{
  "report_version": 1,
  "kind": "monthly-no-log-audit",
  "host": "public",
  "month": "2026-10",
  "state": "month-to-date",
  "generated_at": "2026-10-09T09:40:54Z",
  "status": "clean",
  "all_ok": true,
  "coverage": {
    "expected_days": 9,
    "days_with_report": 9,
    "days_missing": [],
    "archive_starts": "2026-09-18"
  },
  "signatures": {
    "checked": 9,
    "verified": 9,
    "unverified": []
  },
  "violations": {
    "count": 0,
    "check_failures": [],
    "signature_failures": [],
    "unreadable_reports": []
  },
  "checks": [
    {
      "id": "adguard:wg2-standby:buffer",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:no-querylog-file",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:querylog_config",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2-standby:stats_config",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "journal:no-client-tier-address",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "nolog:clientsv-nolog-standby",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "unbound:/etc/unbound/unbound.conf",
      "ok_days": 9,
      "fail_days": 0
    }
  ],
  "key_fingerprints": [
    "256 SHA256:NkQoFKJH/tiH+K+8fICk3nCukwo35G+P4BdZDVnA/vU logging-audit@public (ED25519)"
  ],
  "system_generations": [
    {
      "generation": "/nix/store/4ibjzxdc6vkdbf3wadp9s1naznvlrbv5-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-09",
      "last_seen": "2026-10-09"
    },
    {
      "generation": "/nix/store/9vi66mjnby0gn2my9gpy453bzn854wrq-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-07",
      "last_seen": "2026-10-07"
    },
    {
      "generation": "/nix/store/d0dbc0m95283kkibj7i3d31pfm7mfqq3-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-04",
      "last_seen": "2026-10-04"
    },
    {
      "generation": "/nix/store/gzxvwq1bdqkgnxbpdllcm60zp1pb6dkl-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-08",
      "last_seen": "2026-10-08"
    },
    {
      "generation": "/nix/store/qcbgvficwsyavczfd87zi90qsz6xnr3i-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-01",
      "last_seen": "2026-10-01"
    },
    {
      "generation": "/nix/store/qf68llbmqj7sr6rwyd15mxg40d019x13-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-05",
      "last_seen": "2026-10-05"
    },
    {
      "generation": "/nix/store/vk6x63zwn31zsvm6vk0khfwdywazr7kn-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-03",
      "last_seen": "2026-10-03"
    },
    {
      "generation": "/nix/store/x5yxrif6saihvwka9hb2gv63dxld5cdk-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-02",
      "last_seen": "2026-10-02"
    },
    {
      "generation": "/nix/store/yix171xlsr4jzavdc6ckxk51h139rhh4-nixos-system-public-26.11.20260909.7b66dac",
      "first_seen": "2026-10-06",
      "last_seen": "2026-10-06"
    }
  ],
  "retention": {
    "adguard-querylog": "disabled (no querylog.json, no retrievable tier entries)",
    "journald": "30d local ceiling (a maximum, not an achieved window: size-bounded, ~18d at the measured rate), AND 14d in VictoriaLogs on mail (shipped off-host since 2026-09-22, WP4)"
  },
  "signing_key": {
    "type": "ssh-ed25519",
    "identity": "logging-audit@public",
    "allowed_signers": "logging-audit.allowed_signers",
    "fingerprint": "256 SHA256:NkQoFKJH/tiH+K+8fICk3nCukwo35G+P4BdZDVnA/vU logging-audit@public (ED25519)",
    "verify": "ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@public -n logging-audit -s 2026-10.json.sig < 2026-10.json"
  },
  "how_to_verify": [
    "Every figure above comes from the dated daily reports in history/ ; this summary is derived from them, not a replacement for them.",
    "Fetch monthly/2026-10.json and monthly/2026-10.json.sig from this host together with logging-audit.allowed_signers, then run the verify command in signing_key.verify from the directory that holds them.",
    "Each day listed in coverage can be re-checked the same way against history/public-<date>.json(.sig).",
    "The daily report itself records which checks ran and what each observed, so a reader can audit the auditor."
  ],
  "notes": [
    "state=month-to-date means the month is still running: it is rewritten on every run and its hash WILL change. state=final means the month is closed and the report is frozen - its hash must not change again.",
    "days_missing are coverage gaps (no report was published that day), not passes and not violations; a gap is stated rather than filled in.",
    "check_failures are periods during which an invariant was VIOLATED. A failing daily report is still written and signed before the audit unit fails, so a violation cannot be hidden by the failure itself.",
    "retention values are DECLARED from the configuration, recorded here so a change to them shows up as a diff.",
    "The audit runs on the hosts it audits. A reader who does not trust the host should treat it as self-reported evidence whose value comes from being signed, dated, published, and reproducible from published configuration - not from an independent third party."
  ]
}
