# YMRTECH VPN - monthly no-log audit - October 2026

**Host:** `vpn`  
**State:** month-to-date  
**Status:** CLEAN  
**Generated:** 2026-10-09T09:44:29Z  
**Report version:** 1

## Result

| | |
|---|---|
| Days with a signed report | 9 of 9 expected |
| Days missing (no report published) | 0 |
| Daily signatures checked / verified | 9 / 9 |
| Violations and unverifiable reports | 0 |

## Checks

| Check | Days passed | Days failed | What it asserts |
|---|---|---|---|
| `adguard:fleet:buffer` | 8 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:fleet:no-querylog-file` | 8 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:fleet:querylog_config` | 8 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:fleet:stats_config` | 8 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:wg2:buffer` | 9 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:wg2:no-querylog-file` | 9 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:wg2:querylog_config` | 9 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `adguard:wg2:stats_config` | 9 | 0 | the resolver's query log and statistics are OFF (re-applied on every run), a persisted query log is purged, and a real query plus a unique canary name provably wrote nothing |
| `blocky:fleet:no-querylog-file` | 1 | 0 |  |
| `blocky:fleet:querylog-off` | 1 | 0 |  |
| `journal:no-client-tier-address` | 9 | 0 | the shipped system journal contains no client-tier address from the VPN tunnel ranges |
| `nolog:adguardhome-nolog` | 8 | 0 | the behavioural no-log unit was re-run and succeeded (a live lookup was sent and left no log) |
| `nolog:clientsv-nolog-primary` | 9 | 0 | the behavioural no-log unit was re-run and succeeded (a live lookup was sent and left no log) |
| `unbound:/etc/unbound-client/unbound.conf` | 9 | 0 | the effective unbound configuration contains no log-queries directive |
| `unbound:/etc/unbound/unbound.conf` | 9 | 0 | the effective unbound configuration contains no log-queries directive |

No invariant was violated in this period, and every daily report's signature verified.

## What was running

Each distinct `system_generation` seen in the month, i.e. the deployed configuration the checks ran against:

| System generation | First seen | Last seen |
|---|---|---|
| `/nix/store/1xih1nf0zxcvrp2yyvqvb7svnzksmyy7-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-05 | 2026-10-05 |
| `/nix/store/6gkbzcbij41ksizg5gnjim37ncx28qz7-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-07 | 2026-10-07 |
| `/nix/store/lbqbkv9z8rhlkphw6n2kswhyxx7ssnfg-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-08 | 2026-10-08 |
| `/nix/store/najkk5zz57rij9n5p12a0x0c34gn37dw-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-09 | 2026-10-09 |
| `/nix/store/nbbgimpfscgzmfx4ny4nx6wrdiglb8j8-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-02 | 2026-10-02 |
| `/nix/store/nf5nzj4n0r6sclhbw5qqngz7cyyz0v33-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-01 | 2026-10-01 |
| `/nix/store/r53md4fzhllfb0x4xh6qk8h3jsmrrwc4-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-06 | 2026-10-06 |
| `/nix/store/y38qsssgx285c9jpcv9y8gmwa4hfkvgs-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-03 | 2026-10-03 |
| `/nix/store/z0zjh983iwvbzz2qzjinq1jfkj7h3acx-nixos-system-vpn-26.11.20260909.7b66dac` | 2026-10-04 | 2026-10-04 |

## Retention declared by the configuration

| Data | Retention |
|---|---|
| adguard-querylog | disabled on the wg2 tier instance (the fleet instance on 11.0.0.1 is blocky now) |
| blocky-querylog | disabled on blocky-fleet: queryLog.type is forced to "none" by nix-config-private modules/resolver-blocky.nix (a host cannot override it; the module fails evaluation instead) |
| hermes-lcm | 90d (enforced daily by systemd.timers.hermes-lcm-retention) |
| journald | 30d local ceiling (a maximum, not an achieved window: size-bounded to 512M by NCFG-754, vpn's worst-case full-replay bound, where it holds ~2 d at the measured 235-312 MiB/day; the 14 d surface is VictoriaLogs, whole journal shipped off-host) |
| victorialogs | 14d |
| victoriametrics | 30d (per-device byte counters are attributable to a customer's device) |

## Verify this report

```sh
curl -O https://vpn.ymrtech.com/logging-audit/logging-audit.allowed_signers
curl -O https://vpn.ymrtech.com/logging-audit/monthly/2026-10.json
curl -O https://vpn.ymrtech.com/logging-audit/monthly/2026-10.json.sig
ssh-keygen -Y verify -f logging-audit.allowed_signers -I logging-audit@vpn -n logging-audit -s 2026-10.json.sig < 2026-10.json
```

Every daily report can be checked the same way, and the raw machine-readable report for this month is `monthly/2026-10.json`.

- Every figure above comes from the dated daily reports in history/ ; this summary is derived from them, not a replacement for them.
- Fetch monthly/2026-10.json and monthly/2026-10.json.sig from this host together with logging-audit.allowed_signers, then run the verify command in signing_key.verify from the directory that holds them.
- Each day listed in coverage can be re-checked the same way against history/vpn-<date>.json(.sig).
- The daily report itself records which checks ran and what each observed, so a reader can audit the auditor.

Signing key: `256 SHA256:nLZOwc5NYNz4dWnTI6ZDOYi3IGsiFj9yhKEs/VzCpzY logging-audit@vpn (ED25519)`

## Notes

- state=month-to-date means the month is still running: it is rewritten on every run and its hash WILL change. state=final means the month is closed and the report is frozen - its hash must not change again.
- days_missing are coverage gaps (no report was published that day), not passes and not violations; a gap is stated rather than filled in.
- check_failures are periods during which an invariant was VIOLATED. A failing daily report is still written and signed before the audit unit fails, so a violation cannot be hidden by the failure itself.
- retention values are DECLARED from the configuration, recorded here so a change to them shows up as a diff.
- The audit runs on the hosts it audits. A reader who does not trust the host should treat it as self-reported evidence whose value comes from being signed, dated, published, and reproducible from published configuration - not from an independent third party.
