Fix approved Linux backup, monitoring and configuration safety findings - #1
Draft
blow-tech wants to merge 2 commits into
Draft
Fix approved Linux backup, monitoring and configuration safety findings#1blow-tech wants to merge 2 commits into
blow-tech wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Continues the approved 8–9 September remediation on the existing draft branch. Not merged or deployed.
Earlier fixes retained: versioned verified backups, retention previews, explicit mount identity, local alerts/locking, alert-only service checks, one-pass disk reporting, Nginx preview/rollback, separated Apache/firewall planning and bounded audit scope.
9 September changes
scripts/core/backup_engine.sh: no-clobber checksum publication, refusing existing checksum files, symlinks and directories; failures preserve incomplete evidence and cannot claim verification.scripts/backup/backup_rotation.sh: daily and weekly publication share the same verified helper.Validation
Final head:
f8ca5736d1ceb6fa75d492df67960b3eb51d5a4d.All 12 isolated tests passed locally and in GitHub Actions, including syntax checks for all 13 Bash sources/modules, disposable backup restoration, checksum collisions/failure and mocked monitoring/configuration previews. Local tree matches the published tree.
Remaining gates
Require application-aware restoration, CA/system-state recovery where applicable, protected directories/mounts, capacity tests, Nginx integration/reload/rollback, and scheduler migration before deployment. Archive/checksum pairs are not published as one transaction; investigate orphan archives/partial artifacts after interruption. Old backups are retained, not cleaned up. External alert delivery is not configured. No production execution, merge, deployment, network scan or person-directed comment was made.
Cumulative manual Linux source coverage: all 13 operational/module paths; runtime fixture coverage is limited to stated cases. This is not a blanket safety guarantee. No benchmark is claimed. The cross-repository inventory and unresolved findings are in the weekly review.