{
  "report_version": 1,
  "kind": "monthly-no-log-audit",
  "host": "vpn",
  "month": "2026-10",
  "state": "month-to-date",
  "generated_at": "2026-10-09T09:44:29Z",
  "status": "clean",
  "all_ok": true,
  "coverage": {
    "expected_days": 9,
    "days_with_report": 9,
    "days_missing": [],
    "archive_starts": "2026-09-18"
  },
  "signatures": {
    "checked": 9,
    "verified": 9,
    "unverified": []
  },
  "violations": {
    "count": 0,
    "check_failures": [],
    "signature_failures": [],
    "unreadable_reports": []
  },
  "checks": [
    {
      "id": "adguard:fleet:buffer",
      "ok_days": 8,
      "fail_days": 0
    },
    {
      "id": "adguard:fleet:no-querylog-file",
      "ok_days": 8,
      "fail_days": 0
    },
    {
      "id": "adguard:fleet:querylog_config",
      "ok_days": 8,
      "fail_days": 0
    },
    {
      "id": "adguard:fleet:stats_config",
      "ok_days": 8,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2:buffer",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2:no-querylog-file",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2:querylog_config",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "adguard:wg2:stats_config",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "blocky:fleet:no-querylog-file",
      "ok_days": 1,
      "fail_days": 0
    },
    {
      "id": "blocky:fleet:querylog-off",
      "ok_days": 1,
      "fail_days": 0
    },
    {
      "id": "journal:no-client-tier-address",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "nolog:adguardhome-nolog",
      "ok_days": 8,
      "fail_days": 0
    },
    {
      "id": "nolog:clientsv-nolog-primary",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "unbound:/etc/unbound-client/unbound.conf",
      "ok_days": 9,
      "fail_days": 0
    },
    {
      "id": "unbound:/etc/unbound/unbound.conf",
      "ok_days": 9,
      "fail_days": 0
    }
  ],
  "key_fingerprints": [
    "256 SHA256:nLZOwc5NYNz4dWnTI6ZDOYi3IGsiFj9yhKEs/VzCpzY logging-audit@vpn (ED25519)"
  ],
  "system_generations": [
    {
      "generation": "/nix/store/1xih1nf0zxcvrp2yyvqvb7svnzksmyy7-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-05",
      "last_seen": "2026-10-05"
    },
    {
      "generation": "/nix/store/6gkbzcbij41ksizg5gnjim37ncx28qz7-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-07",
      "last_seen": "2026-10-07"
    },
    {
      "generation": "/nix/store/lbqbkv9z8rhlkphw6n2kswhyxx7ssnfg-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-08",
      "last_seen": "2026-10-08"
    },
    {
      "generation": "/nix/store/najkk5zz57rij9n5p12a0x0c34gn37dw-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-09",
      "last_seen": "2026-10-09"
    },
    {
      "generation": "/nix/store/nbbgimpfscgzmfx4ny4nx6wrdiglb8j8-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-02",
      "last_seen": "2026-10-02"
    },
    {
      "generation": "/nix/store/nf5nzj4n0r6sclhbw5qqngz7cyyz0v33-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-01",
      "last_seen": "2026-10-01"
    },
    {
      "generation": "/nix/store/r53md4fzhllfb0x4xh6qk8h3jsmrrwc4-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-06",
      "last_seen": "2026-10-06"
    },
    {
      "generation": "/nix/store/y38qsssgx285c9jpcv9y8gmwa4hfkvgs-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-03",
      "last_seen": "2026-10-03"
    },
    {
      "generation": "/nix/store/z0zjh983iwvbzz2qzjinq1jfkj7h3acx-nixos-system-vpn-26.11.20260909.7b66dac",
      "first_seen": "2026-10-04",
      "last_seen": "2026-10-04"
    }
  ],
  "retention": {
    "adguard-querylog": "disabled on the wg2 tier instance (the fleet instance on 11.0.0.1 is blocky now)",
    "blocky-querylog": "disabled on blocky-fleet: queryLog.type is forced to \"none\" by nix-config-private modules/resolver-blocky.nix (a host cannot override it; the module fails evaluation instead)",
    "hermes-lcm": "90d (enforced daily by systemd.timers.hermes-lcm-retention)",
    "journald": "30d local ceiling (a maximum, not an achieved window: size-bounded to 512M by NCFG-754, vpn's worst-case full-replay bound, where it holds ~2 d at the measured 235-312 MiB/day; the 14 d surface is VictoriaLogs, whole journal shipped off-host)",
    "victorialogs": "14d",
    "victoriametrics": "30d (per-device byte counters are attributable to a customer's device)"
  },
  "signing_key": {
    "type": "ssh-ed25519",
    "identity": "logging-audit@vpn",
    "allowed_signers": "logging-audit.allowed_signers",
    "fingerprint": "256 SHA256:nLZOwc5NYNz4dWnTI6ZDOYi3IGsiFj9yhKEs/VzCpzY logging-audit@vpn (ED25519)",
    "verify": "ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@vpn -n logging-audit -s 2026-10.json.sig < 2026-10.json"
  },
  "how_to_verify": [
    "Every figure above comes from the dated daily reports in history/ ; this summary is derived from them, not a replacement for them.",
    "Fetch monthly/2026-10.json and monthly/2026-10.json.sig from this host together with logging-audit.allowed_signers, then run the verify command in signing_key.verify from the directory that holds them.",
    "Each day listed in coverage can be re-checked the same way against history/vpn-<date>.json(.sig).",
    "The daily report itself records which checks ran and what each observed, so a reader can audit the auditor."
  ],
  "notes": [
    "state=month-to-date means the month is still running: it is rewritten on every run and its hash WILL change. state=final means the month is closed and the report is frozen - its hash must not change again.",
    "days_missing are coverage gaps (no report was published that day), not passes and not violations; a gap is stated rather than filled in.",
    "check_failures are periods during which an invariant was VIOLATED. A failing daily report is still written and signed before the audit unit fails, so a violation cannot be hidden by the failure itself.",
    "retention values are DECLARED from the configuration, recorded here so a change to them shows up as a diff.",
    "The audit runs on the hosts it audits. A reader who does not trust the host should treat it as self-reported evidence whose value comes from being signed, dated, published, and reproducible from published configuration - not from an independent third party."
  ]
}
