{
  "schema": 1,
  "generated_at": "2026-10-08T06:10:03Z",
  "doctrine": "Attack yourself first.",
  "order": [
    "verified_restore",
    "backup_jobs",
    "offsite_copy",
    "immutable_copy",
    "self_heal",
    "awaiting_approval",
    "drift_detectors",
    "adversarial_review",
    "offnet_probe",
    "agent_paths_to_vault",
    "nodes_up"
  ],
  "metrics": {
    "verified_restore": {
      "label": "Last verified restore",
      "value": "1 h ago",
      "status": "ok",
      "detail": "Most recent successful restore evidence: Specola automated restore.",
      "source": "prometheus: specola_dr_last_restore_success"
    },
    "backup_jobs": {
      "label": "Backup jobs healthy",
      "value": "22 / 23 healthy",
      "status": "red",
      "detail": "1 unhealthy and 0 older than 48 h.",
      "source": "prometheus: backup_healthy, backup_last_success_seconds"
    },
    "offsite_copy": {
      "label": "Off-site copy freshness (Iceland)",
      "value": "3 h ago",
      "status": "ok",
      "detail": "Freshness of the Iceland coldiron off-site backup job.",
      "source": "prometheus: time()-backup_last_success_seconds"
    },
    "immutable_copy": {
      "label": "Immutable off-site copy",
      "value": "yes",
      "status": "ok",
      "detail": "Two layers since 2026-09-03. (1) coldIRON serves the Iceland restic repository through rest-server --append-only (dedicated restsrv user, mode 0700, tailnet-only), so the push identity on tensor-core cannot forget or delete (PT-2010, 403 verified). (2) PT-2032: a second host, coldbaron-vm, is the vault proper: it PULLS coldIRON's DR sets every 2h over a read-only rrsync forced command into hardlinked generations retained 90 days (never fewer than 10). No fleet identity can log in to it: the tailnet policy allows the fleet exporter scrapes only, its sshd holds the operator's device keys alone, and its Hyper-V host is in the same class. coldIRON itself is an ordinary agent-reachable node again; an agent that destroyed coldIRON's copy would find the previous generations intact in the vault.",
      "source": "manual.json"
    },
    "self_heal": {
      "label": "Self-healing, 30 d",
      "value": "62 cured \u00b7 22 self-cleared \u00b7 19 failed \u00b7 28 escalated \u00b7 33 held",
      "status": "ok",
      "detail": "pureMEND last cycled 34 sec ago. Counts cover pureMEND's runs since it went live on 2026-10-03; 23% of cure attempts failed (ok through 25%, warn through 50%). Held faults wait quietly for a later look; only a tensor-core reboot or a destructive deletion reaches the operator.",
      "source": "puremend.db runs, 30 d; prometheus: puremend_cycle_timestamp_seconds"
    },
    "awaiting_approval": {
      "label": "Findings held for human approval",
      "value": "0",
      "status": "ok",
      "detail": "pureMEND approval cards awaiting the operator: only a tensor-core reboot or a destructive deletion needs one. The count is not treated as a failure.",
      "source": "prometheus: puremend_approvals{status=\"requested\"}"
    },
    "drift_detectors": {
      "label": "Drift detectors",
      "value": "1 / 4 ran, 0 mutations",
      "status": "red",
      "detail": "1 fresh, 3 stale, and 0 failed systemd runs; firmware Prometheus check passed.",
      "source": "systemd show + journal; prometheus: fw_drift, verity_drift"
    },
    "adversarial_review": {
      "label": "Adversarial review, 30 d (opened \u00b7 merged \u00b7 closed unmerged)",
      "value": "1323 \u00b7 1292 \u00b7 18",
      "status": "ok",
      "detail": "Pull-request activity over the trailing 30-day evidence window.",
      "source": "adversarial_prs.json"
    },
    "offnet_probe": {
      "label": "Last off-net exposure probe",
      "value": "2026-08-29",
      "status": "ok",
      "detail": "Second-opinion security survey probed from an off-net vantage; open recursive-DNS finding falsified, 7 hardening actions same day.",
      "source": "manual.json"
    },
    "agent_paths_to_vault": {
      "label": "Agent identities with a path to DR/backup storage",
      "value": "0",
      "status": "ok",
      "detail": "11 LLM-driven agent seats probed inside their own systemd sandbox; 0 hold a direct or transitive path to the restic repositories or the Iceland DR host.",
      "source": "audit/agent_vault_audit.py"
    },
    "nodes_up": {
      "label": "Monitored targets up",
      "value": "114 targets up",
      "status": "ok",
      "detail": "Current count of monitored Prometheus targets reporting up.",
      "source": "prometheus: count(up==1)"
    }
  }
}
