Backups: exercise + escrow the disaster-recovery age key #157

Öppen
öppnade 2026-07-19 21:51:33 +00:00 av supernaut · 2 kommentarer
Ägare

Split from #126 (backup-robustness umbrella). The bug-class items (M6/M7/L2/L3) shipped in PR #147; this is one of the remaining design items.

Severity: HIGH — area/backups.

The DR-key decryption path is never exercised or escrowed

The restore drill (backup-drill/bitborg-backup-drill.py.j2) and the weekly verify (bitborg-backup-verify.sh.j2) both decrypt with the on-host verify age key. The real disaster-recovery key (backup_age_recipient, group_vars/all/vars.yml) lives only in 1Password — nothing ever proves an archive actually decrypts with the DR key, and it is a single-vault SPOF.

Ask

  • Periodic manual DR-key restore test: decrypt a real off-site archive with the offline DR identity and restore it.
  • Store a second sealed copy of the DR identity independent of 1Password (offline escrow).

Refs #126.

> Split from #126 (backup-robustness umbrella). The bug-class items (M6/M7/L2/L3) shipped in PR #147; this is one of the remaining design items. **Severity: HIGH** — `area/backups`. ## The DR-key decryption path is never exercised or escrowed The restore drill (`backup-drill/bitborg-backup-drill.py.j2`) and the weekly verify (`bitborg-backup-verify.sh.j2`) both decrypt with the on-host **verify** age key. The real disaster-recovery key (`backup_age_recipient`, `group_vars/all/vars.yml`) lives **only in 1Password** — nothing ever proves an archive actually decrypts with the DR key, and it is a single-vault SPOF. ### Ask - Periodic **manual DR-key restore test**: decrypt a real off-site archive with the offline DR identity and restore it. - Store a **second sealed copy** of the DR identity independent of 1Password (offline escrow). Refs #126.
Upphovsperson
Ägare
Epic: bitborg/bitborg-docs#107
Upphovsperson
Ägare

Status 2026-09-30: an operator walkthrough for the exercise (fetch one off-site archive, decrypt with the DR identity, verify contents, wipe) and for escrow (paper copy, text plus QR, in a physical safe) is written and tracked internally. Remaining here: the operator runs the exercise and records date, archive name and pass or fail in this issue, then the runbook gets a DR-key subsection with the cadence and the escrow location.

Status 2026-09-30: an operator walkthrough for the exercise (fetch one off-site archive, decrypt with the DR identity, verify contents, wipe) and for escrow (paper copy, text plus QR, in a physical safe) is written and tracked internally. Remaining here: the operator runs the exercise and records date, archive name and pass or fail in this issue, then the runbook gets a DR-key subsection with the cadence and the escrow location.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#157
Ingen beskrivning angiven.