{
  "report_version": 1,
  "host": "vpn",
  "generated_at": "2026-09-19T09:39:35Z",
  "system_generation": "/nix/store/qz7lm6y9biy8dcwb3g40zc7v7r3f3k1c-nixos-system-vpn-26.11.20260909.7b66dac",
  "all_ok": true,
  "checks": [
    {
      "id": "adguard:fleet:querylog_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:fleet:stats_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:fleet:no-querylog-file",
      "ok": true,
      "detail": "/var/lib/AdGuardHome/data/querylog.json absent after live queries; purge=False; probe reached the resolver=True (rc=0 after 1 attempt(s): dig @127.0.0.1 example.com A +time=3 +tries=1)"
    },
    {
      "id": "adguard:fleet:buffer",
      "ok": true,
      "detail": "in-memory entries=0 (before the probe: 0); canary audit-canary-4b3be58035.ymrtech.invalid present=False; grew=False \u2014 a present canary or growth means the resolver still logs, and that is a violation on every tier; a non-zero count that does neither is residue from before the disable, which only a restart clears"
    },
    {
      "id": "adguard:wg2:querylog_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:wg2:stats_config",
      "ok": true,
      "detail": "enforce POST accepted after 1 attempt(s); behavioural check below"
    },
    {
      "id": "adguard:wg2:no-querylog-file",
      "ok": true,
      "detail": "/var/lib/adguardhome-client/data/querylog.json absent after live queries; purge=False; probe reached the resolver=True (rc=0 after 1 attempt(s): dig -b 172.16.41.1 @172.16.41.1 example.com A +time=3 +tries=1)"
    },
    {
      "id": "adguard:wg2:buffer",
      "ok": true,
      "detail": "in-memory entries=0 (before the probe: 0); canary audit-canary-1ca59e127f.ymrtech.invalid present=False; grew=False \u2014 a present canary or growth means the resolver still logs, and that is a violation on every tier; a non-zero count that does neither is residue from before the disable, which only a restart clears"
    },
    {
      "id": "unbound:/etc/unbound/unbound.conf",
      "ok": true,
      "detail": "log-queries lines=none"
    },
    {
      "id": "unbound:/etc/unbound-client/unbound.conf",
      "ok": true,
      "detail": "log-queries lines=none"
    },
    {
      "id": "journal:no-client-tier-address",
      "ok": true,
      "detail": "0 client match(es) in 7153 line(s) of units adguardhome,adguardhome-client,unbound,unbound-client since 14 days ago; 373 non-client line(s) ignored (sudo audit trail, or this host's own gateway addresses)"
    },
    {
      "id": "nolog:adguardhome-nolog",
      "ok": true,
      "detail": "ActiveState=active ExecMainStatus=0 behavioural_ok=True"
    },
    {
      "id": "nolog:clientsv-nolog-primary",
      "ok": true,
      "detail": "ActiveState=active ExecMainStatus=0 behavioural_ok=True"
    }
  ],
  "retention": {
    "adguard-querylog": "disabled on both instances",
    "journald": "14d in VictoriaLogs (whole journal shipped off-host)",
    "victorialogs": "14d",
    "victoriametrics": "365d (no client identity: per-interface counters only)"
  },
  "notes": [
    "adguard:* checks ENFORCE the setting (idempotent POST), purge any persisted querylog, then require that a real query wrote nothing: the API has no read endpoint for this setting and its querylog GET serves stale memory.",
    "nolog:<unit> checks re-read the deploy-gated behavioural assertion (unit state + its NO-LOG OK journal line); they do not re-run the probe themselves.",
    "journal:no-client-tier-address scans only the resolver units named in queryUnits, and counts only lines naming a tier address this host does not own: provisioning output (the sudo audit trail, `ip route`/`ip address` commands) is counted and reported as non-client. It has still never seen real client traffic (no wg1/wg2 client has connected yet).",
    "retention values are DECLARED claims from the configuration, recorded here so a change to them is visible as a diff."
  ],
  "signing_key": {
    "type": "ssh-ed25519",
    "identity": "logging-audit@vpn",
    "allowed_signers": "logging-audit.allowed_signers",
    "fingerprint": "256 SHA256:nLZOwc5NYNz4dWnTI6ZDOYi3IGsiFj9yhKEs/VzCpzY logging-audit@vpn (ED25519)",
    "verify": "ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@vpn -n logging-audit -s logging-audit.json.sig < logging-audit.json"
  }
}
