CLI command

skarbiec recovery-drill

Prove that exactly one expected recovery identity in an isolated keyring can decrypt a deterministic live canary.

Invocation#

Shell
skarbiec recovery-drill <recipient-uid|recovery>

Purpose#

Prove that exactly one expected recovery identity in an isolated keyring can decrypt a deterministic live canary.

Required inputs and options#

  • Requires a registered recovery recipient uid or the literal recovery. GNUPGHOME must point to an isolated keyring containing only that expected vault opener.

Output and state effects#

  • Decrypts and discards the lowest live item as a canary, appends pass/fail evidence, and prints status, recipient, fingerprint, canary_item, and isolated_keyring.

Refusals#

  • Refuses a missing secret half, a non-isolated keyring with another vault opener, an unknown recipient, or an empty vault.