feat: DID persistence + federation node names in sync
Part 1 — DID Persistence: - Deploy script creates /var/lib/archipelago/identity/ directory - First-boot script creates identity dir with proper ownership - Identity load now logs pubkey to confirm persistence across restarts Part 2 — Node Names: - NodeStateSnapshot includes node_name field - build_local_state() passes server name to sync responses - update_node_state() stores peer's announced name on the FederatedNode - Names propagate automatically during federation.sync-state Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
f8eefa87d2
commit
f8794791f3
@@ -17,6 +17,7 @@
|
||||
| **TASK-10** | **ISO build verification + multi-hardware test** | **P1** | PLANNED | - |
|
||||
| **TASK-12** | **Beta telemetry — reporter + toggle + collector POST** | **P1** | IN PROGRESS | - |
|
||||
| **TASK-39** | **Finish .198 rootless container migration** | **P1** | PLANNED | TASK-11 |
|
||||
| **TASK-42** | **LUKS2 full-partition encryption for /var/lib/archipelago/** | **P1** | PLANNED | TASK-10 |
|
||||
|
||||
### Phase 2: User Testing (controlled, real hardware)
|
||||
|
||||
@@ -105,6 +106,44 @@ Tag every significant alpha version with git tags for easy rollback. Each tag sh
|
||||
|
||||
---
|
||||
|
||||
### TASK-42: LUKS2 full-partition encryption for /var/lib/archipelago/ (PLANNED)
|
||||
**Priority**: P1 — High
|
||||
**Status**: PLANNED (2026-03-19)
|
||||
|
||||
Encrypt all Archipelago app data at rest using LUKS2 full-partition encryption. Protects Bitcoin wallet data, LND macaroons, FileBrowser files, Vaultwarden vault, secrets, and everything else from physical disk seizure. Seamless UX — user never interacts with encryption directly.
|
||||
|
||||
**Design**:
|
||||
- LUKS2 partition for `/var/lib/archipelago/` created during ISO install
|
||||
- Cipher: AES-256-XTS (hardware AES-NI on x86_64, ChaCha20 fallback on ARM without AES-NI)
|
||||
- Key derived from setup password via Argon2id + hardware salt (`/sys/class/dmi/id/product_uuid`)
|
||||
- Key file stored at `/root/.luks-archipelago.key` (root:600, on boot partition)
|
||||
- Auto-unlock via `/etc/crypttab` on every boot — no passphrase prompt
|
||||
- Password change in Settings re-derives key and rotates LUKS keyslot
|
||||
|
||||
**Threat model**:
|
||||
- Disk removed from machine = fully encrypted, unreadable
|
||||
- Running machine with login = transparent (same as today)
|
||||
- Forgot password = cannot decrypt (correct sovereign behavior)
|
||||
|
||||
**Tasks**:
|
||||
- [ ] ISO installer: create LUKS2 partition, format + mount at `/var/lib/archipelago/`
|
||||
- [ ] First-boot: derive LUKS key from setup password via Argon2id + hardware salt
|
||||
- [ ] Store key file at `/root/.luks-archipelago.key` with 600 perms
|
||||
- [ ] Configure `/etc/crypttab` for auto-unlock at boot
|
||||
- [ ] Settings password change: re-derive LUKS key, add new keyslot, remove old
|
||||
- [ ] Detect AES-NI availability, fall back to ChaCha20 on ARM without it
|
||||
- [ ] Test: fresh install, reboot survives, power-cycle survives, password change works
|
||||
- [ ] Test: disk removed from machine is unreadable
|
||||
- [ ] Update `BUILD-GUIDE.md` and `image-recipe/build-auto-installer-iso.sh`
|
||||
|
||||
**Key files**:
|
||||
- `image-recipe/build-auto-installer-iso.sh` — partition creation
|
||||
- `scripts/first-boot-containers.sh` — runs after LUKS mount
|
||||
- `core/archipelago/src/api/rpc/system.rs` — password change handler
|
||||
- `core/archipelago/src/server.rs` — startup checks
|
||||
|
||||
---
|
||||
|
||||
## Post-Beta (FROZEN)
|
||||
|
||||
*These tasks are deferred until after beta ships. Do not start.*
|
||||
|
||||
Reference in New Issue
Block a user