Files
felhom.eu/documentation/audits/offsite-lock-build-2026-10-03/partA/EXIT-TEST.md
T
admin f417cdede1
gates / gates (push) Successful in 29s
hub v0.127.0: off-site key registrar (box never gets the storage password), password sealed at rest, daily key check, clean-up window (shipped off) — decisions 68-69, R-820/R-821/R-822
Part A evidence (migration spike, sftp-written repo through the pinned rclone key) and the hub
red-proofs under documentation/audits/offsite-lock-build-2026-10-03/. Manifest bump follows after
the image is built and Secret/offsite-secret-key exists.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 16:57:04 +02:00

13 lines
944 B
Markdown

# Part A exit test — written before any command (2026-10-03 evening)
Venue: `u629488-sub4` (tester-1), repo dir `spike-migrate` only. restic 0.14.0 from controller image 0.288.0.
1. A repo is created and backed up TODAY'S way: `sftp:` transport, an UNPINNED key, port 23 — 2 snapshots.
2. The key line is then replaced by the PINNED line (`command="rclone serve restic --stdio --append-only spike-migrate",restrict`).
3. Through the pinned key over `rclone:` (`-o rclone.program="ssh -p 23 … -i <key> … rclone"`), MUST succeed:
`snapshots` (both sftp-era snapshots listed), `backup` (count 2 → 3, parent = the sftp-era snapshot),
`restore` of one file from an sftp-era snapshot (bytes identical), `check` (exclusive lock taken and released),
`check --read-data` (the integrity job's full depth).
4. Through the pinned key MUST be refused: `forget <sftp-era id>` (403). Count stays 3.
5. Fail → stop and report; no build.