Oct 07 13:36:05 demo-hp felhom-agent[54286]: time=2026-10-07T13:36:05.870+02:00 level=WARN msg="osupdate: capability probe after the config bundle" ok=68 total=68 degraded=""
--- sudo -l (filtered)
0
(root) NOPASSWD: /usr/local/sbin/felhom-priv-apply ^unit mnt-[A-Za-z0-9_.\\-]+\.(mount|automount)$, /usr/bin/systemctl daemon-reload, /usr/bin/systemctl ^enable --now -- mnt-[A-Za-z0-9_.\\-]+\.mount$, /usr/bin/systemctl ^disable -- mnt-[A-Za-z0-9_.\\-]+\.mount$, /usr/bin/systemctl ^stop -- mnt-[A-Za-z0-9_.\\-]+\.mount$, /usr/sbin/smartctl ^-a -j /dev/(sd[a-z]+|nvme[0-9]+n[0-9]+|vd[a-z]+|hd[a-z]+)$, /usr/sbin/lvs ^--reportformat json --units b -o lv_name\,data_percent\,metadata_percent -- [A-Za-z0-9_.+-]+(/[A-Za-z0-9_.+-]+)?$, /usr/sbin/pvs --reportformat json --noheadings -o pv_name, /usr/sbin/zpool status -P, /usr/bin/chown ^-R 100000\:100000 /var/lib/felhom-agent/guests/[0-9]+(/bootstrap)?$, /usr/sbin/pct ^set [0-9]+ -mp[0-9]+ /var/lib/felhom-agent/guests/[0-9]+/bootstrap\,mp\=/[A-Za-z0-9/_.-]+(\,ro\=1)?$, /usr/sbin/pct ^set [0-9]+ -onboot 1$, /usr/sbin/blkid ^-p -o export /dev/[^ ]+$, /usr/bin/lsblk ^-J -o NAME\,FSTYPE\,PTTYPE\,MOUNTPOINT /dev/[^ ]+$, /usr/local/sbin/felhom-mkfs-guarded ^/dev/[^ ]+ (ext4|xfs)$, /usr/bin/apt-get install -y -q dnsmasq, /usr/local/sbin/felhom-priv-apply ^dnsmasq /tmp/felhom-resolver-[0-9]+\.conf felhom-[a-z0-9][a-z0-9._-]*\.conf$, /usr/bin/systemctl enable --now dnsmasq, /usr/bin/systemctl reload dnsmasq, /usr/bin/systemctl restart dnsmasq, /usr/bin/rm ^-f /etc/dnsmasq\.d/felhom-[a-z0-9][a-z0-9._-]*\.conf$, /usr/sbin/pct ^exec [0-9]+ -- ip -4 -o addr show dev eth0$, /usr/sbin/pct ^exec [0-9]+ -- docker exec felhom-controller cat /opt/docker/felhom-controller/controller\.yaml$, /usr/sbin/pct ^set [0-9]+ --hookscript local\:snippets/felhom-guest-hook\.sh$, /usr/sbin/pct ^set [0-9]+ --delete mp[0-9]+$, /usr/sbin/pct ^reboot [0-9]+$, /usr/bin/mkdir -p /mnt/felhom-drives, /usr/bin/mkdir ^-p /mnt/felhom-drives/[A-Za-z0-9_-][A-Za-z0-9_.-]*$, /usr/bin/mkdir ^-p /mnt/[A-Za-z0-9_-][A-Za-z0-9_.-]*/felhom-data$, /usr/bin/chown ^100000\:100000 /mnt/[A-Za-z0-9_-][A-Za-z0-9_.-]*/felhom-data$, /usr/bin/mount --bind /mnt/felhom-drives /mnt/felhom-drives, /usr/bin/mount --make-shared /mnt/felhom-drives, /usr/bin/mount --make-private /mnt/felhom-drives, /usr/bin/mount ^--bind /mnt/[A-Za-z0-9_-][A-Za-z0-9_.-]*/felhom-data /mnt/felhom-drives/[A-Za-z0-9_-][A-Za-z0-9_.-]*$, /usr/bin/umount ^/mnt/felhom-drives/[A-Za-z0-9_-][A-Za-z0-9_.-]*$, /usr/bin/systemctl enable felhom-shared-parent.service, /usr/bin/lxc-info ^-n [0-9]+ -p -H$, /usr/sbin/pct ^set [0-9]+ -mp8 /mnt/felhom-drives\,mp\=/mnt/felhom-drives$, /usr/sbin/pct ^exec [0-9]+ -- cat /etc/felhom-controller-image$, /usr/sbin/pct ^exec [0-9]+ -- docker image inspect gitea\.dooplex\.hu/admin/felhom-controller\:[0-9]+\.[0-9]+\.[0-9]+$, /usr/sbin/pct ^exec [0-9]+ -- docker inspect -f .+ (felhom-controller|cloudflared)$, /usr/sbin/pct ^exec [0-9]+ -- systemctl restart felhom-controller-bootstrap\.service$, /usr/local/sbin/felhom-priv-apply ^controller-image [0-9]+$, /usr/sbin/pct ^unlock [0-9]+$, /usr/sbin/pct ^fstrim [0-9]+$, /usr/bin/systemctl ^enable --now -- mnt-[A-Za-z0-9_.\\-]+\.automount$, /usr/bin/systemctl ^disable -- mnt-[A-Za-z0-9_.\\-]+\.automount$, /usr/bin/systemctl ^stop -- mnt-[A-Za-z0-9_.\\-]+\.automount$, /usr/bin/systemctl ^reset-failed -- mnt-felhom[A-Za-z0-9_.\\-]*\.(mount|automount)$, /usr/bin/rmdir ^/mnt/felhom-drives/[A-Za-z0-9_-][A-Za-z0-9_.-]*$, /usr/bin/rm ^-f /etc/systemd/system/mnt-felhom[A-Za-z0-9_.\\-]*\.(mount|automount)$, /usr/bin/apt-get install -y -q wireguard-tools, /usr/local/sbin/felhom-priv-apply wg, /usr/bin/systemctl enable --now wg-quick@wg-felhom, /usr/bin/systemctl restart wg-quick@wg-felhom, /usr/bin/systemctl disable --now wg-quick@wg-felhom, /usr/bin/wg show wg-felhom latest-handshakes, /usr/local/sbin/felhom-selfupdate-guarded commit, /usr/local/sbin/felhom-selfupdate-guarded rollback, /usr/local/sbin/felhom-priv-apply sshd-config, /usr/local/sbin/felhom-priv-apply sshd-key, /usr/sbin/sshd -t -f /var/lib/felhom-agent/felhom-sshd/sshd_config, /usr/sbin/sshd -t -f /etc/felhom-sshd/sshd_config, /usr/sbin/sshd -T -f /etc/felhom-sshd/sshd_config, /usr/bin/systemctl enable --now felhom-sshd, /usr/bin/systemctl reload felhom-sshd, /usr/bin/systemctl restart felhom-sshd, /usr/bin/systemctl reset-failed felhom-sshd, /usr/bin/wg show wg-felhom latest-handshakes, /usr/sbin/nft list set inet felhom_oob operator_ips, /usr/sbin/nft list set inet felhom_oob ssh_port, /usr/sbin/nft flush set inet felhom_oob operator_ips, /usr/sbin/nft flush set inet felhom_oob ssh_port, /usr/sbin/nft ^add element inet felhom_oob operator_ips \{ [0-9.]+(/[0-9]+)? \}$, /usr/sbin/nft ^add element inet felhom_oob ssh_port \{ [0-9]+ \}$, /usr/local/sbin/felhom-pbs-apply create *, /usr/local/sbin/felhom-pbs-apply reconcile *, /usr/local/sbin/felhom-pbs-apply grant *, /usr/local/sbin/felhom-pbs-apply read *, /usr/local/sbin/felhom-backup-target-apply create *, /usr/local/sbin/felhom-backup-target-apply grant *, /usr/bin/systemctl start networking.service, /usr/local/bin/felhom-agent --config /etc/felhom-agent/agent.json --selftest\=escrow-create --upload --output\=json, /usr/sbin/pct ^exec [0-9]+ -- ip route show default$, /usr/sbin/pct ^exec [0-9]+ -- cat /etc/network/interfaces$, /usr/sbin/pct ^exec [0-9]+ -- pgrep -x dhclient$, /usr/sbin/pct ^exec [0-9]+ -- dhclient -pf /run/dhclient\.eth0\.pid -lf /var/lib/dhcp/dhclient\.eth0\.leases eth0$, /usr/sbin/pct destroy 99000[0-9] --purge, /usr/local/sbin/felhom-os-apply --plan /var/lib/felhom-agent/os/plan-*.json
(root) NOPASSWD: /usr/bin/mkdir -p /run/sshd, /usr/bin/systemctl reset-failed wg-quick@wg-felhom, /usr/bin/systemctl restart wg-quick@wg-felhom, /usr/bin/systemctl start felhom-agent, /usr/bin/systemctl restart felhom-agent, /usr/bin/systemctl reset-failed felhom-sshd, /usr/bin/systemctl restart felhom-sshd, /usr/sbin/pct list, /usr/sbin/pct ^start [0-9]+$, /usr/sbin/pct ^stop [0-9]+$, /usr/sbin/pct ^unlock [0-9]+$
--- hand-fed alpine ref
felhom-priv-apply: REFUSED [I1] controller-image 9202: the image ref is not gitea.dooplex.hu/admin/felhom-controller:<x.y.z>
rc=3
image file unchanged: gitea.dooplex.hu/admin/felhom-controller:0.301.0
Oct 07 13:36:33 demo-hp sudo[102483]: felhom-agent : PWD=/root ; USER=root ; COMMAND=/usr/local/sbin/felhom-priv-apply controller-image 9202
Oct 07 13:36:33 demo-hp felhom-priv-apply[102486]: felhom-priv-apply: REFUSED [I1] controller-image 9202: the image ref is not gitea.dooplex.hu/admin/felhom-controller:<x.y.z>
--- old tee path
sudo: a password is required
rc=1
