Commit 5c4e2fad20
5c4e2fad20392c9a31ef76114cc0ec8d457143fb
parent: e58a7dbc60
Verified · cmc ci/build: success ci/test: skipped
cmc <hello@cleberg.net> · 2026-09-29 15:07 UTC
wiki: off-host secret.key confirmed
Closes #305
Layout: unified · split
.gitbay/wiki/Admin.org
+4 −2
| @@ -831,8 +831,10 @@ The first drill ran on the operator's laptop rather than a provisioned |
| 831 | host, so its time to service has no provisioning in it, and it could |
831 | host, so its time to service has no provisioning in it, and it could |
| 832 | not check secrets: no copy of =secret.key= was on the machine, and |
832 | not check secrets: no copy of =secret.key= was on the machine, and |
| 833 | gitbayd refuses to start while any sealed value does not open. The |
833 | gitbayd refuses to start while any sealed value does not open. The |
| 834 | sealed values were cleared in the drill copy to reach service; #305 |
834 | sealed values were cleared in the drill copy to reach service. The |
| 835 | tracks proving the off-host key. |
835 | off-host copy of the key is confirmed to exist (#305); the next drill |
| |
836 | restores it with the snapshot and runs =admin secrets check= on the |
| |
837 | restored copy. |
| 836 | |
838 | |
| 837 | | Date | Host | Snapshot restored (UTC) | Newest issue / comment / push | Time to service | DB integrity | Connectivity | LFS | Release assets | Host key | Secrets | Notes | |
839 | | Date | Host | Snapshot restored (UTC) | Newest issue / comment / push | Time to service | DB integrity | Connectivity | LFS | Release assets | Host key | Secrets | Notes | |
| 838 | |------+------+-------------------------+-------------------------------+-----------------+--------------+--------------+-----+----------------+----------+---------+-------| |
840 | |------+------+-------------------------+-------------------------------+-----------------+--------------+--------------+-----+----------------+----------+---------+-------| |
.gitbay/wiki/Architecture/09-Controls.org
+1 −1
| @@ -99,6 +99,6 @@ chapter names of OWASP ASVS 4.0 where one fits. |
| 99 | | Concurrency limit on git pack generation | in place | global, per-principal, bounded queue across SSH, HTTP and git:// (=internal/packlimit=); not in system SSH mode | |
99 | | Concurrency limit on git pack generation | in place | global, per-principal, bounded queue across SSH, HTTP and git:// (=internal/packlimit=); not in system SSH mode | |
| 100 | | Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) | |
100 | | Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) | |
| 101 | | Backups offsite and append-only | in place | restic with append-only credentials (documented) | |
101 | | Backups offsite and append-only | in place | restic with append-only credentials (documented) | |
| 102 | | Restore tested | partial | drill 2026-09-29 from the offsite copy (Admin wiki "Restore drill"); secrets not checked, the off-host =secret.key= unproven (#305) | |
102 | | Restore tested | partial | drill 2026-09-29 from the offsite copy (Admin wiki "Restore drill"); secrets not checked in that drill; the off-host =secret.key= exists (#305) and is checked in the next | |
| 103 | | Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) | |
103 | | Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) | |
| 104 | | Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys | |
104 | | Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys | |
.gitbay/wiki/Architecture/10-Known-Gaps.org
−1
| @@ -10,7 +10,6 @@ what the 2026-09-27 review found; remove a row when its issue closes. |
| 10 | |
10 | |
| 11 | | Issue | Area | Gap | Severity | |
11 | | Issue | Area | Gap | Severity | |
| 12 | |-------+------------------+-----------------------------------------------------------------------+----------| |
12 | |-------+------------------+-----------------------------------------------------------------------+----------| |
| 13 | | #305 | Recovery | The off-host =secret.key= has not been shown to open a restored database; without it a restore does not start | high | |
| |
| 14 | |
13 | |
| 15 | * Not filed |
14 | * Not filed |
| 16 | |
15 | |