diff --git a/CLAUDE.md b/CLAUDE.md index a84d20a..c667538 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -115,7 +115,7 @@ truth is the **manifest**: happened — reconcile via the manifest, not the changelog. - Green gate before any hub commit: `go build ./... && go vet ./... && go test ./...` in `hub/`. -Steps: commit+push code → `./build.sh --push` on 180 (`~/build/felhom-hub`) → bump +Steps: commit+push code → `./build.sh --push` on 180 (`/mnt/5_hdd/felhom.eu/build/felhom-hub` — all felhom build dirs/repos moved off the SSD to `/mnt/5_hdd/felhom.eu/` on 2026-07-18) → bump `manifests/hub.yaml` tag + push → ArgoCD hard-refresh + sync (kubectl-patch method in the skill) → verify Synced/Healthy + rollout + image + startup log. diff --git a/CONTEXT.md b/CONTEXT.md index 6251fdf..fcea0f4 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -714,7 +714,7 @@ fetch-verified **ANONYMOUSLY** (Gate 3c finding: generic packages are world-readable → G3 git.token read-only rotation CANNOT break fetches; but the INSTALLER dies on an empty token — script-side requirement, not Gitea's). Drill VM restored to `virgin`; evidence - `~/drill/bake-0.103.0.log` on 180 + `documentation/pilot/RUNBOOK-GL1-publish-2026-07-07.md`. + `/mnt/5_hdd/felhom.eu/drill/bake-0.103.0.log` on 180 + `documentation/pilot/RUNBOOK-GL1-publish-2026-07-07.md`. **OPERATOR NEXT: bump the hub Day-0 manifest** to agent 0.74.0 / golden 0.103.0 (the four values are in the execution record) — until then fresh installs land 0.63.0/0.98.3. Also recorded: operator-key pin follow-up (fold into GL-4); GO-LIVE-PACKAGE.md still not in the repo (G1 status @@ -853,7 +853,7 @@ pre-floor controller 0.85.1 → **fresh installs need the one-time D.1b update** (agent restart → update button → 0.98.3); follow-ups recorded: rebuild golden ≥0.86.0 + re-vouch (operator), agent `mkdir -p` for the guesthook snippet dir, fresh-install local-API 401 (pre-existing), hub has no - host-delete path. Drill VM parked virgin-snapshotted on 180 (`~/drill/`). + host-delete path. Drill VM parked virgin-snapshotted on 180 (`/mnt/5_hdd/felhom.eu/drill/` — moved off the SSD 2026-07-18). - **2026-07-03 — A1 CLOSED (host-install v1.9.0 + agent v0.62.0)** — `Pool.Audit` added to `FelhomAgentGuest`; the agent's stale-lock reaper now intersects its scan with `GET /pools/felhom` membership (fail-safe skip on read failure). Spike: diff --git a/documentation/pilot/RUNBOOK-publish-0.90-0.143-2026-07-18.md b/documentation/pilot/RUNBOOK-publish-0.90-0.143-2026-07-18.md index 6595979..08c6f8f 100644 --- a/documentation/pilot/RUNBOOK-publish-0.90-0.143-2026-07-18.md +++ b/documentation/pilot/RUNBOOK-publish-0.90-0.143-2026-07-18.md @@ -73,7 +73,7 @@ transient unit baking `felhom-controller:0.143.0`: sha **matches**. - **Teardown (GL-1):** build guest 9100 `--purge`d; in-VM token/script/log `shred`ded; VM powered off; qemu exited; qcow2 reverted to `virgin` (snapshot intact, exactly-as-found); staged token on 180 - shredded. **Token-leak grep of the saved log (literal value) = 0.** Evidence: `180:~/drill/bake-0.143.0.log`. + shredded. **Token-leak grep of the saved log (literal value) = 0.** Evidence: `180:/mnt/5_hdd/felhom.eu/drill/bake-0.143.0.log`. ## Phase 3 — manifest vouch + floor ✅ DONE (Viktor 2026-07-18), CC-verified @@ -109,19 +109,19 @@ all exactly the published values. No ordering issue (both persisted). Built on 180 from `~/git/felhom.eu` @ `cfdcb50` (scripts v1.20.0), assistant `felhom-iso-assistant:trixie`. **Input PVE ISO:** `proxmox-ve_9.2-1.iso`, sha256 `4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c` -(the exact recorded July input, at `180:~/drill/`). Both builds: pairing mode, **build manifest +(the exact recorded July input, at `180:/mnt/5_hdd/felhom.eu/drill/`). Both builds: pairing mode, **build manifest `secret-bearing: no`**, loader `mkimage`, script v1.20.0. **Build 1 — safety pre-flight ISO** (`profiles/n100.profile` AS-IS, `--pairing`): -- `180:~/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-generic-mkimage.iso` +- `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-generic-mkimage.iso` - sha256 **`2e1107a15ea2abd892426661a853610dfb2ff49ec1d3e7561a876a393d4ea5c7`**, 1 704 417 280 bytes - embedded answer.toml: `filter.ID_SERIAL_SHORT = "REPLACE-WITH-TARGET-SSD-SERIAL"` (**match-nothing** → installer aborts fail-safe, touches no disk — S5c). Purpose: prove the mkimage loader boots the real board before anything destructive. -**Build 2 — real install ISO** (uncommitted working profile `180:~/felhom-iso/n100-demo.profile`, +**Build 2 — real install ISO** (uncommitted working profile `180:/mnt/5_hdd/felhom.eu/felhom-iso/n100-demo.profile`, `--pairing`; profile mirrors the prior v1.16.0 run + the two allowed v1.20.0 deltas): -- `180:~/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-demo-generic-mkimage.iso` +- `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-demo-generic-mkimage.iso` - sha256 **`69cd7ba5872bb02c4977959bfe97312690f3a164937e71609bb987ac93e435dc`**, 1 704 417 280 bytes - embedded answer.toml verified: `fqdn = "demo-felhom.local"`, `filter.ID_SERIAL_SHORT = "QDF922W009654S30EX"` (internal SSD; **≠** external HDD `65NOP3HDT` → backup drive protected), @@ -156,5 +156,5 @@ freemail.hu, confirm `dmarc=pass`) — the open half of R-4. console shows the Hungarian pairing-code banner → **bind** (prefer the self-bind flow to live-validate R-27 slice 1) → day-0. -Both ISOs + sha256 + manifest are on `180:~/felhom-iso/out/`. This run unblocks the R-1 supervised +Both ISOs + sha256 + manifest are on `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/`. This run unblocks the R-1 supervised rehearsal and closes the DNS half of R-4 once B is applied. diff --git a/documentation/runbooks/RUNBOOK-manual-build.md b/documentation/runbooks/RUNBOOK-manual-build.md index 5e49bfa..95aa7fb 100644 --- a/documentation/runbooks/RUNBOOK-manual-build.md +++ b/documentation/runbooks/RUNBOOK-manual-build.md @@ -30,16 +30,17 @@ acts immediately; save it LAST). Rules: `publish-train-rules.md`. ```bash SSH=/c/Windows/System32/OpenSSH/ssh.exe # Git Bash's own ssh fails silently against the Windows agent export MSYS_NO_PATHCONV=1 # before any felhom-pve command with absolute paths (pct etc.) +FELHOM_ROOT=/mnt/5_hdd/felhom.eu # build-server working root: ALL felhom repos/build/drill/iso moved HERE 2026-07-18 ``` | Host | Access | Role | |---|---|---| -| Build server | `$SSH kisfenyo@192.168.0.180` | builds (`~/git/felhom-agent`, `~/build/felhom-controller`, `~/build/felhom-hub`), kubectl | +| Build server | `$SSH kisfenyo@192.168.0.180` | builds (`$FELHOM_ROOT/git/felhom-agent`, `$FELHOM_ROOT/build/felhom-controller`, `$FELHOM_ROOT/build/felhom-hub`), kubectl | | Demo PVE host | `$SSH felhom-pve` (root@192.168.0.162) | agent install, `pct exec 9201` | | Hub UI | hub.felhom.eu → Configuration | manifest vouch, MinAgent, floor (operator password) | -Housekeeping note: `~/build/felhom-agent` on 180 is a stale pre-June-23 leftover — agent builds live -in `~/git/felhom-agent` now. Safe to remove the old dir. +Housekeeping note: `$FELHOM_ROOT/build/felhom-agent` on 180 is a stale pre-June-23 leftover — agent +builds live in `$FELHOM_ROOT/git/felhom-agent` now. Safe to remove the old dir. ## 2. Agent (felhom-agent binary → felhom-pve, then optionally publish) @@ -47,7 +48,7 @@ Always commit+push to `main` first (an unpushed change does not exist). ```bash # BUILD on 180 (the explicit git pull is load-bearing) -$SSH kisfenyo@192.168.0.180 "cd ~/git/felhom-agent && git pull && go build -ldflags '-X main.version=' -o /tmp/felhom-agent- ./cmd/felhom-agent" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/git/felhom-agent && git pull && go build -ldflags '-X main.version=' -o /tmp/felhom-agent- ./cmd/felhom-agent" # FETCH locally, PUSH to the PVE host (Windows scp needs cygpath for the local side) scp kisfenyo@192.168.0.180:/tmp/felhom-agent- "$(cygpath -w /tmp/felhom-agent-)" @@ -82,7 +83,7 @@ artifact manifest**. (This save does NOT move the floor — that's a separate ca ```bash # BUILD+PUSH the image (build.sh does NOT pull — the explicit pull is load-bearing) -$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-controller && git -C ~/git/felhom-controller pull && ./build.sh --push" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-controller && git -C $FELHOM_ROOT/git/felhom-controller pull && ./build.sh --push" # DEPLOY on the demo guest $SSH felhom-pve "pct exec 9201 -- bash -c 'docker pull gitea.dooplex.hu/admin/felhom-controller: && echo gitea.dooplex.hu/admin/felhom-controller: > /etc/felhom-controller-image && systemctl restart felhom-controller-bootstrap.service'" @@ -119,7 +120,7 @@ tag changes in git and the ArgoCD app is deliberately synced (auto-sync is OFF; `kubectl set image`, never `:latest`). ```bash -$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-hub && ./build.sh --push" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-hub && ./build.sh --push" # edit manifests/hub.yaml image tag → ; commit; push $SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd annotate application felhom argocd.argoproj.io/refresh=hard --overwrite; sleep 8; sudo kubectl -n argocd get application felhom -o jsonpath='{.status.sync.status} {.status.sync.revision}{\"\n\"}'" $SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd patch application felhom --type merge -p '{\"operation\":{\"initiatedBy\":{\"username\":\"op\"},\"sync\":{\"syncStrategy\":{\"apply\":{}}}}}'" diff --git a/hub/README.md b/hub/README.md index 67d8e77..60ba894 100644 --- a/hub/README.md +++ b/hub/README.md @@ -356,8 +356,8 @@ Runs on k3s (Kubernetes) in the `felhom-system` namespace: - **Geo-restriction:** Hungary only (nginx annotation) ```bash -# Build and push (on 192.168.0.180) -cd ~/build/felhom-hub +# Build and push (on 192.168.0.180; felhom build dirs moved to /mnt/5_hdd/felhom.eu/ off the SSD 2026-07-18) +cd /mnt/5_hdd/felhom.eu/build/felhom-hub ./build.sh v0.3.8 --push # Build script auto-syncs app assets from website/assets/ into the image diff --git a/scripts/iso/README.md b/scripts/iso/README.md index e4b64cd..1b117c6 100644 --- a/scripts/iso/README.md +++ b/scripts/iso/README.md @@ -38,8 +38,13 @@ scripts/iso/build-felhom-iso.sh \ --iso-sha256 4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c \ --profile scripts/iso/profiles/nested-vm.profile \ --bootstrap-env /secure/bootstrap.env \ - --out ~/felhom-iso/out + --out /mnt/5_hdd/felhom.eu/felhom-iso/out ``` +> On the DooPlex build server (180) the felhom working dirs were moved off the SSD to +> `/mnt/5_hdd/felhom.eu/` (2026-07-18): the input PVE ISO lives at +> `/mnt/5_hdd/felhom.eu/drill/proxmox-ve_9.2-1.iso` and ISO output goes to +> `/mnt/5_hdd/felhom.eu/felhom-iso/out`. The script's built-in `--out` default is still `$HOME/felhom-iso/out` +> (portable) — **always pass `--out` explicitly on 180** so nothing regrows the SSD. Output: `felhom-pve--v-.iso` + `.sha256` + `.manifest.txt`. diff --git a/skills/felhom-build-deploy/SKILL.md b/skills/felhom-build-deploy/SKILL.md index 4a473f6..d45eb95 100644 --- a/skills/felhom-build-deploy/SKILL.md +++ b/skills/felhom-build-deploy/SKILL.md @@ -13,11 +13,13 @@ Update the repo's `CHANGELOG.md` (+ `REUSE.md` if a shared helper changed) in th ```bash SSH=/c/Windows/System32/OpenSSH/ssh.exe # Git Bash's /usr/bin/ssh can't reach the Windows agent — fails silently export MSYS_NO_PATHCONV=1 # before any ssh felhom-pve command with absolute paths (pct etc.) +FELHOM_ROOT=/mnt/5_hdd/felhom.eu # build-server working root — ALL felhom repos/build/drill/iso live HERE + # (moved off the SSD 2026-07-18; expands locally into the "…" SSH strings below) ``` | Host | Access | Role | |---|---|---| -| Build server (k3s) | `$SSH kisfenyo@192.168.0.180` | build+push images/binaries (`~/build/felhom-{controller,hub,agent}`), `sudo kubectl` | +| Build server (k3s) | `$SSH kisfenyo@192.168.0.180` | build+push images/binaries (`$FELHOM_ROOT/build/felhom-{controller,hub,agent}`, repos under `$FELHOM_ROOT/git/`), `sudo kubectl` | | Demo Proxmox host | `$SSH felhom-pve` (root@192.168.0.162) | agent deploy, `pct` into guests | | Demo guest 9201 | via `pct exec 9201 -- bash -c '...'` on felhom-pve | the live controller | | felhotest (legacy) | `$SSH -p 33022 kisfenyo@router.abonet.hu` | OLD /opt/docker compose mechanism — not the 9201 flow | @@ -32,7 +34,7 @@ the tag written in `/etc/felhom-controller-image` (anonymous Gitea pull). Data v ```bash # 1. commit+push the repo # 2. build+push image (build.sh does NOT git-pull — the explicit pull is load-bearing) -$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-controller && git -C ~/git/felhom-controller pull && ./build.sh --push" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-controller && git -C $FELHOM_ROOT/git/felhom-controller pull && ./build.sh --push" # 3. deploy in the guest $SSH felhom-pve "pct exec 9201 -- bash -c 'docker pull gitea.dooplex.hu/admin/felhom-controller: && echo gitea.dooplex.hu/admin/felhom-controller: > /etc/felhom-controller-image && systemctl restart felhom-controller-bootstrap.service'" # 4. verify @@ -48,7 +50,7 @@ Runs as the NON-ROOT `felhom-agent` user: `/usr/local/bin/felhom-agent --config ```bash # build on 180 (pull first!) -$SSH kisfenyo@192.168.0.180 "cd ~/git/felhom-agent && git pull && go build -ldflags '-X main.version=' -o /tmp/felhom-agent- ./cmd/felhom-agent" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/git/felhom-agent && git pull && go build -ldflags '-X main.version=' -o /tmp/felhom-agent- ./cmd/felhom-agent" # fetch to local, then push to the PVE host (Windows scp needs cygpath -w for the LOCAL path) scp kisfenyo@192.168.0.180:/tmp/felhom-agent- "$(cygpath -w /tmp/felhom-agent-)" scp "$(cygpath -w /tmp/felhom-agent-)" felhom-pve:/tmp/ @@ -73,7 +75,7 @@ operator-password-gated (CC cannot); flag it as an operator follow-up. ```bash # 1. commit+push code 2. build+push image -$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-hub && ./build.sh --push" +$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-hub && ./build.sh --push" # 3. bump manifests/hub.yaml image tag → , commit, push # 4. hard-refresh + sync (argocd CLI on 180 is not logged in — drive the Application CR) $SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd annotate application felhom argocd.argoproj.io/refresh=hard --overwrite; sleep 8; sudo kubectl -n argocd get application felhom -o jsonpath='{.status.sync.status} {.status.sync.revision}{\"\n\"}'"