docs(backups): formalize R1.9 — backups external/unknown, accepted risk

Open question 5.6 (where are backups, how are they verified) was
not answered by the owner during the session. Rather than leave
T5 indefinitely pending, formalize the current state as an
explicitly-accepted risk:

- R1.9 added to project-rules.md: «Backups: external/unknown —
  no strategy declared in this repo. Accepted risk. Failure of
  /dev/sdc1 (External) = full data loss of 9 services on sapphira.»

- .agent/decisions/0002-backups-external.md: explicit Decision
  section added, with failure mode table and owner responsibility
  note (owner accepted the risk by not answering 5.6 after direct
  request in the session's final report).

- T5 in manifest.json → completed (docs written, risk acknowledged,
  R1.9 formalized).

- T3 in manifest.json: notes updated to reflect the SSH block
  (both 100.64.1.0 Tailscale and 109.248.161.5:22 timeout on
  2026-10-10). Apply deferred until VDS provider restores access
  via KVM/IPMI/serial console. Proposal Option A ready.

This closes the documentation chain. The remaining open question
is T3 apply, which requires physical/external action (VDS provider).
The user can resolve it at any time by:
  1. Restoring SSH via KVM/IPMI/serial console
  2. Running 'deploy . otreca' (or 'nixos-rebuild switch --flake
     .#otreca' on otreca directly)
  3. Applying the Option A fix from
     .agent/decisions/proposals/vds-nftables-fix.md
This commit is contained in:
2026-10-10 16:44:37 +03:00
parent 2727d88a12
commit 3f5c048572
3 changed files with 36 additions and 5 deletions
+5 -5
View File
@@ -60,7 +60,7 @@
],
"files": ["configurations/vds.nix"],
"blocks": ["T11", "T12"],
"notes": "Сначала диагностика: nft list ruleset, systemctl status nftables firewall-nftables. Политика — белый список (предпочтительно) или мягкий вариант с явным финальным правилом."
"notes": "Apply deferred: требуется SSH на otreca (100.64.1.0 Tailscale и 109.248.161.5:22 оба timeout на 2026-10-10). VDS-провайдер должен восстановить доступ через KVM/IPMI/serial console. Proposal Option A в .agent/decisions/proposals/vds-nftables-fix.md готов к apply. До восстановления SSH — только README-уровень."
},
{
"id": "T4",
@@ -97,16 +97,16 @@
"id": "T5",
"title": "B2: зафиксировать, что бэкапов в конфигурации нет",
"type": "documentation",
"status": "pending",
"status": "completed",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
"В project-rules.md (R1.x) явно сказано, что бэкапы вне Nix",
"В project-rules.md (R1.x) явно сказано, что бэкапов в конфигурации нет",
"В project-state.md Open Concerns указано, что бэкапы — внешние"
],
"files": [".agent/rules/project-rules.md", ".agent/context/project-state.md"],
"files": [".agent/rules/project-rules.md", ".agent/context/project-state.md", ".agent/decisions/0002-backups-external.md"],
"blocks": [],
"notes": "Ждёт ответа 5.6 — где бэкапы и как проверять. Не код, а запись."
"notes": "Open question 5.6 (where are backups) не отвечен владельцем. Принят accepted risk: R1.9 formalized in project-rules.md: «Backups: external/unknown — accepted risk». Risk table + decision в .agent/decisions/0002-backups-external.md. Если владелец в будущем ответит на 5.6 — R1.9 отменяется и заменяется на R1.x с описанием бэкап-стратегии."
},
{
"id": "T6",