secret/offsite-secret-key exists.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 16:57:04 +02:00

944 B

Part A exit test — written before any command (2026-10-03 evening)

Venue: u629488-sub4 (tester-1), repo dir spike-migrate only. restic 0.14.0 from controller image 0.288.0.

  1. A repo is created and backed up TODAY'S way: sftp: transport, an UNPINNED key, port 23 — 2 snapshots.
  2. The key line is then replaced by the PINNED line (command="rclone serve restic --stdio --append-only spike-migrate",restrict).
  3. Through the pinned key over rclone: (-o rclone.program="ssh -p 23 … -i <key> … rclone"), MUST succeed: snapshots (both sftp-era snapshots listed), backup (count 2 → 3, parent = the sftp-era snapshot), restore of one file from an sftp-era snapshot (bytes identical), check (exclusive lock taken and released), check --read-data (the integrity job's full depth).
  4. Through the pinned key MUST be refused: forget <sftp-era id> (403). Count stays 3.
  5. Fail → stop and report; no build.