Skip to content

Fix approved Linux backup, monitoring and configuration safety findings - #1

Draft
blow-tech wants to merge 2 commits into
mainfrom
fix/approved-script-review-2026-09-08
Draft

Fix approved Linux backup, monitoring and configuration safety findings#1
blow-tech wants to merge 2 commits into
mainfrom
fix/approved-script-review-2026-09-08

Conversation

@blow-tech

@blow-tech blow-tech commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Continues the approved 8–9 September remediation on the existing draft branch. Not merged or deployed.

Earlier fixes retained: versioned verified backups, retention previews, explicit mount identity, local alerts/locking, alert-only service checks, one-pass disk reporting, Nginx preview/rollback, separated Apache/firewall planning and bounded audit scope.

9 September changes

  • scripts/core/backup_engine.sh: no-clobber checksum publication, refusing existing checksum files, symlinks and directories; failures preserve incomplete evidence and cannot claim verification.
  • scripts/backup/backup_rotation.sh: daily and weekly publication share the same verified helper.
  • README migration clarification; two new fixture tests.

Validation

Final head: f8ca5736d1ceb6fa75d492df67960b3eb51d5a4d.
All 12 isolated tests passed locally and in GitHub Actions, including syntax checks for all 13 Bash sources/modules, disposable backup restoration, checksum collisions/failure and mocked monitoring/configuration previews. Local tree matches the published tree.

Remaining gates

Require application-aware restoration, CA/system-state recovery where applicable, protected directories/mounts, capacity tests, Nginx integration/reload/rollback, and scheduler migration before deployment. Archive/checksum pairs are not published as one transaction; investigate orphan archives/partial artifacts after interruption. Old backups are retained, not cleaned up. External alert delivery is not configured. No production execution, merge, deployment, network scan or person-directed comment was made.

Cumulative manual Linux source coverage: all 13 operational/module paths; runtime fixture coverage is limited to stated cases. This is not a blanket safety guarantee. No benchmark is claimed. The cross-repository inventory and unresolved findings are in the weekly review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant