{
  "report_version": 1,
  "kind": "monthly-no-log-audit",
  "host": "public",
  "month": "2026-09",
  "state": "month-to-date",
  "generated_at": "2026-09-19T09:29:31Z",
  "status": "incomplete",
  "all_ok": false,
  "coverage": {
    "expected_days": 19,
    "days_with_report": 2,
    "days_missing": [
      "2026-09-01",
      "2026-09-02",
      "2026-09-03",
      "2026-09-04",
      "2026-09-05",
      "2026-09-06",
      "2026-09-07",
      "2026-09-08",
      "2026-09-09",
      "2026-09-10",
      "2026-09-11",
      "2026-09-12",
      "2026-09-13",
      "2026-09-14",
      "2026-09-15",
      "2026-09-16",
      "2026-09-17"
    ],
    "archive_starts": "2026-09-18"
  },
  "signatures": {
    "checked": 2,
    "verified": 2,
    "unverified": []
  },
  "violations": {
    "count": 0,
    "check_failures": [],
    "signature_failures": [],
    "unreadable_reports": []
  },
  "checks": [
    {
      "id": "adguard:wg2-standby:buffer",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:no-querylog-file",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:querylog_config",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:stats_config",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "journal:no-client-tier-address",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "nolog:clientsv-nolog-standby",
      "ok_days": 2,
      "fail_days": 0
    },
    {
      "id": "unbound:/etc/unbound/unbound.conf",
      "ok_days": 2,
      "fail_days": 0
    }
  ],
  "key_fingerprints": [
    "256 SHA256:NkQoFKJH/tiH+K+8fICk3nCukwo35G+P4BdZDVnA/vU logging-audit@public (ED25519)"
  ],
  "system_generations": [
    {
      "generation": "/nix/store/9xmj5kfcdk07h3182zpssqri3hbcxvcs-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-09-18",
      "last_seen": "2026-09-18"
    },
    {
      "generation": "/nix/store/j0gyn6q1d2la1miafw0zvypvdlfa9n10-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-09-19",
      "last_seen": "2026-09-19"
    }
  ],
  "retention": {
    "adguard-querylog": "disabled (no querylog.json, no retrievable tier entries)",
    "journald": "14d (local; public's journal is NOT shipped off-host)"
  },
  "signing_key": {
    "type": "ssh-ed25519",
    "identity": "logging-audit@public",
    "allowed_signers": "logging-audit.allowed_signers",
    "fingerprint": "256 SHA256:NkQoFKJH/tiH+K+8fICk3nCukwo35G+P4BdZDVnA/vU logging-audit@public (ED25519)",
    "verify": "ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@public -n logging-audit -s 2026-09.json.sig < 2026-09.json"
  },
  "how_to_verify": [
    "Every figure above comes from the dated daily reports in history/ ; this summary is derived from them, not a replacement for them.",
    "Fetch monthly/2026-09.json and monthly/2026-09.json.sig from this host together with logging-audit.allowed_signers, then run the verify command in signing_key.verify from the directory that holds them.",
    "Each day listed in coverage can be re-checked the same way against history/public-<date>.json(.sig).",
    "The daily report itself records which checks ran and what each observed, so a reader can audit the auditor."
  ],
  "notes": [
    "state=month-to-date means the month is still running: it is rewritten on every run and its hash WILL change. state=final means the month is closed and the report is frozen - its hash must not change again.",
    "days_missing are coverage gaps (no report was published that day), not passes and not violations; a gap is stated rather than filled in.",
    "check_failures are periods during which an invariant was VIOLATED. A failing daily report is still written and signed before the audit unit fails, so a violation cannot be hidden by the failure itself.",
    "retention values are DECLARED from the configuration, recorded here so a change to them shows up as a diff.",
    "The audit runs on the hosts it audits. A reader who does not trust the host should treat it as self-reported evidence whose value comes from being signed, dated, published, and reproducible from published configuration - not from an independent third party."
  ]
}
