| P0 |
Machine confirmation — assistant runs on .27 (sam-4screen-desktop); .13 reachable via sam@192.168.20.13 |
hostname sam-4screen-desktop = .27 |
| P1 |
AWS account ready; IAM user backup-offsite created (programmatic, least-priv) |
— |
| P1 |
Credentials verified via AWS STS (get-caller-identity) |
Account 648879824522, user backup-offsite, region ap-southeast-2 |
| P1 |
Credentials stored local-only (aws-credentials.local 0600, .27) + copied to .13 (~/.aws-credentials.local.new 0600). Not in Obsidian. |
— |
| P1 |
Verified .13 has no aws-cli/rclone; will use one-off nix-shell awscli2 for imperative steps until backup.nix updated |
verified |
| P1 |
STS key check OK (Account 648879824522, user backup-offsite); created env-helper ~/.aws-offsite-env.sh on .13 (0600, sources creds from file, no secrets echoed) |
verified |
| P1 |
MFA: root MFA enabled in console; Ente Auth as authenticator (phone). Ente recovery keyphrase stored in local aws-credentials.local (0600), NOT Obsidian |
— |
| P1 |
Blocked on expanded IAM policy attach (bucket-mgmt + object actions scoped to sam-offsite-backup) before bucket+lifecycle can be created |
awaiting user |
| P1 |
Bucket sam-offsite-backup created (ap-southeast-2, ACLs disabled, all public-access blocked, versioning enabled) — created via console as root; IAM backup-offsite kept object-only |
created |
| P1 |
Object pipeline verified on .13: PUT/LIST/GET/DELETE probe to s3://sam-offsite-backup/test/ all succeeded via backup-offsite |
probe-write, content readback OK |
| P1 |
TODO: add lifecycle rule (S3→Glacier Flexible@30d→Glacier Deep Archive@90d) — IAM backup-offsite lacks lifecycle perm, so rule will be created via console (root) |
pending |
| P1 |
Lifecycle rule archive-to-glacier created via console (root): S3 Standard → Glacier Flexible @ 90 days → Glacier Deep Archive @ 180 days (current AWS min: 90/180) |
user-confirmed in console |
| P1 |
Pipeline chosen: AWS CLI s3 sync (NOT rclone). rclone fought S3 region-discovery (needs ListAllMyBuckets/GetBucketLocation which least-priv reserved user lacks); AWS CLI works with object-only perms. |
validated: full UP/LIST/READBACK/DELETE sync test passed on sam-offsite-backup |
| P1 |
Cleaned up temp rclone config + test scripts on .13; kept ~/.aws-offsite-env.sh env helper (0600, reads creds from file, no secrets echoed) |
— |
| P1 |
Bandwidth probe on .13: ~3.3 MB/s upstream to AWS → ~62 h for full ~712 GB seed |
measured |
| P1 |
Wrote Backup Architecture — Offsite to AWS S3 note (source set, tech stack, procedure, cost, status) |
obsidian |
| P1 |
Refined source set (~712 GB): photos/by_date(373G), photos/phone-only(.35 Immich, small), archive/rest(177G), borg/.27(162G). Skips duplicates/transient/regenerable |
per Google-photos agent note |
| P1 |
Awaiting user go/no-go on seed scope + storage-class (Standard vs Deep Archive for cold set) |
decision needed |