{
  "report_version": 1,
  "host": "public",
  "generated_at": "2026-09-19T09:29:30Z",
  "system_generation": "/nix/store/j0gyn6q1d2la1miafw0zvypvdlfa9n10-nixos-system-public-26.11.20260909.7b66dac",
  "all_ok": true,
  "checks": [
    {
      "id": "adguard:wg2-standby:querylog_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:wg2-standby:stats_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:wg2-standby:no-querylog-file",
      "ok": true,
      "detail": "/var/lib/adguardhome-client-standby/data/querylog.json absent after live queries; purge=False; probe reached the resolver=True (rc=0 after 1 attempt(s): dig @127.0.0.1 example.com A +time=3 +tries=1)"
    },
    {
      "id": "adguard:wg2-standby:buffer",
      "ok": true,
      "detail": "in-memory entries=1 (before the probe: 1); canary audit-canary-081adb5c18.ymrtech.invalid present=False; grew=False \u2014 a present canary or growth means the resolver still logs, and that is a violation on every tier; a non-zero count that does neither is residue from before the disable, which only a restart clears"
    },
    {
      "id": "unbound:/etc/unbound/unbound.conf",
      "ok": true,
      "detail": "log-queries lines=none"
    },
    {
      "id": "journal:no-client-tier-address",
      "ok": true,
      "detail": "0 client match(es) in 1235 line(s) of units adguardhome-client-standby,unbound since 14 days ago; 58 non-client line(s) ignored (sudo audit trail, or this host's own gateway addresses)"
    },
    {
      "id": "nolog:clientsv-nolog-standby",
      "ok": true,
      "detail": "ActiveState=active ExecMainStatus=0 behavioural_ok=True"
    }
  ],
  "retention": {
    "adguard-querylog": "disabled (no querylog.json, no retrievable tier entries)",
    "journald": "14d (local; public's journal is NOT shipped off-host)"
  },
  "notes": [
    "adguard:* checks ENFORCE the setting (idempotent POST), purge any persisted querylog, then require that a real query wrote nothing: the API has no read endpoint for this setting and its querylog GET serves stale memory.",
    "nolog:<unit> checks re-read the deploy-gated behavioural assertion (unit state + its NO-LOG OK journal line); they do not re-run the probe themselves.",
    "journal:no-client-tier-address scans only the resolver units named in queryUnits, and counts only lines naming a tier address this host does not own: provisioning output (the sudo audit trail, `ip route`/`ip address` commands) is counted and reported as non-client. It has still never seen real client traffic (no wg1/wg2 client has connected yet).",
    "retention values are DECLARED claims from the configuration, recorded here so a change to them is visible as a diff."
  ],
  "signing_key": {
    "type": "ssh-ed25519",
    "identity": "logging-audit@public",
    "allowed_signers": "logging-audit.allowed_signers",
    "fingerprint": "256 SHA256:NkQoFKJH/tiH+K+8fICk3nCukwo35G+P4BdZDVnA/vU logging-audit@public (ED25519)",
    "verify": "ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@public -n logging-audit -s logging-audit.json.sig < logging-audit.json"
  }
}
