feat(skills): ship ha-git-backup — two-circuit HA backup ops-companion skill

Circuit 1: real git in /config (deploy key, pre-commit secret scanner,
meaningful commits). Circuit 2: age-encrypted native HA backups in GitHub
Releases with rotation and a mandatory monthly restore drill. Ships
install/sync/scan/offsite/restore scripts, HA automations/snippets,
setup + architecture + incident + runbook references, EN + RU skill docs.
README/README.ru gain an ops-companion bullet in Scenario 3;
CHANGELOG [Unreleased] Added entry (no version bump).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Nikolay Miroshnichenko
2026-07-07 22:15:44 +02:00
co-authored by Claude Fable 5
parent 74ac2ac830
commit 1aea8a6d9b
18 changed files with 802 additions and 0 deletions
+6
View File
@@ -8,6 +8,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
### Added
- **`skills/ha-git-backup`** — an ops-companion skill for the engineer package: a two-circuit
Home Assistant backup system (real git in `/config` with a deploy key and a pre-commit secret
scanner + age-encrypted full backups in GitHub Releases), with install/sync/scan/offsite/restore
scripts, HA automations, a restore runbook and a mandatory monthly drill. Field-tested;
the secret scanner ships canary-tested (BusyBox `grep -e` lesson recorded).
- **Manufacturer names from the archive itself** (`appprog_parser.py`): `parse_devices_from_project`
now reads vendor names from the `knx_master.xml` shipped inside every `.knxproj`/`.knxprod`
(e.g. M-0073 → HDL, M-00B6 → Ekinex S.p.A.) instead of relying on a hardcoded id map that can