Decisions 157-158 recorded; R-892 corrected (VM 341), R-894 filed (unreadable off-site storage reads due after an agent restart); Part C/E/F evidence; nodes.md: the Tester 1 box; 11 §5.8: the memory-kill check
gates / gates (push) Successful in 2m47s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 19:18:14 +02:00
parent eed1dbd80c
commit 01c4a5d2a9
30 changed files with 845 additions and 2 deletions
+11
View File
@@ -34,6 +34,17 @@ rather than trusting these** (`ip -br addr show vmbr0`; the N100 read `.162` on
tailnet addresses are the stable ones — use those. Direct LAN literals are **not** reachable from
DooPlex while the boxes are away (`felhom-pve-lan` → `No route to host`, 2026-07-30).
## The Tester 1 box — a VM on the HP box (`09` §3 decision 158)
| | `tester-1-d70be4` |
|---|---|
| What it is | **QEMU VM 341 `night1004-tester1` on demo-hp** (installed from the ISO on 2026-10-04, `audits/night-2026-10-04/tester1/`); disposable (operator) |
| PVE node name | `felhom` (its certificate: `CN=felhom.enkicsifelhom.hu`) |
| LAN address | **DHCP** — read 2026-10-06 as `192.168.0.154` (MAC `bc:24:11:ac:e3:f9`; find it with `ip neigh` after a ping) |
| Customer / guest | `tester-1`; guest LXC 9201 at `192.168.0.101`, dashboard `felhom.enkicsifelhom.hu` |
| SSH | through the HP box: `ssh -J demo-hp root@<VM address>` — **DooPlex's key is NOT authorized there yet** (2026-10-06: `Permission denied (publickey,password)`); `box_walk.py` `TARGET=tester-1` holds the route |
| Identity checked | 2026-10-06: the agent's own report `host.node=felhom` = the VM's certificate; the guest answers its domain (200) and not demo-hp's (404) — `audits/readback-2026-10-07/E1-identity-match.txt` |
**Which box is safe to break, and what may be done to each:
[`../runbooks/target-selection.md`](../runbooks/target-selection.md).** This page is *what the hardware
is*; that page is *what you may do to it*.