Backups: exercise + escrow the disaster-recovery age key #157
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#157
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Severity: HIGH —
area/backups.The DR-key decryption path is never exercised or escrowed
The restore drill (
backup-drill/bitborg-backup-drill.py.j2) and the weekly verify (bitborg-backup-verify.sh.j2) both decrypt with the on-host verify age key. The real disaster-recovery key (backup_age_recipient,group_vars/all/vars.yml) lives only in 1Password — nothing ever proves an archive actually decrypts with the DR key, and it is a single-vault SPOF.Ask
Refs #126.
Epic: bitborg/bitborg-docs#107
Status 2026-09-30: an operator walkthrough for the exercise (fetch one off-site archive, decrypt with the DR identity, verify contents, wipe) and for escrow (paper copy, text plus QR, in a physical safe) is written and tracked internally. Remaining here: the operator runs the exercise and records date, archive name and pass or fail in this issue, then the runbook gets a DR-key subsection with the cadence and the escrow location.