docs: relocate felhom build root to /mnt/5_hdd/felhom.eu (moved off DooPlex SSD 2026-07-18)
This commit is contained in:
@@ -115,7 +115,7 @@ truth is the **manifest**:
|
||||
happened — reconcile via the manifest, not the changelog.
|
||||
- Green gate before any hub commit: `go build ./... && go vet ./... && go test ./...` in `hub/`.
|
||||
|
||||
Steps: commit+push code → `./build.sh <VER> --push` on 180 (`~/build/felhom-hub`) → bump
|
||||
Steps: commit+push code → `./build.sh <VER> --push` on 180 (`/mnt/5_hdd/felhom.eu/build/felhom-hub` — all felhom build dirs/repos moved off the SSD to `/mnt/5_hdd/felhom.eu/` on 2026-07-18) → bump
|
||||
`manifests/hub.yaml` tag + push → ArgoCD hard-refresh + sync (kubectl-patch method in the skill) →
|
||||
verify Synced/Healthy + rollout + image + startup log.
|
||||
|
||||
|
||||
+2
-2
@@ -714,7 +714,7 @@
|
||||
fetch-verified **ANONYMOUSLY** (Gate 3c finding: generic packages are world-readable → G3
|
||||
git.token read-only rotation CANNOT break fetches; but the INSTALLER dies on an empty token —
|
||||
script-side requirement, not Gitea's). Drill VM restored to `virgin`; evidence
|
||||
`~/drill/bake-0.103.0.log` on 180 + `documentation/pilot/RUNBOOK-GL1-publish-2026-07-07.md`.
|
||||
`/mnt/5_hdd/felhom.eu/drill/bake-0.103.0.log` on 180 + `documentation/pilot/RUNBOOK-GL1-publish-2026-07-07.md`.
|
||||
**OPERATOR NEXT: bump the hub Day-0 manifest** to agent 0.74.0 / golden 0.103.0 (the four values
|
||||
are in the execution record) — until then fresh installs land 0.63.0/0.98.3. Also recorded:
|
||||
operator-key pin follow-up (fold into GL-4); GO-LIVE-PACKAGE.md still not in the repo (G1 status
|
||||
@@ -853,7 +853,7 @@
|
||||
pre-floor controller 0.85.1 → **fresh installs need the one-time D.1b update** (agent restart →
|
||||
update button → 0.98.3); follow-ups recorded: rebuild golden ≥0.86.0 + re-vouch (operator), agent
|
||||
`mkdir -p` for the guesthook snippet dir, fresh-install local-API 401 (pre-existing), hub has no
|
||||
host-delete path. Drill VM parked virgin-snapshotted on 180 (`~/drill/`).
|
||||
host-delete path. Drill VM parked virgin-snapshotted on 180 (`/mnt/5_hdd/felhom.eu/drill/` — moved off the SSD 2026-07-18).
|
||||
- **2026-07-03 — A1 CLOSED (host-install v1.9.0 + agent v0.62.0)** — `Pool.Audit` added to
|
||||
`FelhomAgentGuest`; the agent's stale-lock reaper now intersects its scan with
|
||||
`GET /pools/felhom` membership (fail-safe skip on read failure). Spike:
|
||||
|
||||
@@ -73,7 +73,7 @@ transient unit baking `felhom-controller:0.143.0`:
|
||||
sha **matches**.
|
||||
- **Teardown (GL-1):** build guest 9100 `--purge`d; in-VM token/script/log `shred`ded; VM powered off;
|
||||
qemu exited; qcow2 reverted to `virgin` (snapshot intact, exactly-as-found); staged token on 180
|
||||
shredded. **Token-leak grep of the saved log (literal value) = 0.** Evidence: `180:~/drill/bake-0.143.0.log`.
|
||||
shredded. **Token-leak grep of the saved log (literal value) = 0.** Evidence: `180:/mnt/5_hdd/felhom.eu/drill/bake-0.143.0.log`.
|
||||
|
||||
## Phase 3 — manifest vouch + floor ✅ DONE (Viktor 2026-07-18), CC-verified
|
||||
|
||||
@@ -109,19 +109,19 @@ all exactly the published values. No ordering issue (both persisted).
|
||||
|
||||
Built on 180 from `~/git/felhom.eu` @ `cfdcb50` (scripts v1.20.0), assistant `felhom-iso-assistant:trixie`.
|
||||
**Input PVE ISO:** `proxmox-ve_9.2-1.iso`, sha256 `4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c`
|
||||
(the exact recorded July input, at `180:~/drill/`). Both builds: pairing mode, **build manifest
|
||||
(the exact recorded July input, at `180:/mnt/5_hdd/felhom.eu/drill/`). Both builds: pairing mode, **build manifest
|
||||
`secret-bearing: no`**, loader `mkimage`, script v1.20.0.
|
||||
|
||||
**Build 1 — safety pre-flight ISO** (`profiles/n100.profile` AS-IS, `--pairing`):
|
||||
- `180:~/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-generic-mkimage.iso`
|
||||
- `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-generic-mkimage.iso`
|
||||
- sha256 **`2e1107a15ea2abd892426661a853610dfb2ff49ec1d3e7561a876a393d4ea5c7`**, 1 704 417 280 bytes
|
||||
- embedded answer.toml: `filter.ID_SERIAL_SHORT = "REPLACE-WITH-TARGET-SSD-SERIAL"` (**match-nothing** →
|
||||
installer aborts fail-safe, touches no disk — S5c). Purpose: prove the mkimage loader boots the real
|
||||
board before anything destructive.
|
||||
|
||||
**Build 2 — real install ISO** (uncommitted working profile `180:~/felhom-iso/n100-demo.profile`,
|
||||
**Build 2 — real install ISO** (uncommitted working profile `180:/mnt/5_hdd/felhom.eu/felhom-iso/n100-demo.profile`,
|
||||
`--pairing`; profile mirrors the prior v1.16.0 run + the two allowed v1.20.0 deltas):
|
||||
- `180:~/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-demo-generic-mkimage.iso`
|
||||
- `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/felhom-pve-9.2-1-v1.20.0-n100-demo-generic-mkimage.iso`
|
||||
- sha256 **`69cd7ba5872bb02c4977959bfe97312690f3a164937e71609bb987ac93e435dc`**, 1 704 417 280 bytes
|
||||
- embedded answer.toml verified: `fqdn = "demo-felhom.local"`, `filter.ID_SERIAL_SHORT =
|
||||
"QDF922W009654S30EX"` (internal SSD; **≠** external HDD `65NOP3HDT` → backup drive protected),
|
||||
@@ -156,5 +156,5 @@ freemail.hu, confirm `dmarc=pass`) — the open half of R-4.
|
||||
console shows the Hungarian pairing-code banner → **bind** (prefer the self-bind flow to live-validate
|
||||
R-27 slice 1) → day-0.
|
||||
|
||||
Both ISOs + sha256 + manifest are on `180:~/felhom-iso/out/`. This run unblocks the R-1 supervised
|
||||
Both ISOs + sha256 + manifest are on `180:/mnt/5_hdd/felhom.eu/felhom-iso/out/`. This run unblocks the R-1 supervised
|
||||
rehearsal and closes the DNS half of R-4 once B is applied.
|
||||
|
||||
@@ -30,16 +30,17 @@ acts immediately; save it LAST). Rules: `publish-train-rules.md`.
|
||||
```bash
|
||||
SSH=/c/Windows/System32/OpenSSH/ssh.exe # Git Bash's own ssh fails silently against the Windows agent
|
||||
export MSYS_NO_PATHCONV=1 # before any felhom-pve command with absolute paths (pct etc.)
|
||||
FELHOM_ROOT=/mnt/5_hdd/felhom.eu # build-server working root: ALL felhom repos/build/drill/iso moved HERE 2026-07-18
|
||||
```
|
||||
|
||||
| Host | Access | Role |
|
||||
|---|---|---|
|
||||
| Build server | `$SSH kisfenyo@192.168.0.180` | builds (`~/git/felhom-agent`, `~/build/felhom-controller`, `~/build/felhom-hub`), kubectl |
|
||||
| Build server | `$SSH kisfenyo@192.168.0.180` | builds (`$FELHOM_ROOT/git/felhom-agent`, `$FELHOM_ROOT/build/felhom-controller`, `$FELHOM_ROOT/build/felhom-hub`), kubectl |
|
||||
| Demo PVE host | `$SSH felhom-pve` (root@192.168.0.162) | agent install, `pct exec 9201` |
|
||||
| Hub UI | hub.felhom.eu → Configuration | manifest vouch, MinAgent, floor (operator password) |
|
||||
|
||||
Housekeeping note: `~/build/felhom-agent` on 180 is a stale pre-June-23 leftover — agent builds live
|
||||
in `~/git/felhom-agent` now. Safe to remove the old dir.
|
||||
Housekeeping note: `$FELHOM_ROOT/build/felhom-agent` on 180 is a stale pre-June-23 leftover — agent
|
||||
builds live in `$FELHOM_ROOT/git/felhom-agent` now. Safe to remove the old dir.
|
||||
|
||||
## 2. Agent (felhom-agent binary → felhom-pve, then optionally publish)
|
||||
|
||||
@@ -47,7 +48,7 @@ Always commit+push to `main` first (an unpushed change does not exist).
|
||||
|
||||
```bash
|
||||
# BUILD on 180 (the explicit git pull is load-bearing)
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/git/felhom-agent && git pull && go build -ldflags '-X main.version=<VER>' -o /tmp/felhom-agent-<VER> ./cmd/felhom-agent"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/git/felhom-agent && git pull && go build -ldflags '-X main.version=<VER>' -o /tmp/felhom-agent-<VER> ./cmd/felhom-agent"
|
||||
|
||||
# FETCH locally, PUSH to the PVE host (Windows scp needs cygpath for the local side)
|
||||
scp kisfenyo@192.168.0.180:/tmp/felhom-agent-<VER> "$(cygpath -w /tmp/felhom-agent-<VER>)"
|
||||
@@ -82,7 +83,7 @@ artifact manifest**. (This save does NOT move the floor — that's a separate ca
|
||||
|
||||
```bash
|
||||
# BUILD+PUSH the image (build.sh does NOT pull — the explicit pull is load-bearing)
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-controller && git -C ~/git/felhom-controller pull && ./build.sh <VER> --push"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-controller && git -C $FELHOM_ROOT/git/felhom-controller pull && ./build.sh <VER> --push"
|
||||
|
||||
# DEPLOY on the demo guest
|
||||
$SSH felhom-pve "pct exec 9201 -- bash -c 'docker pull gitea.dooplex.hu/admin/felhom-controller:<VER> && echo gitea.dooplex.hu/admin/felhom-controller:<VER> > /etc/felhom-controller-image && systemctl restart felhom-controller-bootstrap.service'"
|
||||
@@ -119,7 +120,7 @@ tag changes in git and the ArgoCD app is deliberately synced (auto-sync is OFF;
|
||||
`kubectl set image`, never `:latest`).
|
||||
|
||||
```bash
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-hub && ./build.sh <VER> --push"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-hub && ./build.sh <VER> --push"
|
||||
# edit manifests/hub.yaml image tag → <VER>; commit; push
|
||||
$SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd annotate application felhom argocd.argoproj.io/refresh=hard --overwrite; sleep 8; sudo kubectl -n argocd get application felhom -o jsonpath='{.status.sync.status} {.status.sync.revision}{\"\n\"}'"
|
||||
$SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd patch application felhom --type merge -p '{\"operation\":{\"initiatedBy\":{\"username\":\"op\"},\"sync\":{\"syncStrategy\":{\"apply\":{}}}}}'"
|
||||
|
||||
+2
-2
@@ -356,8 +356,8 @@ Runs on k3s (Kubernetes) in the `felhom-system` namespace:
|
||||
- **Geo-restriction:** Hungary only (nginx annotation)
|
||||
|
||||
```bash
|
||||
# Build and push (on 192.168.0.180)
|
||||
cd ~/build/felhom-hub
|
||||
# Build and push (on 192.168.0.180; felhom build dirs moved to /mnt/5_hdd/felhom.eu/ off the SSD 2026-07-18)
|
||||
cd /mnt/5_hdd/felhom.eu/build/felhom-hub
|
||||
./build.sh v0.3.8 --push
|
||||
# Build script auto-syncs app assets from website/assets/ into the image
|
||||
|
||||
|
||||
@@ -38,8 +38,13 @@ scripts/iso/build-felhom-iso.sh \
|
||||
--iso-sha256 4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c \
|
||||
--profile scripts/iso/profiles/nested-vm.profile \
|
||||
--bootstrap-env /secure/bootstrap.env \
|
||||
--out ~/felhom-iso/out
|
||||
--out /mnt/5_hdd/felhom.eu/felhom-iso/out
|
||||
```
|
||||
> On the DooPlex build server (180) the felhom working dirs were moved off the SSD to
|
||||
> `/mnt/5_hdd/felhom.eu/` (2026-07-18): the input PVE ISO lives at
|
||||
> `/mnt/5_hdd/felhom.eu/drill/proxmox-ve_9.2-1.iso` and ISO output goes to
|
||||
> `/mnt/5_hdd/felhom.eu/felhom-iso/out`. The script's built-in `--out` default is still `$HOME/felhom-iso/out`
|
||||
> (portable) — **always pass `--out` explicitly on 180** so nothing regrows the SSD.
|
||||
|
||||
Output: `felhom-pve-<pvever>-v<isover>-<profile>.iso` + `.sha256` + `.manifest.txt`.
|
||||
|
||||
|
||||
@@ -13,11 +13,13 @@ Update the repo's `CHANGELOG.md` (+ `REUSE.md` if a shared helper changed) in th
|
||||
```bash
|
||||
SSH=/c/Windows/System32/OpenSSH/ssh.exe # Git Bash's /usr/bin/ssh can't reach the Windows agent — fails silently
|
||||
export MSYS_NO_PATHCONV=1 # before any ssh felhom-pve command with absolute paths (pct etc.)
|
||||
FELHOM_ROOT=/mnt/5_hdd/felhom.eu # build-server working root — ALL felhom repos/build/drill/iso live HERE
|
||||
# (moved off the SSD 2026-07-18; expands locally into the "…" SSH strings below)
|
||||
```
|
||||
|
||||
| Host | Access | Role |
|
||||
|---|---|---|
|
||||
| Build server (k3s) | `$SSH kisfenyo@192.168.0.180` | build+push images/binaries (`~/build/felhom-{controller,hub,agent}`), `sudo kubectl` |
|
||||
| Build server (k3s) | `$SSH kisfenyo@192.168.0.180` | build+push images/binaries (`$FELHOM_ROOT/build/felhom-{controller,hub,agent}`, repos under `$FELHOM_ROOT/git/`), `sudo kubectl` |
|
||||
| Demo Proxmox host | `$SSH felhom-pve` (root@192.168.0.162) | agent deploy, `pct` into guests |
|
||||
| Demo guest 9201 | via `pct exec 9201 -- bash -c '...'` on felhom-pve | the live controller |
|
||||
| felhotest (legacy) | `$SSH -p 33022 kisfenyo@router.abonet.hu` | OLD /opt/docker compose mechanism — not the 9201 flow |
|
||||
@@ -32,7 +34,7 @@ the tag written in `/etc/felhom-controller-image` (anonymous Gitea pull). Data v
|
||||
```bash
|
||||
# 1. commit+push the repo
|
||||
# 2. build+push image (build.sh does NOT git-pull — the explicit pull is load-bearing)
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-controller && git -C ~/git/felhom-controller pull && ./build.sh <VER> --push"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-controller && git -C $FELHOM_ROOT/git/felhom-controller pull && ./build.sh <VER> --push"
|
||||
# 3. deploy in the guest
|
||||
$SSH felhom-pve "pct exec 9201 -- bash -c 'docker pull gitea.dooplex.hu/admin/felhom-controller:<VER> && echo gitea.dooplex.hu/admin/felhom-controller:<VER> > /etc/felhom-controller-image && systemctl restart felhom-controller-bootstrap.service'"
|
||||
# 4. verify
|
||||
@@ -48,7 +50,7 @@ Runs as the NON-ROOT `felhom-agent` user: `/usr/local/bin/felhom-agent --config
|
||||
|
||||
```bash
|
||||
# build on 180 (pull first!)
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/git/felhom-agent && git pull && go build -ldflags '-X main.version=<VER>' -o /tmp/felhom-agent-<VER> ./cmd/felhom-agent"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/git/felhom-agent && git pull && go build -ldflags '-X main.version=<VER>' -o /tmp/felhom-agent-<VER> ./cmd/felhom-agent"
|
||||
# fetch to local, then push to the PVE host (Windows scp needs cygpath -w for the LOCAL path)
|
||||
scp kisfenyo@192.168.0.180:/tmp/felhom-agent-<VER> "$(cygpath -w /tmp/felhom-agent-<VER>)"
|
||||
scp "$(cygpath -w /tmp/felhom-agent-<VER>)" felhom-pve:/tmp/
|
||||
@@ -73,7 +75,7 @@ operator-password-gated (CC cannot); flag it as an operator follow-up.
|
||||
|
||||
```bash
|
||||
# 1. commit+push code 2. build+push image
|
||||
$SSH kisfenyo@192.168.0.180 "cd ~/build/felhom-hub && ./build.sh <VER> --push"
|
||||
$SSH kisfenyo@192.168.0.180 "cd $FELHOM_ROOT/build/felhom-hub && ./build.sh <VER> --push"
|
||||
# 3. bump manifests/hub.yaml image tag → <VER>, commit, push
|
||||
# 4. hard-refresh + sync (argocd CLI on 180 is not logged in — drive the Application CR)
|
||||
$SSH kisfenyo@192.168.0.180 "sudo kubectl -n argocd annotate application felhom argocd.argoproj.io/refresh=hard --overwrite; sleep 8; sudo kubectl -n argocd get application felhom -o jsonpath='{.status.sync.status} {.status.sync.revision}{\"\n\"}'"
|
||||
|
||||
Reference in New Issue
Block a user