Record successful full offsite Forgejo recovery and remaining custody gate
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 01:36:39 +02:00
parent 603c2926fa
commit 5567fa979e
11 changed files with 187 additions and 10 deletions

View file

@ -7,7 +7,7 @@ repo: railiance-platform
status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
updated: "2026-09-06"
state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd"
---
@ -45,11 +45,13 @@ Provider-side invalidation and replacement custody need the attended provider ow
Prepared owner execution procedure: `docs/backup-credential-recovery.md`.
The dedicated Backup account cutover is complete under T03. Awaiting owner
authority for invalidating the old Bernd-owned share and a real offsite restore. Activity-core is
authority for invalidating the old Bernd-owned share. Full offsite application
recovery passed on September 6 (evidence below). Activity-core is
also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical
exposure evidence; upload-token rotation cannot clear recovery-key taint.
T03 proves encrypted fixture transport and decryption; full application restore
and historical predecessor invalidation remain open.
T03 proves encrypted fixture transport and decryption; September 6 evidence
also proves full application recovery. Historical predecessor invalidation
remains open.
## Portfolio review — 2026-09-05
@ -128,3 +130,30 @@ Barman destination and the Forgejo full-archive uploader still targets Nextcloud
Do not conflate this coverage gap with the old-share incident or silently move
archives into a database-owned prefix. WP-0029's secondary acceptance gates
remain explicit. Source/platform assurance records now name the correct primary.
## Follow-up — 2026-09-06
Repaired the missing WSL browser-launcher path while retaining Warden
containment. Fresh attended login reached the owner command, the full verified
5.35 GB archive uploaded to Backup (201), downloaded (200), matched ciphertext
and decrypted archive hashes, and Warden exited 0 after session cleanup.
Evidence: `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`.
Application recovery and predecessor invalidation remain separate gates.
The earlier primary gap observation is superseded for forgejo-db: native
Scaleway base backup/WAL and isolated database recovery now pass under
RPF-WP-0038-T02/T03. Forgejo's primary full-archive delivery remains T04.
The Backup account's 10 GiB quota holds only about two current full archives;
growth and other consumers require a bounded retention policy, not automatic
deletion of retained backups.
Replacement recovery PASSED: isolated Forgejo healthy, 142 repositories, six
users, two public Git clones plus fsck, and all 2,040 package blob digests
verified. Disposable resources removed. Evidence:
`docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`.
T02 remains `wait` solely for the Bernd-owned predecessor invalidation/custody
receipt; do not repeat the completed replacement restore as an open gate.
Rejected drill-copy cleanup completed with conditional DELETE 204; attended
session exited 0. Temporary plaintext removed; good encrypted backups retained.