- README: remove hardcoded srv paths; add configs/ to components table;
document BACKUP_CONF usage for multi-server setups; note DB_CONTAINER=
makes docker optional
- RUNBOOK: generalize §1 setup to use config variables (source config,
use $REPO / $BORG_PASSPHRASE_FILE / etc. instead of hardcoded paths);
§4 day-2 ops now shows source-config pattern before direct borg commands;
§5 recovery notes BACKUP_CONF for restore.sh; §6 drill uses config vars
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A3rQSEidP6Y61kaCtxjVV1
CLAUDE.md previously said the repo was encrypted, which was true when
written but no longer matches this deployment - the operator chose to
stay unencrypted, so the recurring "not encrypted" warning is expected
behavior, not something to fix.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>