Felhom Hub

← Hosts

tester-1-33b6a9

ONLINE
Host ID tester-1-33b6a9
Customer Tester 1
Agent Version 0.131.0
PBS wrapper matches vouched 104db0a4401f…
Enrolled 2h ago
Last Report 4 min ago
Desired Generation 2

Vitals

CPU 0%
Memory 29%
Disk (root fs) 40%
Cloudflared inactive
Guests 1/1 running

Guests

VMID Name Status Controller Last Seen
9201 tester-1 running — 4 min ago

Storage Targets

Name Role Type State Fill Thin Pool SMART Temp Wear
felhom-pbs — pbs attached 0% — UNKNOWN — —
local — local attached 40% — UNKNOWN 0°C —
local-lvm — lvmthin attached 62% 62% UNKNOWN — —

Capabilities

Capability Status Feature / reason
controllerswap-image-inspect critical ok controller-swap / managed auto-update
controllerswap-inspect critical ok controller-swap / managed auto-update
controllerswap-read critical ok controller-swap / managed auto-update
controllerswap-restart critical ok controller-swap / managed auto-update
controllerswap-write critical ok controller-swap / managed auto-update
disk-blkid critical ok disk data-bearing classify (format gate)
disk-lsblk critical ok disk topology read (format gate)
disk-lvs ok thin-pool usage read
disk-mkfs-ext4 critical ok guarded format (ext4)
disk-mkfs-xfs ok guarded format (xfs)
disk-smart ok disk SMART health read
dnsmasq-enable ok dnsmasq enable
dnsmasq-guest-domain ok guest domain discovery
dnsmasq-guest-ip ok guest LAN IP discovery
dnsmasq-install ok dnsmasq package install
dnsmasq-reload ok dnsmasq reload
dnsmasq-restart ok dnsmasq restart (LAN-DNS self-heal)
dnsmasq-rm ok dnsmasq drop-in remove (decommission)
dnsmasq-write ok dnsmasq drop-in write
drive-bind critical ok drive attach (felhom-data bind under parent)
drive-umount critical ok drive detach (fail-closed unmount)
drives-chown-data ok felhom-data guest-root chown
drives-mkdir-data ok felhom-data namespace create
drives-mkdir-parent ok stable parent dir create
drives-mkdir-sub ok per-drive stable dir create
escrow-ceremony critical ok customer recovery-code ceremony (controller-driven)
guest-init-pid critical ok drive-gate guest-sees check (multi-drive concurrency)
guest-reboot ok enroll activate-binds reboot
guesthook-delete-mp ok dead mountpoint slot delete (C1 net)
guesthook-install ok pre-start hook snippet install
guesthook-register ok pre-start hook register
guestnet-dhclient-probe ok guest DHCP-client liveness probe
guestnet-heal ok guest DHCP-client restart (the 2026-07-20 heal)
guestnet-ifaces ok guest interface-mode read
guestnet-route ok guest default-route probe
mount-daemon-reload ok systemd reload after unit write
mount-unit-disable ok mount unit disable
mount-unit-enable ok mount unit enable
mount-unit-install ok fs-UUID mount unit install
mount-unit-stop ok mount unit stop
netmount-reset-failed ok NAS automount re-arm after start-limit (F10)
netmount-rmdir ok removed-share mountpoint cleanup (F1)
parent-bind-mp8 ok parent bind into guest at provision
parent-make-private critical ok intermediary shared-parent peer-group isolation
parent-make-shared critical ok intermediary shared-parent propagation
parent-script-install ok shared-parent boot script install
parent-self-bind critical ok intermediary shared-parent self-bind
parent-unit-enable ok shared-parent boot-persistence enable
parent-unit-install ok shared-parent boot unit install
pbsdr-create ok PBS DR storage-entry create (K autogen)
pbsdr-grant ok PBS DR storage ACL self-grant
pbsdr-read ok PBS DR credential read (verify-loop auth probe)
pbsdr-reconcile ok PBS DR storage-entry reconcile (set-only)
provision-chown ok bootstrap mount guest-root chown
provision-config-mount ok bootstrap config bind mount
provision-onboot ok customer guest autostart (onboot)
pve:pool-read ok stale-lock recovery scoping (pool ownership check)
pve:store-grant:felhom-pbs critical ok backup tier felhom-pbs readable by the agent (archive listing, restore-test candidacy)
pve:store-grant:local ok backup tier local readable by the agent (archive listing, restore-test candidacy)
selfheal-networking-start ok appliance networking recovery at boot (F12 defense in depth)
selfupdate-apply ok agent self-update apply (A/B flip)
selfupdate-commit ok agent self-update commit
selfupdate-rollback ok agent self-update rollback
stalelock-unlock critical ok reboot-during-backup stale-lock recovery
wg-conf-install critical ok wg-felhom conf install
wg-disable ok wg-quick@wg-felhom disable (revocation)
wg-enable critical ok wg-quick@wg-felhom enable
wg-handshake-read critical ok tunnel handshake-age read
wg-restart critical ok wg-quick@wg-felhom restart (conf change)
wg-tools-install ok wireguard-tools package install

Diagnostics — Log Bundles

Pull-based: the box ships its debug ring on its own next cycle — controller ≤ one report interval (~15 min), agent ≈ one heartbeat. The pull is recorded in the box's own log (customer-visible). Bundles expire after 72 h.

No log bundles. Use the request buttons above — the box delivers on its next cycle.

Network

WireGuard 10.77.0.5 confirmed
InterfaceAddress
vmbr0 192.168.0.101/24

Every routable address the box holds, as the kernel sees it. Loopback and link-local are excluded — including the 169.254.253.1 local-API island, which is identical on every box. The PVE web console is at https://<the LAN address>:8006.

Guest network healthy

GuestStateAddressRoutedhclientRepairs (1h)
9201 healthy 192.168.0.107 (dhcp) yes yes 0

Last swept 2026-09-16T17:46:20Z. One row per owned running guest the watchdog has probed.

DR / Backup

DR Recipe present
Key Escrow present

Console access

User root@pam
Password set 2h ago
••••••••••••••••

Break-glass credential for the PVE web console at https://<host-ip>:8006 (realm: Linux PAM standard authentication). Copy puts it straight on the clipboard without showing it; Reveal displays it for 60 s. Either one is recorded on the customer's event timeline. Last vaulted value — if root@pam was changed on the box without re-vaulting, this is stale.