Some checks failed
Demo images / Build & push demo images (push) Failing after 1m32s
The full backup carried identity/lnd_aezeed.enc but NOT the per-node wallet secret that encrypts it (secrets/lnd-wallet-password), so a restored node could never decrypt its Lightning seed. The secrets dir now rides the backup (archive v3; the .bak itself is passphrase-encrypted). Restore gains a staging-presence guard so restoring an older archive without a secrets dir can no longer displace and delete the node's live secrets — covered by two new tests. Backups can now also be downloaded through the browser: a session-gated GET /api/blob/backup/<id> endpoint (under the existing nginx /api/blob prefix, so no fleet nginx changes) plus a Download button next to Verify / USB / Restore / Delete in Settings → Backup & Restore. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>