drill: a stranger's first hour on 0.242.0 — 1 intervention, not ready for a volunteer
gates / gates (push) Successful in 21s

Golden 0.242.0 baked, round-trip verified and vouched (cadence rule, R-468).
Fresh box from the public ISO on demo-hp: landed on the vouched set, two apps
deployed and used, backup, remove, byte-identical restore, power cut and code
typo all PASS. Stopped for a volunteer by R-493 (no instructions) and R-494
(the setup mail's dashboard link has no DNS; intervention I1). R-493..R-500
filed. Capability map: first-hour row added (PARTIAL), journey row scoped.
Stopgap Hungarian volunteer guide written. Hub teardown layer pending.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-14 16:17:47 +02:00
parent 41590f8ee6
commit 38848ffbeb
62 changed files with 7988 additions and 1 deletions
+109
View File
@@ -0,0 +1,109 @@
# REPORT — DRILL: a stranger's first hour on 0.242.0 (2026-09-14)
**Runbook-style validation. No product code written.** A parallel session owns root `REPORT.md`, so
this is a topic sibling (`CLAUDE.md`). Findings doc: `documentation/audits/DRILL-fresh-install-0242-2026-09-14.md`;
every observable: `documentation/audits/evidence-drill-fresh-install-0242-2026-09-14/journal.md`.
## 0. Claims in the brief that turned out wrong, or incomplete — named first
1. **"ep0 is not touched."** Enrolment itself registers a WireGuard peer on ep0 for every box
(`wg registered … ip=10.77.0.5/32 … sync=ok`), DR tier on or off. I avoided the part I could (DR
tier off, which would have created an ep0 namespace and token); the peer is the product's own act
and is removed by the host delete (§5).
2. **"This run re-proves or narrows the journey row (~L90)."** That row is the **rebuild-and-recover**
journey (walk 5). This drill walked the **first hour**, with off-site off. It can neither re-prove
nor narrow that row. I added a scope note to it and a **new first-hour row** (PARTIAL).
3. **"Claim the box with the code."** There are three secrets, not one: the console **Párosító kód**,
the operator-held **Tulajdonosi jelmondat** (nothing delivers it — R-497) and the mailed
**Beállító kód**. Two of the three arrive by mail, which this harness cannot read.
4. **The three claims marked "read, not measured"** — measured now: **website** — true, no mention of
the installer or `iso.felhom.eu`, and the ISO host has no index; **instructions** — true, none exist
(R-493); **golden landing** — the box landed on 0.242.0, the new golden, with no self-update.
5. **"Newest baked golden 0.236.0; waiver to 2026-09-27; highest R-492; baselines"** — all correct.
## 1. Baselines (re-verified 12:58 UTC)
controller `406755fa8fba` v0.242.0 · agent `4586f0f7f6d1` v0.130.0 · felhom.eu `41590f8ee618`
hub v0.112.0. Hub before: agent 0.130.0, golden 0.236.0, `min_agent` 0.129.0, floor 0.242.0.
Architecture read for the area: `00-capability-map.md` (journey row), `09-update-architecture.md` §3.
## 2. The golden
**0.242.0 baked, round-trip verified, vouched** — sha `3ab480dd…e6d8`, 653 288 425 B, all markers
pass, token-leak 0 with a working control, three readers agree. Only `golden_version` moved.
`documentation/tests/golden-0.242.0-2026-09-14/README.md`. The golden-currency gate is now plain OK.
One slip: my first template pick was arm64; caught before the bake.
## 3. The verdict
**Interventions: 1.** **Ready for a volunteer: no** — no instructions exist (R-493), and the setup
mail's dashboard link does not open for a new customer (R-494). Every mechanism after that passed:
install, landing on the vouched set, deploy, use, backup, remove, **byte-identical restore**, power cut
(same versions, no alarm), code typo and lockout.
| intervention | row | what |
|---|---|---|
| **I1** | R-494 (filed before acting) | dashboard reached by LAN address with the name forced — the mailed name has no DNS |
Harness substitutions (a volunteer would not need them; each hides a part of the path): **H1** no
mailbox → operator bind instead of the self-bind page, and two box-printed setup codes via the vaulted
break-glass; **H2** US keyboard layout; **H3** auto-reboot unticked, ISO detached; **H4** Terminal UI
entry. Full list with harness slips: findings doc §3.
## 4. Findings — every one a row
| row | rank | |
|---|---|---|
| R-493 | P1 | no customer install instructions; ISO host has no index |
| R-494 | P1 | new customer's dashboard has no address (I1) |
| R-495 | P2 | installer's unanswered questions; refuses its own default hostname |
| R-496 | P2 | console sends a stranger to the Proxmox admin page; „a jelszavadat" |
| R-497 | P2 | the Tulajdonosi jelmondat is delivered by nothing |
| R-499 | P2 | „already in the PBS backup, nothing to do" on a box with no PBS |
| R-498 | P3 | 52 of 53 app pages say literal `wiki.DOMAIN` |
| R-500 | P3 | dashboard backup time in UTC, backup pages in local time |
**R-469 was not touched.** R-214 reproduced (recorded, row unchanged).
**Register: 200 → 208 table rows. Opened 8, closed 0.**
## 5. Teardown — three layers
| layer | before | after |
|---|---|---|
| **1. machine** | `qm list`: VM 330 running, 8.6 G in `/mnt/hdd_1/images/330` | `qm destroy 330 --purge` → `qm list` empty; `images/330` gone; `images/9202` untouched |
| **2. host** | `nvme-scratch` used 19 059 372 KiB · `local` used 24 768 200 KiB · ISO present · `/root/drill0242` 40 files | `nvme-scratch` **10 130 532 KiB** (≈8.5 GiB returned) · `local` **23 013 832 KiB** (the 1.7 GiB ISO) · ISO 0 · scratch dir shredded and removed. `nvme-scratch` storage itself stays — it hosts 9202. `vmbr9` pre-existed |
| **3. hub** | customer `drill0242`, host `drill0242-3f4b42` ONLINE, `deletable:false`, `wg_peer_bound:true`, `recovery_present:true` | **PENDING — see §5b** |
### 5b. The hub record
*(Filled in when the host has aged to stale and the delete cascade has run.)*
**Append-only and staying, by design:** the hub's event stream (`controller_started`, `app_removed`,
`claim_lockout`, the bind and enrol lines) and the operator e-mail for the lockout.
**Untouched, and checked:** demo-hp guests 9201 and 9202 (running before and after); `local-lvm`
(44.17 % before and after); demo-felhom; DooPlex services (the bake VM, the accepted exception, back
on `virgin`); Peti's box; ep0 beyond the product's own peer. `drill-r50` does not exist (R-461).
## 6. Secrets
Hub password, BookStack and dashboard passwords, the passphrase, both setup codes, the break-glass
credential and the installer root password lived only in `0600` files in the session scratchpad.
**Every committed file was swept for each, with a planted control that was found: 0 hits.** The
pairing code is redacted in two screenshots and the text. The break-glass reveal emitted its audit
event, by design.
## 7. `unproven.py --summary`
Unchanged: 55 claims, NOT WALKED 35 of 55. It reads its own claim list, not the new map row.
## 8. Observations
- The deploy page's poll has no `degraded` branch; 16 s of stale step text on BookStack.
- The drive-attach list offers the guest's own system volume as an existing drive.
- The removal dialog names „éjszakai restic pillanatképek" on a box with no restic.
- „0 °C" beside „Nincs adat" for a virtual disk; an English „Debug" menu item.
- The claim lockout is global as well as per source; its mail reaches the operator only.
- Two of my first readings were of script-rendered elements from server HTML (host-metrics banner,
restore-finish message); both corrected in the journal. **No browser here — strict UI coverage is
the operator's click-through.**
+34
View File
@@ -1,5 +1,39 @@
# STATUS — what works, what's broken, what's next
**Updated 2026-09-14 (afternoon) — the first-hour drill on a fresh box.**
> **Ready for a volunteer: not yet.** Two things would stop a stranger before their first app: **there
> are no instructions anywhere telling them where the installer is or what to type**, and **the link
> in the "your server started" e-mail does not open for a new customer**, because nobody creates its
> web address automatically. Everything after that point worked.
**What I exercised.** A brand-new machine on the HP, installed from the public installer, connected
to a new test customer, claimed, two apps installed and used (a family wiki with a Hungarian page and
an attachment, and an encrypted note), a manual backup, one app removed with its data, the other
restored after I deleted its page, a power cut, and a mistyped code. The new golden image was built
first, as the weekly rule says, and the fresh box landed on today's release by itself.
**What broke.** Nothing lost data: the restore brought the deleted page back byte for byte, and the
power cut brought every app back on the same version with no false alarm. What a stranger would trip
on: no instructions (I wrote a Hungarian draft for you to approve); the dashboard address; the
installer refusing its own default machine name; the box's screen first telling people, in English, to
open the admin page they must never use; the five-word passphrase that no e-mail ever delivers; one
backup page wrongly saying "already covered, nothing to do"; app pages saying "open wiki.DOMAIN"
literally; and the dashboard showing the backup two hours off from the backup page. I reached the
dashboard once in a way a volunteer could not — that is the single intervention. I fixed nothing; this
run only records.
**Rows.** Opened 8, closed 0. Register table rows: 200 before, 208 after.
**Needs you.** (1) **Decide how a new customer reaches their dashboard**: the hub creates the web
address automatically, or the box offers a home-network address that works with no setup. **If you do
nothing:** every volunteer needs you to create their address by hand before they can log in.
(2) **Read and approve the Hungarian volunteer instructions**, and choose how they are sent. **If you
do nothing:** there is nothing to send a volunteer. (3) **Hand the five-word passphrase to each
volunteer yourself** until an e-mail does it. **If you do nothing:** they cannot connect their box.
---
**Updated 2026-09-14 (morning note, the second night) — the scratch guest is built, one controller release, the rotation restarted.**
**Decisions I took.** (1) The scratch guest on the HP was built as you ruled: a second guest under
File diff suppressed because one or more lines are too long
@@ -0,0 +1,104 @@
# DRILL — a stranger's first hour on 0.242.0 (2026-09-14)
**Interventions a volunteer could not have made: 1** (I1 — reaching the dashboard at all).
**Ready for a volunteer: NO — because no instruction tells a stranger where the installer is or what
to type, and the link in the setup-code e-mail does not open for a new customer; either stops them
before their first app.**
Evidence: `evidence-drill-fresh-install-0242-2026-09-14/` — `journal.md` (every observable, in
order), `screens/` (installer and console, codes redacted), `box-logs-phase1/`, `A1-power-cut.txt`,
`step10-remove-observe.txt`. Golden: `../tests/golden-0.242.0-2026-09-14/`.
---
## 1. What held, in one table
| # | step | result | time |
|---|---|---|---|
| 0.1 | golden 0.242.0 baked, round-trip verified, vouched | **PASS** | bake ≈6 min |
| 0.2 | customer-facing instructions exist | **FAIL — none exist** (R-493) | — |
| 1 | download the installer | PASS — but only with the exact file name; the site has no index (R-493) | 32 s, sha matches |
| 2 | install | PASS with **four unanswered questions**, one of which refuses its own default (R-495) | ≈12 min at the keyboard, 3 m 24 s copying |
| 3 | first screen, pairing, claim | box registered in 86 s; console sends a stranger to the Proxmox admin page and misnames the passphrase (R-496); passphrase is delivered by nothing (R-497); **the dashboard has no address** (R-494, **I1**); claim itself < 1 s | power-on → claimed 27 m 37 s |
| 4 | "ready", version | **PASS** — landed on controller 0.242.0 + agent 0.130.0, the vouched set; no self-update needed | power-on → controller 4 m 14 s |
| 5 | deploy BookStack + PrivateBin | **PASS** — 68 s and 21 s; pages honest about where data goes; first steps say literal `wiki.DOMAIN` (R-498) | |
| 6 | use both through their front doors | **PASS** — BookStack login, password change, book, Hungarian page, 256 KiB attachment; PrivateBin encrypted paste, decrypted round trip | |
| 7 | read the backups pages | mostly honest; **one page says „already in the PBS backup, nothing to do" on a box with no PBS** (R-499); „Következő mentés — 0 órája" reads backwards | |
| 8 | backup now | **PASS** — dates move to the true time on both pages | 21 s |
| 9 | version labels / Update | „Naprakész" true (installed == catalog); **no newer version offered — skipped** | |
| 10 | remove with „delete my data too" | **PASS** — volume, backup folder and restore points gone, front door 404; response names each removal | 6 s stop + <1 s remove |
| 11 | restore the other app | **DATA PASS** — deleted page and attachment back, sha256 identical, Hungarian intact | 32 s to healthy |
| 12 | status pages a week later | dashboard shows the backup in UTC, backup pages in local time (R-500) | |
| A1 | power cut | **PASS** — same versions, data intact, no alarm; one re-login | ≈2 min to dashboard |
| A2 | typo in the code | **PASS** — typo refused, right code accepted after it; 5 failures lock 15 min with an honest Hungarian message; lockout mail goes to the operator only | |
## 2. The intervention
**I1 — the dashboard has no reachable address (R-494, P1).** The setup-code mail says
`https://felhom.drill0242.felhom.eu`. That name has no DNS record; the hub never creates the
Cloudflare tunnel or record (the token is a pasted, optional field); the box's own split-horizon
resolver learns the name 3 m 46 s after the controller starts, but only a device that uses the box as
its DNS server benefits, and nothing says so. The walk reached the dashboard at the guest's LAN address
with the name forced. **Filed before it was performed.** It was performed once and covered every later
dashboard and app request.
**The stop rule (four) was not reached.**
## 3. Harness substitutions — not interventions, and why
These are things **this harness** could not do and **a volunteer could**, so they are not counted.
They are listed because each one hides a part of the path from this walk.
| | what | consequence for the claim |
|---|---|---|
| **H1** | **No mailbox.** Both customer mails go only to the registered address; the hub keeps hashes; the Resend key is send-only. | **The self-bind page was not exercised** — the operator's bind fallback was used. The setup code was minted box-side twice (`--print-reset-code`, generations 3 and 4) via the vaulted break-glass. **The mailed code and the self-bind link are unproven by this walk.** |
| H2 | `qm sendkey` sends US scancodes; the layout was switched from Hungarian to U.S. English | Hungarian keyboard entry of the password and e-mail not exercised |
| H3 | auto-reboot unticked, ISO detached by `qm set` | the "stick still in" reboot not exercised |
| H4 | Terminal UI entry chosen over the graphical default | graphical installer not exercised this run |
**Harness slips, recorded:** the first box-side code (generation 2) was captured with a pattern that
does not match accented letters and was shredded unseen; the first template pick for the bake was
arm64; two BookStack calls used wrong routes (405); one removal was called on a running app, which the
screens never offer (409 — withdrawn as a finding); the A1 poll misread an expired session for 8 min;
the monitoring banner and the restore-finish message were first read from server HTML and are script-
rendered — both readings were corrected in the journal.
## 4. Findings
| row | rank | one line |
|---|---|---|
| **R-493** | **P1** | No customer-facing install instructions; the ISO site has no index. **Blocks inviting anyone.** Stopgap: `runbooks/VOLUNTEER-first-hour.md` |
| **R-494** | **P1** | A new customer's dashboard has no address unless the operator hand-makes a tunnel — the setup mail's link is dead (**I1**) |
| R-495 | P2 | The installer asks four unanswered questions and refuses its own default hostname |
| R-496 | P2 | The console first tells a stranger, in English, to open the Proxmox admin page; calls the passphrase „a jelszavadat" |
| R-497 | P2 | Nothing delivers the Tulajdonosi jelmondat, yet the mail says it was received at setup |
| R-499 | P2 | „Already in the full system backup (PBS) — nothing to do" on a box with no PBS |
| R-498 | P3 | 52 of 53 app pages say a literal `wiki.DOMAIN` |
| R-500 | P3 | Dashboard shows the backup time in UTC, backup pages in local time |
Observations, not filed: the deploy poll has no `degraded` branch (16 s of stale step text);
„0 °C" beside „Nincs adat" for a virtual disk; the removal dialog mentions „éjszakai restic
pillanatképek" on a box with no restic; the drive „attach" list offers the guest's own system volume;
the launcher menu shows an English „Debug"; the lockout e-mail reaches the operator only;
**R-214 still reproduces** (pairing banner and stale code on the console after bind).
## 5. Scope and what this walk does NOT claim
- **Not the recovery-after-rebuild journey.** The capability map's journey row (walk 5) is about a
rebuilt box recovering off-site data. This drill walked the **first hour**; it neither re-proves nor
contradicts that row, and the map is annotated to say so.
- **DR tier off, off-site off.** The customer was created with the DR tier unticked (it provisions an
ep0 namespace; the brief fenced ep0). The off-site and escrow screens were therefore not walked.
- **ep0 was touched anyway, by the product:** enrolment registers a WireGuard peer on ep0 for every
box (`wg registered … ip=10.77.0.5/32 … sync=ok`). The teardown removes it through the host delete.
- **No browser.** Every screen was driven through the endpoint the page calls; script-rendered state
(restore-finish banner, host-metrics card) was not observed.
## 6. Teardown — three layers
See `REPORT-drill-fresh-install-0242.md` §Teardown for the measured before/after of each layer and
the disposition of customer `drill0242`.
Untouched, and checked: demo-hp guests **9201** and **9202** (running throughout), `local-lvm`, the
demo-felhom box, DooPlex's services (only the bake VM, which is the accepted bake exception, reverted
to `virgin`), ep0 beyond the product's own peer registration, and Peti's box.
@@ -0,0 +1,16 @@
=== A1 AFTER 13:58:33 — power-on was 13:48:36
bookstack: running healthy= True images= {'bookstack': 'lscr.io/linuxserver/bookstack:26.05.2', 'bookstack-db': 'mariadb:12.3'}
felhom-controller gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 7 minutes (healthy)
bookstack lscr.io/linuxserver/bookstack:26.05.2 Up 7 minutes (healthy)
bookstack-db mariadb:12.3 Up 7 minutes (healthy)
filebrowser gtstef/filebrowser:1.3.3-stable Up 7 minutes (healthy)
traefik traefik:v3.6.7 Up 7 minutes
felhom-agent 0.130.0
2026-09-14 15:48:51
T_readback 13:58:36
login with the post-change password -> location: https://wiki.drill0242.felhom.eu
page GET 200
sentence present: 2 (negative control: 0)
Hungarian bytes intact (árvíztűrő tükörfúrógép): 2
attachment GET 200 262144B
attachment sha256 equal to the pre-backup upload: YES
@@ -0,0 +1,475 @@
2026-09-14T13:50:38.274225565Z 2026/09/14 13:50:38 [INFO] local-api: channel up (agent 169.254.253.1:8443) — guest 9201, 3 mount(s) visible
2026-09-14T13:50:38.274267604Z 2026/09/14 13:50:38 [INFO] local-api: mount mp9 → /etc/felhom-bootstrap (storage=/var/lib/felhom-agent/guests/9201/bootstrap, class=, backup=false)
2026-09-14T13:50:38.274271331Z 2026/09/14 13:50:38 [INFO] local-api: mount mp8 → /mnt/felhom-drives (storage=/mnt/felhom-drives, class=, backup=false)
2026-09-14T13:50:38.274274066Z 2026/09/14 13:50:38 [INFO] local-api: mount mp0 → /var/lib/felhom (storage=local-lvm, class=, backup=true)
2026-09-14T13:50:38.274276611Z 2026/09/14 13:50:38 [INFO] felhom-controller 0.242.0 starting (customer: drill0242, domain: drill0242.felhom.eu)
2026-09-14T13:50:38.274649891Z 2026/09/14 13:50:38 [INFO] [settings] Loaded settings from /opt/docker/felhom-controller/data/settings.json
2026-09-14T13:50:38.275187830Z 2026/09/14 13:50:38 [INFO] Encryption key loaded from /opt/docker/felhom-controller/data/encryption.key
2026-09-14T13:50:38.406075327Z 2026/09/14 13:50:38 [INFO] [stacks] Using compose command: docker compose
2026-09-14T13:50:38.444994725Z 2026/09/14 13:50:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:50:38.463429119Z 2026/09/14 13:50:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:50:38.463996443Z 2026/09/14 13:50:38 [INFO] [stacks] InjectMissingFields: processed 1 stacks
2026-09-14T13:50:38.465608570Z 2026/09/14 13:50:38 [INFO] [stacks] Encryption migration: no stacks needed migration
2026-09-14T13:50:38.465649647Z 2026/09/14 13:50:38 [INFO] [quiesce] loop started (poll 5m0s, max-quiesce 30m0s)
2026-09-14T13:50:38.468527579Z 2026/09/14 13:50:38 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 0 encrypted, 2 sensitive fields
2026-09-14T13:50:38.469286974Z 2026/09/14 13:50:38 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:50:38.469427367Z 2026/09/14 13:50:38 [INFO] [stacks] desired state for bookstack recorded as "running" (was "")
2026-09-14T13:50:38.469606154Z 2026/09/14 13:50:38 [INFO] [stacks] desired-state backfill: 1 app(s) recorded as running, 0 left unrecorded (state ambiguous — legacy boot behaviour retained)
2026-09-14T13:50:38.470268918Z 2026/09/14 13:50:38 [INFO] [stacks] installed-images backfill: 0 app(s) recorded, 1 already had a record, 0 left unrecorded (could not be observed completely — unknown, which renders nothing)
2026-09-14T13:50:38.470569893Z 2026/09/14 13:50:38 [INFO] [stacks] pin adoption: 0 pinned, 1 already pinned, 0 left unpinned (0 not completely observed, 0 running something the template no longer offers)
2026-09-14T13:50:38.470696500Z 2026/09/14 13:50:38 [INFO] [sync] Starting catalog sync (repo: https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git, interval: 15m0s)
2026-09-14T13:50:38.470907878Z 2026/09/14 13:50:38 [INFO] [sync] Starting catalog sync
2026-09-14T13:50:38.471404579Z 2026/09/14 13:50:38 [INFO] [sync] Pulling latest from https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git (branch: main)
2026-09-14T13:50:38.480405786Z 2026/09/14 13:50:38 [INFO] Metrics store opened at /opt/docker/felhom-controller/data/metrics.db
2026-09-14T13:50:38.481188877Z 2026/09/14 13:50:38 [INFO] Metrics collector started (60s interval)
2026-09-14T13:50:38.482021790Z 2026/09/14 13:50:38 [INFO] Notifier enabled (hub: https://hub.felhom.eu)
2026-09-14T13:50:38.482302386Z 2026/09/14 13:50:38 [INFO] Self-update enabled (check every 6h, auto-update: false, auto-update time: 04:30)
2026-09-14T13:50:38.482634330Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: status-refresh (every 10s)
2026-09-14T13:50:38.482788058Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: stack-scan (every 2m0s)
2026-09-14T13:50:38.482913513Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: health-probes (every 10s)
2026-09-14T13:50:38.483040612Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: system-health (every 5m0s)
2026-09-14T13:50:38.483159164Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: deadapp-check (every 30s)
2026-09-14T13:50:38.483695171Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: ring-spill (every 30s)
2026-09-14T13:50:38.485041368Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job db-dump scheduled for 2026-09-15 02:30 CEST
2026-09-14T13:50:38.485200817Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: offsite-credential-retry (every 5m0s)
2026-09-14T13:50:38.485304262Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: backup-cache (every 5m0s)
2026-09-14T13:50:38.485500059Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-09-15 03:30 CEST
2026-09-14T13:50:38.485701587Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-09-15 04:15 CEST
2026-09-14T13:50:38.485943302Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-09-15 05:10 CEST
2026-09-14T13:50:38.486111146Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-09-15 06:00 CEST
2026-09-14T13:50:38.486226122Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-09-15 05:30 CEST
2026-09-14T13:50:38.486577732Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-09-15 04:00 CEST
2026-09-14T13:50:38.486743443Z 2026/09/14 13:50:38 [INFO] [scheduler] Daily job fill-watch scheduled for 2026-09-15 03:30 CEST
2026-09-14T13:50:38.486876072Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: hub-report (every 15m0s)
2026-09-14T13:50:38.487003431Z 2026/09/14 13:50:38 [INFO] Hub reporting enabled (every 15m0s to https://hub.felhom.eu)
2026-09-14T13:50:38.487093620Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: selfupdate-check (every 6h0m0s)
2026-09-14T13:50:38.487162159Z 2026/09/14 13:50:38 [INFO] ========== Startup Self-Test ==========
2026-09-14T13:50:38.577256179Z 2026/09/14 13:50:38 [INFO] [PASS] Docker socket: reachable (v29.8.0)
2026-09-14T13:50:38.577597891Z 2026/09/14 13:50:38 [INFO] [PASS] Stacks directory: /opt/docker/stacks
2026-09-14T13:50:38.578252059Z 2026/09/14 13:50:38 [INFO] [PASS] Data directory: /opt/docker/felhom-controller/data (writable)
2026-09-14T13:50:38.578398043Z 2026/09/14 13:50:38 [INFO] [PASS] System data path: /mnt/sys_drive
2026-09-14T13:50:38.578570767Z 2026/09/14 13:50:38 [INFO] [WARN] Storage paths: no storage paths registered
2026-09-14T13:50:38.581490057Z 2026/09/14 13:50:38 [INFO] [PASS] Git catalog: 53 app definitions found
2026-09-14T13:50:38.684386800Z 2026/09/14 13:50:38 [INFO] [infra] connected felhom-controller to traefik-public
2026-09-14T13:50:38.684411897Z 2026/09/14 13:50:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:50:38.715969515Z 2026/09/14 13:50:38 [INFO] [PASS] Hub connectivity: https://hub.felhom.eu reachable (HTTP 200)
2026-09-14T13:50:38.716021042Z 2026/09/14 13:50:38 [INFO] [PASS] Metrics DB: 0.0 MB
2026-09-14T13:50:38.716024298Z 2026/09/14 13:50:38 [INFO] ========================================
2026-09-14T13:50:38.716029538Z 2026/09/14 13:50:38 [INFO] Self-test complete: 7 passed, 1 warnings, 0 failed
2026-09-14T13:50:38.716064934Z 2026/09/14 13:50:38 [INFO] [scheduler] Starting scheduler with 18 jobs
2026-09-14T13:50:38.718596837Z 2026/09/14 13:50:38 [INFO] [report] hub wait channel active (hold ≤240s)
2026-09-14T13:50:38.726454508Z 2026/09/14 13:50:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T13:50:38.731184796Z 2026/09/14 13:50:38 [INFO] [web] Auth: using password from settings.json
2026-09-14T13:50:38.731886393Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: disk-health-check (every 1h0m0s)
2026-09-14T13:50:38.732027068Z 2026/09/14 13:50:38 [INFO] [scheduler] Registered periodic job: agent-channel-health (every 1m0s)
2026-09-14T13:50:38.735821811Z 2026/09/14 13:50:38 [INFO] Web UI listening on :8080
2026-09-14T13:50:38.816939822Z 2026/09/14 13:50:38 [INFO] [backup] Discovered 1 databases
2026-09-14T13:50:38.818763265Z 2026/09/14 13:50:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T13:50:38.822284245Z 2026/09/14 13:50:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:50:38.889427612Z 2026/09/14 13:50:38 [INFO] [web] FileBrowser sync — no config/compose change, ensured running without recreate (0 storage path(s))
2026-09-14T13:50:38.916229043Z 2026/09/14 13:50:38 [INFO] [sync] Catalog sync complete
2026-09-14T13:50:38.916283785Z 2026/09/14 13:50:38 [INFO] [sync] Initial sync: Sablonok naprakészek — nincs változás
2026-09-14T13:50:38.932112189Z 2026/09/14 13:50:38 [INFO] [settings] Settings saved
2026-09-14T13:50:38.957635119Z 2026/09/14 13:50:38 [INFO] [monitor] Health check: status=ok
2026-09-14T13:50:43.505664595Z 2026/09/14 13:50:43 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:50:43.720649887Z 2026/09/14 13:50:43 [INFO] [report] Building system report
2026-09-14T13:50:43.762218276Z 2026/09/14 13:50:43 [INFO] Event pushed: controller_started (info) — Controller elindult (0.242.0)
2026-09-14T13:50:43.934593711Z 2026/09/14 13:50:43 [INFO] [monitor] Health check: status=ok
2026-09-14T13:50:44.059530256Z 2026/09/14 13:50:44 [INFO] [report] Hub report pushed successfully (3837 bytes)
2026-09-14T13:50:44.059978827Z 2026/09/14 13:50:44 [INFO] [settings] Settings saved
2026-09-14T13:50:44.059993045Z 2026/09/14 13:50:44 [INFO] Startup hub report sent
2026-09-14T13:50:45.596028137Z 2026/09/14 13:50:45 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:50:48.525691584Z 2026/09/14 13:50:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:50:48.741468951Z 2026/09/14 13:50:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:50:48.768269049Z 2026/09/14 13:50:48 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:50:53.548503940Z 2026/09/14 13:50:53 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:50:53.548558162Z 2026/09/14 13:50:53 [INFO] [bootrecon] boot window: fleet settled after 10s (3 identical samples 5s apart) — sweeping
2026-09-14T13:50:53.548781240Z 2026/09/14 13:50:53 [INFO] [bootrecon] Boot reconciliation: no boot-orphaned apps (nothing to start)
2026-09-14T13:50:55.781382856Z 2026/09/14 13:50:55 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:50:58.740060537Z 2026/09/14 13:50:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:05.981215321Z 2026/09/14 13:51:05 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:08.740393150Z 2026/09/14 13:51:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:09.104902100Z 2026/09/14 13:51:09 [INFO] [selfupdate] Current version 0.242.0 is up to date
2026-09-14T13:51:16.575626195Z 2026/09/14 13:51:16 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:18.744769085Z 2026/09/14 13:51:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:26.778166994Z 2026/09/14 13:51:26 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:28.739593224Z 2026/09/14 13:51:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:36.966460976Z 2026/09/14 13:51:36 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:38.734771212Z 2026/09/14 13:51:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:51:38.743017480Z 2026/09/14 13:51:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:38.932897819Z 2026/09/14 13:51:38 [INFO] [scheduler] Job agent-channel-health completed (took 199ms)
2026-09-14T13:51:47.539244375Z 2026/09/14 13:51:47 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:48.746762744Z 2026/09/14 13:51:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:51:57.755761528Z 2026/09/14 13:51:57 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:51:58.745175135Z 2026/09/14 13:51:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:07.944061589Z 2026/09/14 13:52:07 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:52:08.488708608Z 2026/09/14 13:52:08 [INFO] [fillwatch] checked 2 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok
2026-09-14T13:52:08.740893525Z 2026/09/14 13:52:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:18.503224418Z 2026/09/14 13:52:18 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:52:18.740883268Z 2026/09/14 13:52:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:28.697293232Z 2026/09/14 13:52:28 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:52:28.741743158Z 2026/09/14 13:52:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:38.719307554Z 2026/09/14 13:52:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:52:38.733552318Z 2026/09/14 13:52:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:52:38.738348353Z 2026/09/14 13:52:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:52:38.766646560Z 2026/09/14 13:52:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:38.766712796Z 2026/09/14 13:52:38 [INFO] [scheduler] Job stack-scan completed (took 47ms)
2026-09-14T13:52:38.794924671Z 2026/09/14 13:52:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:38.941657375Z 2026/09/14 13:52:38 [INFO] [scheduler] Job agent-channel-health completed (took 208ms)
2026-09-14T13:52:39.299734670Z 2026/09/14 13:52:39 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:52:48.741912419Z 2026/09/14 13:52:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:49.494532684Z 2026/09/14 13:52:49 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:52:58.739362708Z 2026/09/14 13:52:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:52:59.683497456Z 2026/09/14 13:52:59 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:08.740587306Z 2026/09/14 13:53:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:53:10.227097889Z 2026/09/14 13:53:10 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:18.741711947Z 2026/09/14 13:53:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:53:20.774641332Z 2026/09/14 13:53:20 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:28.739770727Z 2026/09/14 13:53:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:53:30.962823689Z 2026/09/14 13:53:30 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:38.734100251Z 2026/09/14 13:53:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:53:38.741898837Z 2026/09/14 13:53:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:53:38.915877229Z 2026/09/14 13:53:38 [INFO] [scheduler] Job agent-channel-health completed (took 182ms)
2026-09-14T13:53:41.523925752Z 2026/09/14 13:53:41 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:48.743519954Z 2026/09/14 13:53:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:53:51.706948089Z 2026/09/14 13:53:51 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:53:58.740349454Z 2026/09/14 13:53:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:02.279452257Z 2026/09/14 13:54:02 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:08.743779108Z 2026/09/14 13:54:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:12.477098616Z 2026/09/14 13:54:12 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:18.743552270Z 2026/09/14 13:54:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:23.008101271Z 2026/09/14 13:54:23 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:28.740747795Z 2026/09/14 13:54:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:33.200914621Z 2026/09/14 13:54:33 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:38.719787888Z 2026/09/14 13:54:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:54:38.733581389Z 2026/09/14 13:54:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:54:38.750911329Z 2026/09/14 13:54:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:38.770515726Z 2026/09/14 13:54:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:54:38.789898313Z 2026/09/14 13:54:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:38.789926626Z 2026/09/14 13:54:38 [INFO] [scheduler] Job stack-scan completed (took 70ms)
2026-09-14T13:54:38.939123408Z 2026/09/14 13:54:38 [INFO] [scheduler] Job agent-channel-health completed (took 206ms)
2026-09-14T13:54:43.795752454Z 2026/09/14 13:54:43 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:48.740170753Z 2026/09/14 13:54:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:54:53.994774487Z 2026/09/14 13:54:53 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:54:58.747511538Z 2026/09/14 13:54:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:04.202285492Z 2026/09/14 13:55:04 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:08.741776864Z 2026/09/14 13:55:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:14.791105014Z 2026/09/14 13:55:14 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:18.740711781Z 2026/09/14 13:55:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:24.974409652Z 2026/09/14 13:55:24 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:28.738903152Z 2026/09/14 13:55:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:35.556027483Z 2026/09/14 13:55:35 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:38.722270094Z 2026/09/14 13:55:38 [INFO] [scheduler] Running job: backup-cache
2026-09-14T13:55:38.722342681Z 2026/09/14 13:55:38 [INFO] [scheduler] Running job: system-health
2026-09-14T13:55:38.722350727Z 2026/09/14 13:55:38 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T13:55:38.722356267Z 2026/09/14 13:55:38 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T13:55:38.732703210Z 2026/09/14 13:55:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:55:38.759395119Z 2026/09/14 13:55:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:38.760715588Z 2026/09/14 13:55:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T13:55:38.806641991Z 2026/09/14 13:55:38 [INFO] [backup] Discovered 1 databases
2026-09-14T13:55:38.807873964Z 2026/09/14 13:55:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T13:55:38.810051611Z 2026/09/14 13:55:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:55:38.810077279Z 2026/09/14 13:55:38 [INFO] [scheduler] Job backup-cache completed (took 91ms)
2026-09-14T13:55:38.911750254Z 2026/09/14 13:55:38 [INFO] [monitor] Health check: status=ok
2026-09-14T13:55:38.911778507Z 2026/09/14 13:55:38 [INFO] [scheduler] Job system-health completed (took 192ms)
2026-09-14T13:55:38.925606875Z 2026/09/14 13:55:38 [INFO] [scheduler] Job agent-channel-health completed (took 193ms)
2026-09-14T13:55:38.964484545Z 2026/09/14 13:55:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:55:45.744048340Z 2026/09/14 13:55:45 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:48.741377839Z 2026/09/14 13:55:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:55:48.760809315Z 2026/09/14 13:55:48 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:55:55.937000476Z 2026/09/14 13:55:55 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:55:58.740259851Z 2026/09/14 13:55:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:06.533373660Z 2026/09/14 13:56:06 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:08.744322952Z 2026/09/14 13:56:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:16.734895239Z 2026/09/14 13:56:16 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:18.738377259Z 2026/09/14 13:56:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:27.337711492Z 2026/09/14 13:56:27 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:28.739514591Z 2026/09/14 13:56:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:37.533454725Z 2026/09/14 13:56:37 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:38.719864942Z 2026/09/14 13:56:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:56:38.734404578Z 2026/09/14 13:56:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:56:38.744266936Z 2026/09/14 13:56:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:38.766444867Z 2026/09/14 13:56:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:56:38.788677731Z 2026/09/14 13:56:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:38.788762241Z 2026/09/14 13:56:38 [INFO] [scheduler] Job stack-scan completed (took 69ms)
2026-09-14T13:56:38.939378837Z 2026/09/14 13:56:38 [INFO] [scheduler] Job agent-channel-health completed (took 206ms)
2026-09-14T13:56:47.727602531Z 2026/09/14 13:56:47 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:48.741067645Z 2026/09/14 13:56:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:56:58.299107668Z 2026/09/14 13:56:58 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:56:58.740730913Z 2026/09/14 13:56:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:08.490441165Z 2026/09/14 13:57:08 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:57:08.740259597Z 2026/09/14 13:57:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:18.679590206Z 2026/09/14 13:57:18 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:57:18.739012788Z 2026/09/14 13:57:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:28.741276969Z 2026/09/14 13:57:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:29.259983622Z 2026/09/14 13:57:29 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:57:38.733316139Z 2026/09/14 13:57:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:57:38.740784562Z 2026/09/14 13:57:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:38.908675552Z 2026/09/14 13:57:38 [INFO] [scheduler] Job agent-channel-health completed (took 175ms)
2026-09-14T13:57:39.439439259Z 2026/09/14 13:57:39 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:57:48.740140484Z 2026/09/14 13:57:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:57:50.013849013Z 2026/09/14 13:57:50 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:57:58.740740676Z 2026/09/14 13:57:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:00.220067019Z 2026/09/14 13:58:00 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:58:08.741842477Z 2026/09/14 13:58:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:10.787171434Z 2026/09/14 13:58:10 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:58:11.335895902Z 2026/09/14 13:58:11 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:58:18.741777541Z 2026/09/14 13:58:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:20.975598834Z 2026/09/14 13:58:20 [WARN] [api] Unauthorized request to /api/stacks/bookstack from 172.18.0.3:49792
2026-09-14T13:58:28.739326101Z 2026/09/14 13:58:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:33.589291618Z 2026/09/14 13:58:33 [INFO] [web] Login from 172.18.0.3:49792
2026-09-14T13:58:38.720080441Z 2026/09/14 13:58:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:58:38.733301865Z 2026/09/14 13:58:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:58:38.737772049Z 2026/09/14 13:58:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:58:38.760194274Z 2026/09/14 13:58:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:38.760225223Z 2026/09/14 13:58:38 [INFO] [scheduler] Job stack-scan completed (took 40ms)
2026-09-14T13:58:38.783045581Z 2026/09/14 13:58:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:38.914063952Z 2026/09/14 13:58:38 [INFO] [scheduler] Job agent-channel-health completed (took 181ms)
2026-09-14T13:58:48.739943236Z 2026/09/14 13:58:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:58:58.742129674Z 2026/09/14 13:58:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:08.740352898Z 2026/09/14 13:59:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:18.743886622Z 2026/09/14 13:59:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:28.741814375Z 2026/09/14 13:59:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:38.732819883Z 2026/09/14 13:59:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:59:38.741877721Z 2026/09/14 13:59:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:38.909831249Z 2026/09/14 13:59:38 [INFO] [scheduler] Job agent-channel-health completed (took 177ms)
2026-09-14T13:59:48.739864057Z 2026/09/14 13:59:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:59:58.741931406Z 2026/09/14 13:59:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:08.745693076Z 2026/09/14 14:00:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:10.059073551Z 2026/09/14 14:00:10 [INFO] [settings] Settings saved
2026-09-14T14:00:10.059178829Z 2026/09/14 14:00:10 [INFO] [settings] Settings saved
2026-09-14T14:00:10.059187566Z 2026/09/14 14:00:10 [INFO] [web] All sessions invalidated (cleared 1)
2026-09-14T14:00:10.059191894Z 2026/09/14 14:00:10 [INFO] [web] dashboard password reset by the customer from 192.168.0.104 (code generation 4 consumed)
2026-09-14T14:00:10.321690547Z 2026/09/14 14:00:10 [INFO] [web] Login from 172.18.0.3:57192
2026-09-14T14:00:10.562876456Z 2026/09/14 14:00:10 [WARN] [web] Failed login from 172.18.0.3:57192
2026-09-14T14:00:12.059672296Z 2026/09/14 14:00:12 [INFO] [report] Building system report
2026-09-14T14:00:12.282339052Z 2026/09/14 14:00:12 [INFO] [monitor] Health check: status=ok
2026-09-14T14:00:12.503456144Z 2026/09/14 14:00:12 [INFO] [report] Hub report pushed successfully (3918 bytes)
2026-09-14T14:00:12.503481020Z 2026/09/14 14:00:12 [INFO] [settings] Settings saved
2026-09-14T14:00:12.785392532Z 2026/09/14 14:00:12 [WARN] [web] claim: code lockout tripped (source 192.168.0.104) — 15 min
2026-09-14T14:00:12.795380884Z 2026/09/14 14:00:12 [INFO] Event pushed: claim_lockout (warning) — Túl sok hibás beállító kód — a beállító oldal 15 percre zárolva
2026-09-14T14:00:18.741654602Z 2026/09/14 14:00:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:28.743154183Z 2026/09/14 14:00:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:38.722667331Z 2026/09/14 14:00:38 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T14:00:38.722711625Z 2026/09/14 14:00:38 [INFO] [scheduler] Running job: backup-cache
2026-09-14T14:00:38.722718558Z 2026/09/14 14:00:38 [INFO] [scheduler] Running job: system-health
2026-09-14T14:00:38.722723748Z 2026/09/14 14:00:38 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T14:00:38.722729058Z 2026/09/14 14:00:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:00:38.733509704Z 2026/09/14 14:00:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:00:38.762210202Z 2026/09/14 14:00:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:38.762244508Z 2026/09/14 14:00:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T14:00:38.781523033Z 2026/09/14 14:00:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:00:38.808609468Z 2026/09/14 14:00:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:38.808670673Z 2026/09/14 14:00:38 [INFO] [scheduler] Job stack-scan completed (took 86ms)
2026-09-14T14:00:38.867012224Z 2026/09/14 14:00:38 [INFO] [backup] Discovered 1 databases
2026-09-14T14:00:38.868708905Z 2026/09/14 14:00:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T14:00:38.870246897Z 2026/09/14 14:00:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T14:00:38.870273296Z 2026/09/14 14:00:38 [INFO] [scheduler] Job backup-cache completed (took 150ms)
2026-09-14T14:00:38.925258658Z 2026/09/14 14:00:38 [INFO] [scheduler] Job agent-channel-health completed (took 191ms)
2026-09-14T14:00:38.928250061Z 2026/09/14 14:00:38 [INFO] [monitor] Health check: status=ok
2026-09-14T14:00:38.928286359Z 2026/09/14 14:00:38 [INFO] [scheduler] Job system-health completed (took 208ms)
2026-09-14T14:00:38.978661885Z 2026/09/14 14:00:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T14:00:48.745735218Z 2026/09/14 14:00:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:00:48.753609562Z 2026/09/14 14:00:48 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T14:00:58.743227641Z 2026/09/14 14:00:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:08.742832122Z 2026/09/14 14:01:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:18.743204125Z 2026/09/14 14:01:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:28.742124886Z 2026/09/14 14:01:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:38.733232884Z 2026/09/14 14:01:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:01:38.741317653Z 2026/09/14 14:01:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:38.741445565Z 2026/09/14 14:01:38 [INFO] [deadapp] check alive: 20 scans since boot, 1 deployed app(s) evaluated, 0 currently down
2026-09-14T14:01:38.930412146Z 2026/09/14 14:01:38 [INFO] [scheduler] Job agent-channel-health completed (took 197ms)
2026-09-14T14:01:48.744308226Z 2026/09/14 14:01:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:01:58.746721839Z 2026/09/14 14:01:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:08.739660196Z 2026/09/14 14:02:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:18.742517918Z 2026/09/14 14:02:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:28.742228735Z 2026/09/14 14:02:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:38.719761508Z 2026/09/14 14:02:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:02:38.732862364Z 2026/09/14 14:02:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:02:38.737145054Z 2026/09/14 14:02:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:02:38.760690649Z 2026/09/14 14:02:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:38.760721307Z 2026/09/14 14:02:38 [INFO] [scheduler] Job stack-scan completed (took 41ms)
2026-09-14T14:02:38.783281682Z 2026/09/14 14:02:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:38.917660409Z 2026/09/14 14:02:38 [INFO] [scheduler] Job agent-channel-health completed (took 185ms)
2026-09-14T14:02:48.740276971Z 2026/09/14 14:02:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:02:58.744324460Z 2026/09/14 14:02:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:08.742248743Z 2026/09/14 14:03:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:18.742988096Z 2026/09/14 14:03:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:28.743269822Z 2026/09/14 14:03:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:38.733300658Z 2026/09/14 14:03:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:03:38.746112603Z 2026/09/14 14:03:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:38.914054245Z 2026/09/14 14:03:38 [INFO] [scheduler] Job agent-channel-health completed (took 181ms)
2026-09-14T14:03:48.740792082Z 2026/09/14 14:03:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:03:58.743951990Z 2026/09/14 14:03:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:08.743667254Z 2026/09/14 14:04:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:18.745853288Z 2026/09/14 14:04:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:28.742970858Z 2026/09/14 14:04:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:38.720162752Z 2026/09/14 14:04:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:04:38.734155591Z 2026/09/14 14:04:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:04:38.741650557Z 2026/09/14 14:04:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:38.759643903Z 2026/09/14 14:04:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:04:38.780719219Z 2026/09/14 14:04:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:38.780748004Z 2026/09/14 14:04:38 [INFO] [scheduler] Job stack-scan completed (took 61ms)
2026-09-14T14:04:38.936763133Z 2026/09/14 14:04:38 [INFO] [scheduler] Job agent-channel-health completed (took 203ms)
2026-09-14T14:04:48.742338929Z 2026/09/14 14:04:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:04:58.743400107Z 2026/09/14 14:04:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:08.743398155Z 2026/09/14 14:05:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:18.742061550Z 2026/09/14 14:05:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:28.744904822Z 2026/09/14 14:05:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:38.471528304Z 2026/09/14 14:05:38 [INFO] [sync] Starting catalog sync
2026-09-14T14:05:38.471579762Z 2026/09/14 14:05:38 [INFO] [sync] Pulling latest from https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git (branch: main)
2026-09-14T14:05:38.665304881Z 2026/09/14 14:05:38 [INFO] [sync] Catalog sync complete
2026-09-14T14:05:38.665341510Z 2026/09/14 14:05:38 [INFO] [sync] Periodic sync: Sablonok naprakészek — nincs változás
2026-09-14T14:05:38.719559903Z 2026/09/14 14:05:38 [INFO] [scheduler] Running job: hub-report
2026-09-14T14:05:38.719802701Z 2026/09/14 14:05:38 [INFO] [report] Building system report
2026-09-14T14:05:38.722005297Z 2026/09/14 14:05:38 [INFO] [scheduler] Running job: system-health
2026-09-14T14:05:38.723031568Z 2026/09/14 14:05:38 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T14:05:38.723069879Z 2026/09/14 14:05:38 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T14:05:38.723075089Z 2026/09/14 14:05:38 [INFO] [scheduler] Running job: backup-cache
2026-09-14T14:05:38.734076362Z 2026/09/14 14:05:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:05:38.757378284Z 2026/09/14 14:05:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:38.757406167Z 2026/09/14 14:05:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T14:05:38.820892334Z 2026/09/14 14:05:38 [INFO] [backup] Discovered 1 databases
2026-09-14T14:05:38.822176782Z 2026/09/14 14:05:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T14:05:38.827988652Z 2026/09/14 14:05:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T14:05:38.828017878Z 2026/09/14 14:05:38 [INFO] [scheduler] Job backup-cache completed (took 105ms)
2026-09-14T14:05:38.929726671Z 2026/09/14 14:05:38 [INFO] [scheduler] Job agent-channel-health completed (took 197ms)
2026-09-14T14:05:38.938670033Z 2026/09/14 14:05:38 [INFO] [monitor] Health check: status=ok
2026-09-14T14:05:38.938748832Z 2026/09/14 14:05:38 [INFO] [scheduler] Job system-health completed (took 217ms)
2026-09-14T14:05:38.989880027Z 2026/09/14 14:05:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T14:05:38.993991621Z 2026/09/14 14:05:38 [INFO] [monitor] Health check: status=ok
2026-09-14T14:05:39.138674575Z 2026/09/14 14:05:39 [INFO] [report] Hub report pushed successfully (3441 bytes)
2026-09-14T14:05:39.138702879Z 2026/09/14 14:05:39 [INFO] [settings] Settings saved
2026-09-14T14:05:39.138706866Z 2026/09/14 14:05:39 [INFO] [scheduler] Job hub-report completed (took 419ms)
2026-09-14T14:05:48.743817516Z 2026/09/14 14:05:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:05:48.771959932Z 2026/09/14 14:05:48 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T14:05:58.749258090Z 2026/09/14 14:05:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:08.743355743Z 2026/09/14 14:06:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:18.743789450Z 2026/09/14 14:06:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:28.745986371Z 2026/09/14 14:06:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:38.721859304Z 2026/09/14 14:06:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:06:38.733391561Z 2026/09/14 14:06:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:06:38.743547866Z 2026/09/14 14:06:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:38.762304182Z 2026/09/14 14:06:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:06:38.782734565Z 2026/09/14 14:06:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:38.782762667Z 2026/09/14 14:06:38 [INFO] [scheduler] Job stack-scan completed (took 61ms)
2026-09-14T14:06:38.924845635Z 2026/09/14 14:06:38 [INFO] [scheduler] Job agent-channel-health completed (took 192ms)
2026-09-14T14:06:48.747834948Z 2026/09/14 14:06:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:06:58.745912348Z 2026/09/14 14:06:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:08.743340930Z 2026/09/14 14:07:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:18.743306982Z 2026/09/14 14:07:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:28.744251497Z 2026/09/14 14:07:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:38.733004479Z 2026/09/14 14:07:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:07:38.743114736Z 2026/09/14 14:07:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:38.908643152Z 2026/09/14 14:07:38 [INFO] [scheduler] Job agent-channel-health completed (took 176ms)
2026-09-14T14:07:48.742032479Z 2026/09/14 14:07:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:07:58.743718178Z 2026/09/14 14:07:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:08.740928168Z 2026/09/14 14:08:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:18.741447736Z 2026/09/14 14:08:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:28.742132215Z 2026/09/14 14:08:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:38.720023167Z 2026/09/14 14:08:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:08:38.733972434Z 2026/09/14 14:08:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:08:38.740376425Z 2026/09/14 14:08:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:38.758384663Z 2026/09/14 14:08:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:08:38.778718343Z 2026/09/14 14:08:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:38.778759801Z 2026/09/14 14:08:38 [INFO] [scheduler] Job stack-scan completed (took 59ms)
2026-09-14T14:08:38.907972404Z 2026/09/14 14:08:38 [INFO] [scheduler] Job agent-channel-health completed (took 174ms)
2026-09-14T14:08:48.739844916Z 2026/09/14 14:08:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:08:58.741069783Z 2026/09/14 14:08:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:08.742817670Z 2026/09/14 14:09:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:18.744293945Z 2026/09/14 14:09:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:28.741578244Z 2026/09/14 14:09:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:38.733104923Z 2026/09/14 14:09:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:09:38.746665256Z 2026/09/14 14:09:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:38.928040631Z 2026/09/14 14:09:38 [INFO] [scheduler] Job agent-channel-health completed (took 195ms)
2026-09-14T14:09:48.740020564Z 2026/09/14 14:09:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:09:58.742730504Z 2026/09/14 14:09:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:08.744280183Z 2026/09/14 14:10:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:18.739412985Z 2026/09/14 14:10:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:28.743108698Z 2026/09/14 14:10:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:38.719677230Z 2026/09/14 14:10:38 [INFO] [scheduler] Running job: backup-cache
2026-09-14T14:10:38.720002714Z 2026/09/14 14:10:38 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T14:10:38.720016040Z 2026/09/14 14:10:38 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T14:10:38.720019997Z 2026/09/14 14:10:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:10:38.720023574Z 2026/09/14 14:10:38 [INFO] [scheduler] Running job: system-health
2026-09-14T14:10:38.733215902Z 2026/09/14 14:10:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:10:38.748349506Z 2026/09/14 14:10:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:38.772242798Z 2026/09/14 14:10:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:10:38.794915517Z 2026/09/14 14:10:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:38.795172462Z 2026/09/14 14:10:38 [INFO] [scheduler] Job stack-scan completed (took 75ms)
2026-09-14T14:10:38.795308800Z 2026/09/14 14:10:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T14:10:38.848467850Z 2026/09/14 14:10:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T14:10:38.848774809Z 2026/09/14 14:10:38 [INFO] [backup] Discovered 1 databases
2026-09-14T14:10:38.854669709Z 2026/09/14 14:10:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T14:10:38.854717500Z 2026/09/14 14:10:38 [INFO] [scheduler] Job backup-cache completed (took 135ms)
2026-09-14T14:10:38.907589958Z 2026/09/14 14:10:38 [INFO] [monitor] Health check: status=ok
2026-09-14T14:10:38.907616779Z 2026/09/14 14:10:38 [INFO] [scheduler] Job system-health completed (took 188ms)
2026-09-14T14:10:38.930979499Z 2026/09/14 14:10:38 [INFO] [scheduler] Job agent-channel-health completed (took 198ms)
2026-09-14T14:10:38.962875763Z 2026/09/14 14:10:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T14:10:48.742619311Z 2026/09/14 14:10:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:58.743657055Z 2026/09/14 14:10:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:10:58.774138317Z 2026/09/14 14:10:58 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T14:11:08.744651565Z 2026/09/14 14:11:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:11:18.745295465Z 2026/09/14 14:11:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:11:28.743487023Z 2026/09/14 14:11:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:11:38.733271429Z 2026/09/14 14:11:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:11:38.741440582Z 2026/09/14 14:11:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:11:38.741470960Z 2026/09/14 14:11:38 [INFO] [deadapp] check alive: 40 scans since boot, 1 deployed app(s) evaluated, 0 currently down
2026-09-14T14:11:38.913169164Z 2026/09/14 14:11:38 [INFO] [scheduler] Job agent-channel-health completed (took 180ms)
2026-09-14T14:11:48.741653554Z 2026/09/14 14:11:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:11:58.742226062Z 2026/09/14 14:11:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:08.748807177Z 2026/09/14 14:12:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:18.739698152Z 2026/09/14 14:12:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:28.743618781Z 2026/09/14 14:12:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:38.719449889Z 2026/09/14 14:12:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:12:38.733352831Z 2026/09/14 14:12:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:12:38.743412426Z 2026/09/14 14:12:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:38.763085634Z 2026/09/14 14:12:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:12:38.783007060Z 2026/09/14 14:12:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:38.783048338Z 2026/09/14 14:12:38 [INFO] [scheduler] Job stack-scan completed (took 64ms)
2026-09-14T14:12:38.916081666Z 2026/09/14 14:12:38 [INFO] [scheduler] Job agent-channel-health completed (took 183ms)
2026-09-14T14:12:48.742095296Z 2026/09/14 14:12:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:12:58.745728612Z 2026/09/14 14:12:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:08.742170702Z 2026/09/14 14:13:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:18.741603519Z 2026/09/14 14:13:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:28.740354958Z 2026/09/14 14:13:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:38.733197932Z 2026/09/14 14:13:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:13:38.740989575Z 2026/09/14 14:13:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:38.915563952Z 2026/09/14 14:13:38 [INFO] [scheduler] Job agent-channel-health completed (took 182ms)
2026-09-14T14:13:48.741645790Z 2026/09/14 14:13:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:13:58.743729946Z 2026/09/14 14:13:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:08.742471946Z 2026/09/14 14:14:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:18.746335830Z 2026/09/14 14:14:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:28.745410030Z 2026/09/14 14:14:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:38.720116118Z 2026/09/14 14:14:38 [INFO] [scheduler] Running job: stack-scan
2026-09-14T14:14:38.733590535Z 2026/09/14 14:14:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:14:38.744926715Z 2026/09/14 14:14:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:38.767212173Z 2026/09/14 14:14:38 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T14:14:38.787427061Z 2026/09/14 14:14:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:38.787456978Z 2026/09/14 14:14:38 [INFO] [scheduler] Job stack-scan completed (took 66ms)
2026-09-14T14:14:38.926111631Z 2026/09/14 14:14:38 [INFO] [scheduler] Job agent-channel-health completed (took 193ms)
2026-09-14T14:14:48.742393839Z 2026/09/14 14:14:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:14:58.742826342Z 2026/09/14 14:14:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:08.741505144Z 2026/09/14 14:15:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:18.742807450Z 2026/09/14 14:15:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:28.740478922Z 2026/09/14 14:15:28 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:38.719410829Z 2026/09/14 14:15:38 [INFO] [scheduler] Running job: system-health
2026-09-14T14:15:38.721805602Z 2026/09/14 14:15:38 [INFO] [scheduler] Running job: backup-cache
2026-09-14T14:15:38.721829246Z 2026/09/14 14:15:38 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T14:15:38.721833053Z 2026/09/14 14:15:38 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T14:15:38.733874656Z 2026/09/14 14:15:38 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T14:15:38.743704620Z 2026/09/14 14:15:38 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:38.744476047Z 2026/09/14 14:15:38 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T14:15:38.791614041Z 2026/09/14 14:15:38 [INFO] [backup] Discovered 1 databases
2026-09-14T14:15:38.792594153Z 2026/09/14 14:15:38 [INFO] [backup] Discovered app data: 1 apps
2026-09-14T14:15:38.797860068Z 2026/09/14 14:15:38 [INFO] [backup] Backup status cache refreshed
2026-09-14T14:15:38.797990615Z 2026/09/14 14:15:38 [INFO] [scheduler] Job backup-cache completed (took 78ms)
2026-09-14T14:15:38.895414920Z 2026/09/14 14:15:38 [INFO] [monitor] Health check: status=ok
2026-09-14T14:15:38.895446539Z 2026/09/14 14:15:38 [INFO] [scheduler] Job system-health completed (took 176ms)
2026-09-14T14:15:38.924255890Z 2026/09/14 14:15:38 [INFO] [scheduler] Job agent-channel-health completed (took 190ms)
2026-09-14T14:15:38.945590321Z 2026/09/14 14:15:38 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T14:15:48.740056957Z 2026/09/14 14:15:48 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:15:58.741295784Z 2026/09/14 14:15:58 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:16:08.747272453Z 2026/09/14 14:16:08 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T14:16:08.784512242Z 2026/09/14 14:16:08 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T14:16:18.741716434Z 2026/09/14 14:16:18 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
@@ -0,0 +1,15 @@
felhom-controller gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 25 minutes (healthy)
bookstack lscr.io/linuxserver/bookstack:26.05.2 Up 25 minutes (healthy)
bookstack-db mariadb:12.3 Up 25 minutes (healthy)
filebrowser gtstef/filebrowser:1.3.3-stable Up 25 minutes (healthy)
traefik traefik:v3.6.7 Up 25 minutes
0f949aacc8b358af94f5f66f78179a9e21bb1e8a1f8ffce37377463a1c4cb53a
1fb885018e6c1a8c780c567b1a891bf4585535445e86c7fe25756338d3ef2d48
63cbd6f66e65f3d3a658dd5b472fc252b68b209e1da81e502d6470160270a73c
412bc56bd80a69f8c9bc80f42b99af84042b296816be2ee571f6087309301acb
abcedb24829869e3f4ee70e7fbd58b54b853e07721f3b91ca60351e99b5cfc82
bookstack_bookstack_config
bookstack_bookstack_db_data
cbdab95c27fba5d5b32aa22b3a6802ddd7481c8f2a58a7f2163defa56b344e72
felhom-controller-data
filebrowser_filebrowser_data
@@ -0,0 +1,55 @@
2026/09/14 15:03:04 [INFO] Customer config created: drill0242
2026/09/14 15:03:04 [INFO] self-bind link emailed to the registered address of drill0242
2026/09/14 15:03:04 [INFO] self-bind link (hash 4270bdd2…, valid 7 days) emailed to the registered address of drill0242
2026/09/14 15:03:04 [INFO] self-bind link auto-minted for drill0242 on customer creation (the console banner's promised email now exists)
2026/09/14 15:21:44 [INFO] appliance 25 BOUND to customer drill0242 (mode=appliance) — delivery staged for its next poll
2026/09/14 15:21:45 [INFO] appliance credentials DELIVERED once to appliance 25 (customer=drill0242 mode=appliance; passphrase withheld)
2026/09/14 15:21:52 [INFO] claim claim email sent to the registered address of drill0242
2026/09/14 15:21:52 [INFO] [claim] claim code (gen 1) emailed to the registered address of drill0242
2026/09/14 15:21:52 [INFO] Config downloaded for customer drill0242
2026/09/14 15:22:21 [INFO] host enrolled: drill0242-3f4b42 (customer drill0242)
2026/09/14 15:22:21 [INFO] vaulted break-glass recovery credential for host drill0242-3f4b42 (user=root@pam, secret 32 chars)
2026/09/14 15:22:22 [INFO] Artifact manifest served for customer drill0242 (agent=0.130.0 golden=0.242.0)
2026/09/14 15:22:22 [INFO] Config downloaded for customer drill0242
2026/09/14 15:22:38 [INFO] wg registered: host=drill0242-3f4b42 pubkey=FXutaQg+qb4RQnOaF3WsN6h55nA0NzMi2UL0ZL8GLx0= ip=10.77.0.5/32 changed=true gen=1 sync=ok
2026/09/14 15:22:39 [INFO] host-report from drill0242-3f4b42 (0 guests, 2 storage targets, 0 backups, 0 restore-tests, 0 pbs-snapshots, 10210 bytes)
2026/09/14 15:22:39 [INFO] DR-recipe host-half stored for customer drill0242 (host drill0242-3f4b42, v1)
2026/09/14 15:22:39 [INFO] Config downloaded for customer drill0242
2026/09/14 15:22:49 [INFO] restore-test staleness: drill0242 local tier: not restore-proven yet, but only watching for 0s (grace 168h0m0s since first contact 2026-09-14T13:22:39Z) — newborn, not a fault
2026/09/14 15:23:38 [INFO] Config downloaded for customer drill0242
2026/09/14 15:23:58 [INFO] Event from drill0242: controller_started (info) — Controller elindult (0.242.0)
2026/09/14 15:23:58 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:23:58 [INFO] Received report from drill0242 (2282 bytes)
2026/09/14 15:23:58 [INFO] managed floor SERVED for drill0242: floor 0.242.0, agent requirement "0.129.0" from manifest (golden 0.242.0)
2026/09/14 15:27:25 [INFO] operator revealed break-glass console credential for host drill0242-3f4b42 (user=root@pam, secret 32 chars)
2026/09/14 15:31:23 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:31:23 [INFO] Received report from drill0242 (2306 bytes)
2026/09/14 15:31:23 [INFO] [claim] customer drill0242 CLAIMED its dashboard (password set by the customer)
2026/09/14 15:31:23 [INFO] [claim] notification prefs seeded for drill0242 from the registered email (default critical set)
2026/09/14 15:31:23 [INFO] claim claimed email sent to the registered address of drill0242
2026/09/14 15:34:38 [INFO] Event from drill0242: app_deployed (info) — Alkalmazás telepítve: BookStack
2026/09/14 15:34:41 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:34:41 [INFO] Received report from drill0242 (2372 bytes)
2026/09/14 15:35:47 [INFO] Event from drill0242: app_deployed (info) — Alkalmazás telepítve: PrivateBin
2026/09/14 15:35:50 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:35:50 [INFO] Received report from drill0242 (4629 bytes)
2026/09/14 15:37:40 [INFO] host-report from drill0242-3f4b42 (1 guests, 2 storage targets, 1 backups, 0 restore-tests, 0 pbs-snapshots, 11093 bytes)
2026/09/14 15:37:40 [INFO] DR-recipe host-half stored for customer drill0242 (host drill0242-3f4b42, v1)
2026/09/14 15:38:54 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:38:54 [INFO] Received report from drill0242 (5039 bytes)
2026/09/14 15:45:34 [INFO] Event from drill0242: app_removed (info) — Alkalmazás eltávolítva: privatebin
2026/09/14 15:45:36 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:45:36 [INFO] Received report from drill0242 (4750 bytes)
2026/09/14 15:49:04 [INFO] host-report from drill0242-3f4b42 (1 guests, 2 storage targets, 0 backups, 0 restore-tests, 0 pbs-snapshots, 10548 bytes)
2026/09/14 15:49:04 [INFO] DR-recipe host-half stored for customer drill0242 (host drill0242-3f4b42, v1)
2026/09/14 15:50:43 [INFO] Event from drill0242: controller_started (info) — Controller elindult (0.242.0)
2026/09/14 15:50:44 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 15:50:44 [INFO] Received report from drill0242 (3837 bytes)
2026/09/14 16:00:12 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 16:00:12 [INFO] Received report from drill0242 (3918 bytes)
2026/09/14 16:00:12 [INFO] Event from drill0242: claim_lockout (warning) — Túl sok hibás beállító kód — a beállító oldal 15 percre zárolva
2026/09/14 16:00:16 [INFO] Operator email sent for drill0242/claim_lockout
2026/09/14 16:04:06 [INFO] host-report from drill0242-3f4b42 (1 guests, 2 storage targets, 0 backups, 0 restore-tests, 0 pbs-snapshots, 10777 bytes)
2026/09/14 16:04:06 [INFO] DR-recipe host-half stored for customer drill0242 (host drill0242-3f4b42, v1)
2026/09/14 16:05:39 [INFO] DR-recipe app-half stored for customer drill0242 (v1)
2026/09/14 16:05:39 [INFO] Received report from drill0242 (3441 bytes)
@@ -0,0 +1,173 @@
2026-09-14T15:20:14+02:00 drill0242 systemd[1]: Starting felhom-bootstrap.service - Felhom host bootstrap (fetch + run felhom-host-install.sh unattended, retry until success)...
2026-09-14T15:20:14+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: PAIRING mode (generic ISO, no baked customer/passphrase) — hub=https://hub.felhom.eu
2026-09-14T15:20:14+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: registering unclaimed appliance at the hub
2026-09-14T15:20:15+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: registered — appliance token stored (0600); waiting for the operator or a customer self-bind
2026-09-14T15:20:15+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: console font -> Lat2-Terminus16 (Latin-2, ő/ű capable)
2026-09-14T15:20:15+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: not bound yet — polling every 30s until the operator or a customer self-bind lands (this is the normal waiting state, not an error)
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: bind DELIVERED — writing credentials to the env and switching to direct install
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: fetching host-install: https://felhom.eu/scripts/felhom-host-install.sh
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: running host-install (customer=drill0242 mode=appliance hub=https://hub.felhom.eu)
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] auto-sized guest RAM: 4096 MiB (host 7872 MiB; clamp(host-4096, min 4096, max host-2048), ceiling host-1024)
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] auto-sized guest cores: 3 (host 4 cores; host-1, min 2)
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] felhom-host-install v1.28.0 — mode=appliance customer=drill0242 vmid=9201
2026-09-14T15:21:45+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 1/8 pre-flight
2026-09-14T15:21:46+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve)
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] node: drill0242 (auto)
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] agent config: /etc/felhom-agent/agent.json
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] agent: not installed yet — will be fetched + installed in step 5/8
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] local-lvm free: ~113 GiB
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] local-lvm free ~113 GiB < hard min 120 GiB
2026-09-14T15:21:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] free RAM: ~6213 MiB
2026-09-14T15:21:49+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] existing guests on this host: 0 (pct+qm)
2026-09-14T15:21:50+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] archive storage 'local' present
2026-09-14T15:21:51+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] acl storage 'felhom-pbs' not present yet — expected: the PBS-DR tier creates it; the grant is pre-positioned deliberately
2026-09-14T15:21:51+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] dnsmasq: not present before Felhom — recorded; uninstall will remove it again if we install it
2026-09-14T15:21:52+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] hub reachable (https://hub.felhom.eu)
2026-09-14T15:21:52+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] customer 'drill0242' exists + passphrase valid
2026-09-14T15:21:53+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] golden: none local — will fetch + verify from Gitea in step 7/8
2026-09-14T15:21:55+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] pre-flight passed
2026-09-14T15:21:55+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 2/8 Proxmox API token
2026-09-14T15:21:59+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] token minted (secret captured, not logged)
2026-09-14T15:22:19+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] scoped ACL applied (Base@/, Guest@/pool/felhom + /vms/990000..990009, Store@[local local-lvm felhom-pbs])
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [SKIP] old broad role FelhomAgent already absent
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 3/8 compute volume grows
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] auto-computed from ~113 GiB free (ONE volume since R-165)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] grows: rootfs +0G (->32G), data +46G (->70G, ONE volume)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 4/8 host enrollment (POST /host-enroll)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] host MINTED (first enroll)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] host_id: drill0242-3f4b42 (api_key captured, not logged)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 4b/8 break-glass credential (root@pam console password → hub vault)
2026-09-14T15:22:21+02:00 drill0242 chpasswd[1745]: pam_unix(chpasswd:chauthtok): password changed for root
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] root@pam password set + vaulted to the hub (retrieve via the operator /admin path; never logged here)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] NOTE: the root@pam password just CHANGED — the old one now fails at the PVE web GUI (:8006).
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] Retrieve the new one at hub → host page (vaulted recovery credential).
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 5/8 agent install (fetch + verify + install)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] disabled pve-enterprise.sources (Enabled: no)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] disabled ceph.sources (Enabled: no)
2026-09-14T15:22:21+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] added pve-no-subscription.sources (suite=trixie)
2026-09-14T15:22:22+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] apt repos aligned to no-subscription (changed; apt-get update OK)
2026-09-14T15:22:22+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
2026-09-14T15:22:22+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] manifest: agent v0.130.0 (sha a56a92a7bd68f5b4…), golden v0.242.0
2026-09-14T15:22:22+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] fetching agent binary v0.130.0 from Gitea …
2026-09-14T15:22:23+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] verified sha256 a56a92a7bd68f5b4… matches the hub manifest
2026-09-14T15:22:23+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /usr/local/bin/felhom-agent (felhom-agent 0.130.0)
2026-09-14T15:22:23+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] installing the 'sudo' package (required for the non-root agent model) …
2026-09-14T15:22:26+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] sudo installed (Sudo version 1.9.16p2)
2026-09-14T15:22:26+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] installing the 'age' package (escrow ceremony identity-wrap dependency) …
2026-09-14T15:22:28+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] age installed (1.2.1)
2026-09-14T15:22:28+02:00 drill0242 useradd[1982]: new group: name=felhom-agent, GID=990
2026-09-14T15:22:28+02:00 drill0242 useradd[1982]: new user: name=felhom-agent, UID=999, GID=990, home=/home/felhom-agent, shell=/usr/sbin/nologin, from=none
2026-09-14T15:22:29+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] created service user felhom-agent
2026-09-14T15:22:29+02:00 drill0242 usermod[1990]: add 'felhom-agent' to group 'systemd-journal'
2026-09-14T15:22:29+02:00 drill0242 usermod[1990]: add 'felhom-agent' to shadow group 'systemd-journal'
2026-09-14T15:22:29+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] added felhom-agent to systemd-journal (unprivileged journal read for NAS verify)
2026-09-14T15:22:30+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /usr/local/sbin/felhom-mkfs-guarded (0755, the guarded mkfs path)
2026-09-14T15:22:31+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /usr/local/sbin/felhom-selfupdate-guarded (0755, the guarded A/B binary-swap path)
2026-09-14T15:22:31+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /usr/local/sbin/felhom-pbs-apply (0755, the guarded PBS-DR apply path)
2026-09-14T15:22:31+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)
2026-09-14T15:22:31+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /etc/sudoers.d/felhom-agent (0440, visudo-validated)
2026-09-14T15:22:32+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed /etc/systemd/system/felhom-agent.service + enabled (started in step 6 after config)
2026-09-14T15:22:32+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed self-update rollback unit + start-limit drop-in (auto-rollback armed)
2026-09-14T15:22:33+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed break-glass layers 1+2 (tmpfiles /run/sshd + agent-independent watchdog timer)
2026-09-14T15:22:33+02:00 drill0242 useradd[2253]: new group: name=felhom-op, GID=1000
2026-09-14T15:22:33+02:00 drill0242 useradd[2253]: new user: name=felhom-op, UID=1000, GID=1000, home=/home/felhom-op, shell=/bin/bash, from=none
2026-09-14T15:22:34+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] installed OOB felhom-sshd instance + static belt (agent renders config + fills sets once oob.enabled)
2026-09-14T15:22:34+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 6/8 agent config + service
2026-09-14T15:22:35+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] backup target: DEGRADED — no eligible second drive, so the whole-system backup stays on the SYSTEM drive.
2026-09-14T15:22:35+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] It protects against file corruption but NOT against a disk failure. Attach a second drive and assign it in the dashboard.
2026-09-14T15:22:35+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] creating island bridge vmbr9 (portless, 169.254.253.1/30)
2026-09-14T15:22:36+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] vmbr9 up: 169.254.253.1/30
2026-09-14T15:22:36+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] R-50 island ON: local_api=169.254.253.1:8443 (vmbr9); guest net1=169.254.253.2/30; lan_resolver.host_ip=192.168.0.134
2026-09-14T15:22:36+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] node=drill0242 local_api=169.254.253.1:8443 tls_fp=85:49:34:7C:7A:25…
2026-09-14T15:22:36+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] wrote /etc/felhom-agent/agent.json (0600 felhom-agent)
2026-09-14T15:22:36+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] agent --selftest (read-only) passed
2026-09-14T15:22:39+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] felhom-agent service active (non-root felhom-agent reads the config OK)
2026-09-14T15:22:39+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 7/8 golden archive
2026-09-14T15:22:39+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
2026-09-14T15:22:40+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] fetching golden v0.242.0 from Gitea → /var/lib/vz/dump/vzdump-lxc-9100-2026_09_14-15_22_40.tar.zst
2026-09-14T15:22:46+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] verified sha256 3ab480ddb7c1e690… matches the hub manifest
2026-09-14T15:22:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] golden imported + verified: local:backup/vzdump-lxc-9100-2026_09_14-15_22_40.tar.zst
2026-09-14T15:22:47+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] 8/8 provision guest 9201
2026-09-14T15:22:48+02:00 drill0242 felhom-bootstrap.sh[1490]: [SKIP] pool felhom already exists
2026-09-14T15:22:48+02:00 drill0242 felhom-bootstrap.sh[3500]: === felhom-agent 0.130.0 selftest=provision (vmid=9201 customer=drill0242 hostname=drill0242) ===
2026-09-14T15:22:48+02:00 drill0242 felhom-bootstrap.sh[3500]: --- front half: bring-up (provision) local:backup/vzdump-lxc-9100-2026_09_14-15_22_40.tar.zst → vmid 9201 ---
2026-09-14T15:23:37+02:00 drill0242 felhom-bootstrap.sh[3500]: time=2026-09-14T15:23:37.121+02:00 level=INFO msg="bring-up: pool membership re-asserted" vmid=9201 pool=felhom
2026-09-14T15:23:37+02:00 drill0242 felhom-bootstrap.sh[3500]: [OK] front half: vmid 9201 up (boot+running) in 49s; MAC=BC:24:11:A2:B8:3A
2026-09-14T15:23:37+02:00 drill0242 felhom-bootstrap.sh[3500]: --- back half: mint per-guest token + populate bootstrap config mount ---
2026-09-14T15:23:37+02:00 drill0242 sudo[4502]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown --reference=/var/lib/felhom-agent /var/lib/felhom-agent/guests /var/lib/felhom-agent/guests/9201
2026-09-14T15:23:37+02:00 drill0242 sudo[4502]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:37+02:00 drill0242 sudo[4502]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:37+02:00 drill0242 sudo[4505]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown -R 100000:100000 /var/lib/felhom-agent/guests/9201/bootstrap
2026-09-14T15:23:37+02:00 drill0242 sudo[4505]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:37+02:00 drill0242 sudo[4505]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:37+02:00 drill0242 sudo[4508]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -mp9 /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1
2026-09-14T15:23:37+02:00 drill0242 sudo[4508]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:38+02:00 drill0242 sudo[4508]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:38+02:00 drill0242 sudo[4554]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -onboot 1
2026-09-14T15:23:38+02:00 drill0242 sudo[4554]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:39+02:00 drill0242 sudo[4554]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:39+02:00 drill0242 sudo[4735]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /var/lib/vz/snippets
2026-09-14T15:23:39+02:00 drill0242 sudo[4735]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:39+02:00 drill0242 sudo[4735]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:39+02:00 drill0242 sudo[4745]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/install -m 0755 -- /tmp/felhom-guest-hook-1720529086.sh /var/lib/vz/snippets/felhom-guest-hook.sh
2026-09-14T15:23:39+02:00 drill0242 sudo[4745]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:39+02:00 drill0242 sudo[4745]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:39+02:00 drill0242 sudo[4760]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 --hookscript local:snippets/felhom-guest-hook.sh
2026-09-14T15:23:39+02:00 drill0242 sudo[4760]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:40+02:00 drill0242 sudo[4760]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:40+02:00 drill0242 sudo[5178]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives
2026-09-14T15:23:40+02:00 drill0242 sudo[5178]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:40+02:00 drill0242 sudo[5178]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:40+02:00 drill0242 sudo[5182]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -mp8 /mnt/felhom-drives,mp=/mnt/felhom-drives
2026-09-14T15:23:40+02:00 drill0242 sudo[5182]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0)
2026-09-14T15:23:41+02:00 drill0242 sudo[5182]: pam_unix(sudo:session): session closed for user root
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: time=2026-09-14T15:23:41.673+02:00 level=INFO msg="provision: back-half complete" vmid=9201 mount=mp9 guest_path=/etc/felhom-bootstrap endpoint=169.254.253.1:8443
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: [OK] back half: bootstrap mount mp9 → /etc/felhom-bootstrap on vmid 9201 (host dir /var/lib/felhom-agent/guests/9201/bootstrap)
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: local-api endpoint 169.254.253.1:8443 · leaf fp 3844ca42ee782c51aa44719a08a66aec7bd0349e05e3329853ce43e449ce89af · token: minted (not printed)
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: === selftest=provision OK — guest 9201 provisioned + bootstrap-mounted (KEPT) ===
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: next: reboot the guest → the golden's baked controller-bootstrap unit deploys the controller,
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[3500]: which PULLS its controller.yaml from the hub (retrieval passphrase) and merges in this local_api.
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] provision completed
2026-09-14T15:23:41+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] rebooting guest 9201 so the baked controller-bootstrap unit picks up the mount
2026-09-14T15:23:42+02:00 drill0242 pct[5297]: <root@pam> starting task UPID:drill0242:000014B5:0000582B:6AA7F55E:vzreboot:9201:root@pam:
2026-09-14T15:23:42+02:00 drill0242 pct[5301]: requesting reboot of CT 9201: UPID:drill0242:000014B5:0000582B:6AA7F55E:vzreboot:9201:root@pam:
2026-09-14T15:23:49+02:00 drill0242 pct[5297]: <root@pam> end task UPID:drill0242:000014B5:0000582B:6AA7F55E:vzreboot:9201:root@pam: OK
2026-09-14T15:23:49+02:00 drill0242 felhom-bootstrap.sh[1490]: [STEP] verify
2026-09-14T15:23:50+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] pct status: running
2026-09-14T15:23:51+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] onboot: 1
2026-09-14T15:23:52+02:00 drill0242 felhom-bootstrap.sh[6106]: mp0: local-lvm:vm-9201-disk-1,mp=/var/lib/felhom,backup=1,size=70G
2026-09-14T15:23:52+02:00 drill0242 felhom-bootstrap.sh[6106]: mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
2026-09-14T15:23:52+02:00 drill0242 felhom-bootstrap.sh[6106]: rootfs: local-lvm:vm-9201-disk-0,size=32G
2026-09-14T15:23:53+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] pool: guest 9201 is a member of felhom
2026-09-14T15:23:55+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentBase@/ present (user+token)
2026-09-14T15:23:56+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/pool/felhom present (user+token)
2026-09-14T15:23:57+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentStore@/storage/local present (user+token)
2026-09-14T15:23:58+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentStore@/storage/local-lvm present (user+token)
2026-09-14T15:23:59+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentStore@/storage/felhom-pbs present (user+token)
2026-09-14T15:24:00+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990000 present (user+token)
2026-09-14T15:24:02+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990001 present (user+token)
2026-09-14T15:24:03+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990002 present (user+token)
2026-09-14T15:24:04+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990003 present (user+token)
2026-09-14T15:24:05+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990004 present (user+token)
2026-09-14T15:24:06+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990005 present (user+token)
2026-09-14T15:24:07+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990006 present (user+token)
2026-09-14T15:24:08+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990007 present (user+token)
2026-09-14T15:24:09+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990008 present (user+token)
2026-09-14T15:24:11+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] acl: FelhomAgentGuest@/vms/990009 present (user+token)
2026-09-14T15:24:11+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] authz signers: 2 (operator-signed self-update armed)
2026-09-14T15:24:11+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] controller: Up 19 seconds (healthy) (after ~0s)
2026-09-14T15:24:12+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] controller image: gitea.dooplex.hu/admin/felhom-controller:0.242.0
2026-09-14T15:24:13+02:00 drill0242 felhom-bootstrap.sh[1490]: [WARN] cloudflared not visible yet
2026-09-14T15:24:13+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] (confirm in the hub UI that host drill0242-3f4b42 reports guest 9201)
2026-09-14T15:24:13+02:00 drill0242 felhom-bootstrap.sh[1490]: [OK] Day-0 provision SUCCESS — vmid=9201 host_id=drill0242-3f4b42 customer=drill0242 golden=local:backup/vzdump-lxc-9100-2026_09_14-15_22_40.tar.zst
2026-09-14T15:24:13+02:00 drill0242 felhom-bootstrap.sh[1490]: [INFO] root@pam was rotated + vaulted at step 4b — retrieve at hub → host page (the old GUI password no longer works).
2026-09-14T15:24:13+02:00 drill0242 felhom-bootstrap.sh[1124]: felhom-bootstrap: host-install SUCCESS — writing done-flag, disabling unit, scrubbing secrets
2026-09-14T15:24:14+02:00 drill0242 systemd[1]: felhom-bootstrap.service: Deactivated successfully.
2026-09-14T15:24:14+02:00 drill0242 systemd[1]: Finished felhom-bootstrap.service - Felhom host bootstrap (fetch + run felhom-host-install.sh unattended, retry until success).
2026-09-14T15:24:14+02:00 drill0242 systemd[1]: felhom-bootstrap.service: Consumed 1min 22.057s CPU time, 904.5M memory peak.
===
total 12
drwxr-xr-x 2 root root 4096 Sep 14 15:24 .
drwxr-xr-x 102 root root 4096 Sep 14 15:22 ..
-rw-r--r-- 1 root root 0 Sep 14 15:24 .bootstrap-done
-rw-r--r-- 1 root root 7 Sep 14 15:20 appliance-pairing-code
@@ -0,0 +1,20 @@
felhom-agent 0.130.0
arch: amd64
cores: 3
features: nesting=1,keyctl=1
hookscript: local:snippets/felhom-guest-hook.sh
hostname: drill0242
memory: 4096
mp0: local-lvm:vm-9201-disk-1,mp=/var/lib/felhom,backup=1,size=70G
mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
mp9: /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1
net0: name=eth0,bridge=vmbr0,hwaddr=BC:24:11:A2:B8:3A,ip=dhcp,type=veth
net1: name=eth1,bridge=vmbr9,hwaddr=BC:24:11:DE:63:F8,ip=169.254.253.2/30,type=veth
onboot: 1
ostype: debian
rootfs: local-lvm:vm-9201-disk-0,size=32G
swap: 512
unprivileged: 1
Name Type Status Total (KiB) Used (KiB) Available (KiB) %
local dir active 61429556 5615824 52660836 9.14%
local-lvm lvmthin active 118673408 5328436 113344971 4.49%
@@ -0,0 +1,526 @@
2026-09-14T13:23:53.189438046Z 2026/09/14 13:23:53 [INFO] local-api: channel up (agent 169.254.253.1:8443) — guest 9201, 3 mount(s) visible
2026-09-14T13:23:53.189477549Z 2026/09/14 13:23:53 [INFO] local-api: mount mp0 → /var/lib/felhom (storage=local-lvm, class=, backup=true)
2026-09-14T13:23:53.189481467Z 2026/09/14 13:23:53 [INFO] local-api: mount mp9 → /etc/felhom-bootstrap (storage=/var/lib/felhom-agent/guests/9201/bootstrap, class=, backup=false)
2026-09-14T13:23:53.189484362Z 2026/09/14 13:23:53 [INFO] local-api: mount mp8 → /mnt/felhom-drives (storage=/mnt/felhom-drives, class=, backup=false)
2026-09-14T13:23:53.189487007Z 2026/09/14 13:23:53 [INFO] felhom-controller 0.242.0 starting (customer: drill0242, domain: drill0242.felhom.eu)
2026-09-14T13:23:53.189959944Z 2026/09/14 13:23:53 [INFO] [settings] Loaded settings from /opt/docker/felhom-controller/data/settings.json
2026-09-14T13:23:53.190304750Z 2026/09/14 13:23:53 [INFO] Encryption key loaded from /opt/docker/felhom-controller/data/encryption.key
2026-09-14T13:23:53.324847060Z 2026/09/14 13:23:53 [INFO] [stacks] Using compose command: docker compose
2026-09-14T13:23:53.367288617Z 2026/09/14 13:23:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:23:53.386952624Z 2026/09/14 13:23:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:23:53.386991347Z 2026/09/14 13:23:53 [INFO] [stacks] Encryption migration: no stacks needed migration
2026-09-14T13:23:53.387143351Z 2026/09/14 13:23:53 [INFO] [quiesce] loop started (poll 5m0s, max-quiesce 30m0s)
2026-09-14T13:23:53.389515004Z 2026/09/14 13:23:53 [INFO] [stacks] desired-state backfill: 0 app(s) recorded as running, 0 left unrecorded (state ambiguous — legacy boot behaviour retained)
2026-09-14T13:23:53.389549459Z 2026/09/14 13:23:53 [INFO] [stacks] installed-images backfill: 0 app(s) recorded, 0 already had a record, 0 left unrecorded (could not be observed completely — unknown, which renders nothing)
2026-09-14T13:23:53.389552775Z 2026/09/14 13:23:53 [INFO] [stacks] pin adoption: 0 pinned, 0 already pinned, 0 left unpinned (0 not completely observed, 0 running something the template no longer offers)
2026-09-14T13:23:53.389555931Z 2026/09/14 13:23:53 [INFO] [sync] Starting catalog sync (repo: https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git, interval: 15m0s)
2026-09-14T13:23:53.389558746Z 2026/09/14 13:23:53 [INFO] [sync] Starting catalog sync
2026-09-14T13:23:53.389560991Z 2026/09/14 13:23:53 [INFO] [sync] Pulling latest from https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git (branch: main)
2026-09-14T13:23:53.389570177Z 2026/09/14 13:23:53 [INFO] Metrics store opened at /opt/docker/felhom-controller/data/metrics.db
2026-09-14T13:23:53.389573092Z 2026/09/14 13:23:53 [INFO] Metrics collector started (60s interval)
2026-09-14T13:23:53.389575346Z 2026/09/14 13:23:53 [INFO] Notifier enabled (hub: https://hub.felhom.eu)
2026-09-14T13:23:53.389638825Z 2026/09/14 13:23:53 [INFO] Self-update enabled (check every 6h, auto-update: false, auto-update time: 04:30)
2026-09-14T13:23:53.391677304Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: status-refresh (every 10s)
2026-09-14T13:23:53.391721357Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: stack-scan (every 2m0s)
2026-09-14T13:23:53.391724483Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: health-probes (every 10s)
2026-09-14T13:23:53.391726947Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: system-health (every 5m0s)
2026-09-14T13:23:53.391729292Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: deadapp-check (every 30s)
2026-09-14T13:23:53.391731576Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: ring-spill (every 30s)
2026-09-14T13:23:53.394117817Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job db-dump scheduled for 2026-09-15 02:30 CEST
2026-09-14T13:23:53.394206302Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: offsite-credential-retry (every 5m0s)
2026-09-14T13:23:53.394210099Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: backup-cache (every 5m0s)
2026-09-14T13:23:53.394212303Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-09-15 03:30 CEST
2026-09-14T13:23:53.394214437Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-09-15 04:15 CEST
2026-09-14T13:23:53.394216611Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-09-15 05:10 CEST
2026-09-14T13:23:53.394257558Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-09-15 06:00 CEST
2026-09-14T13:23:53.394262027Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-09-15 05:30 CEST
2026-09-14T13:23:53.394264250Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-09-15 04:00 CEST
2026-09-14T13:23:53.394266504Z 2026/09/14 13:23:53 [INFO] [scheduler] Daily job fill-watch scheduled for 2026-09-15 03:30 CEST
2026-09-14T13:23:53.394268639Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: hub-report (every 15m0s)
2026-09-14T13:23:53.394270763Z 2026/09/14 13:23:53 [INFO] Hub reporting enabled (every 15m0s to https://hub.felhom.eu)
2026-09-14T13:23:53.394272847Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: selfupdate-check (every 6h0m0s)
2026-09-14T13:23:53.394275071Z 2026/09/14 13:23:53 [INFO] ========== Startup Self-Test ==========
2026-09-14T13:23:53.454601041Z 2026/09/14 13:23:53 [INFO] [PASS] Docker socket: reachable (v29.8.0)
2026-09-14T13:23:53.454651165Z 2026/09/14 13:23:53 [INFO] [PASS] Stacks directory: /opt/docker/stacks
2026-09-14T13:23:53.454853042Z 2026/09/14 13:23:53 [INFO] [PASS] Data directory: /opt/docker/felhom-controller/data (writable)
2026-09-14T13:23:53.454956617Z 2026/09/14 13:23:53 [INFO] [PASS] System data path: /mnt/sys_drive
2026-09-14T13:23:53.454965053Z 2026/09/14 13:23:53 [INFO] [WARN] Storage paths: no storage paths registered
2026-09-14T13:23:53.457198196Z 2026/09/14 13:23:53 [INFO] [PASS] Git catalog: 53 app definitions found
2026-09-14T13:23:53.585572573Z 2026/09/14 13:23:53 [INFO] [infra] connected felhom-controller to traefik-public
2026-09-14T13:23:53.585614271Z 2026/09/14 13:23:53 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:23:53.594968804Z 2026/09/14 13:23:53 [INFO] [PASS] Hub connectivity: https://hub.felhom.eu reachable (HTTP 200)
2026-09-14T13:23:53.594996246Z 2026/09/14 13:23:53 [INFO] [PASS] Metrics DB: 0.0 MB
2026-09-14T13:23:53.595036601Z 2026/09/14 13:23:53 [INFO] ========================================
2026-09-14T13:23:53.595039196Z 2026/09/14 13:23:53 [INFO] Self-test complete: 7 passed, 1 warnings, 0 failed
2026-09-14T13:23:53.595044136Z 2026/09/14 13:23:53 [INFO] [scheduler] Starting scheduler with 18 jobs
2026-09-14T13:23:53.598679456Z 2026/09/14 13:23:53 [INFO] [report] hub wait channel active (hold ≤240s)
2026-09-14T13:23:53.602471350Z 2026/09/14 13:23:53 [INFO] [backup] Found 0 DB dump files across drives
2026-09-14T13:23:53.613152569Z 2026/09/14 13:23:53 [INFO] [web] Auth: no password configured — dashboard is open
2026-09-14T13:23:53.613254760Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: disk-health-check (every 1h0m0s)
2026-09-14T13:23:53.613259359Z 2026/09/14 13:23:53 [INFO] [scheduler] Registered periodic job: agent-channel-health (every 1m0s)
2026-09-14T13:23:53.618155260Z 2026/09/14 13:23:53 [INFO] Web UI listening on :8080
2026-09-14T13:23:53.647110192Z 2026/09/14 13:23:53 [INFO] [backup] Discovered 0 databases
2026-09-14T13:23:53.647282194Z 2026/09/14 13:23:53 [INFO] [backup] Discovered app data: 0 apps
2026-09-14T13:23:53.647444930Z 2026/09/14 13:23:53 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:23:53.827322578Z 2026/09/14 13:23:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:23:53.834843957Z 2026/09/14 13:23:53 [INFO] [settings] Settings saved
2026-09-14T13:23:53.874474428Z 2026/09/14 13:23:53 [INFO] [sync] Catalog sync complete
2026-09-14T13:23:53.874507179Z 2026/09/14 13:23:53 [INFO] [sync] Initial sync: Sablonok naprakészek — nincs változás
2026-09-14T13:23:54.384473470Z 2026/09/14 13:23:54 [INFO] [web] FileBrowser mounts synced (recreated) — 0 storage path(s), config updated
2026-09-14T13:23:58.411507445Z 2026/09/14 13:23:58 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:23:58.595990882Z 2026/09/14 13:23:58 [INFO] [report] Building system report
2026-09-14T13:23:58.647280714Z 2026/09/14 13:23:58 [INFO] Event pushed: controller_started (info) — Controller elindult (0.242.0)
2026-09-14T13:23:58.826486063Z 2026/09/14 13:23:58 [INFO] [monitor] Health check: status=ok
2026-09-14T13:23:58.915140281Z 2026/09/14 13:23:58 [INFO] [report] Hub report pushed successfully (2282 bytes)
2026-09-14T13:23:58.915713464Z 2026/09/14 13:23:58 [INFO] [settings] Settings saved
2026-09-14T13:23:58.916314411Z 2026/09/14 13:23:58 [INFO] [settings] Settings saved
2026-09-14T13:23:58.916331252Z 2026/09/14 13:23:58 [INFO] config-refresh: baseline config_version=1 recorded (no restart)
2026-09-14T13:23:58.916722064Z 2026/09/14 13:23:58 [INFO] [settings] Settings saved
2026-09-14T13:23:58.916764263Z 2026/09/14 13:23:58 [INFO] [claim-sync] hub claim code cached (generation 1) — hash first 8: $2a$10$t…
2026-09-14T13:23:58.916769152Z 2026/09/14 13:23:58 [INFO] Startup hub report sent
2026-09-14T13:24:03.436653895Z 2026/09/14 13:24:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:03.620788629Z 2026/09/14 13:24:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:08.460658836Z 2026/09/14 13:24:08 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:08.461180072Z 2026/09/14 13:24:08 [INFO] [bootrecon] boot window: fleet settled after 10s (3 identical samples 5s apart) — sweeping
2026-09-14T13:24:08.461193086Z 2026/09/14 13:24:08 [INFO] [bootrecon] Boot reconciliation: no boot-orphaned apps (nothing to start)
2026-09-14T13:24:13.619638388Z 2026/09/14 13:24:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:23.622944975Z 2026/09/14 13:24:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:23.965970821Z 2026/09/14 13:24:23 [INFO] [selfupdate] Current version 0.242.0 is up to date
2026-09-14T13:24:33.618718613Z 2026/09/14 13:24:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:43.615054062Z 2026/09/14 13:24:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:53.617666643Z 2026/09/14 13:24:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:24:53.618675707Z 2026/09/14 13:24:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:24:53.798794835Z 2026/09/14 13:24:53 [INFO] [scheduler] Job agent-channel-health completed (took 180ms)
2026-09-14T13:25:03.618895165Z 2026/09/14 13:25:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:13.618452762Z 2026/09/14 13:25:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:23.394739694Z 2026/09/14 13:25:23 [INFO] [fillwatch] checked 2 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok
2026-09-14T13:25:23.617322303Z 2026/09/14 13:25:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:33.617203471Z 2026/09/14 13:25:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:43.617379908Z 2026/09/14 13:25:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:53.596220677Z 2026/09/14 13:25:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:25:53.617302152Z 2026/09/14 13:25:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:53.619595635Z 2026/09/14 13:25:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:25:53.635652244Z 2026/09/14 13:25:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:25:53.661204296Z 2026/09/14 13:25:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:25:53.661257976Z 2026/09/14 13:25:53 [INFO] [scheduler] Job stack-scan completed (took 65ms)
2026-09-14T13:25:53.832564211Z 2026/09/14 13:25:53 [INFO] [scheduler] Job agent-channel-health completed (took 213ms)
2026-09-14T13:26:03.617483353Z 2026/09/14 13:26:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:13.617399857Z 2026/09/14 13:26:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:23.618799624Z 2026/09/14 13:26:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:33.617589474Z 2026/09/14 13:26:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:43.615756752Z 2026/09/14 13:26:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:53.619028158Z 2026/09/14 13:26:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:26:53.621539532Z 2026/09/14 13:26:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:26:53.806181671Z 2026/09/14 13:26:53 [INFO] [scheduler] Job agent-channel-health completed (took 187ms)
2026-09-14T13:27:03.616808614Z 2026/09/14 13:27:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:13.617078281Z 2026/09/14 13:27:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:23.625020172Z 2026/09/14 13:27:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:33.615328603Z 2026/09/14 13:27:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:43.619542486Z 2026/09/14 13:27:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:53.596696378Z 2026/09/14 13:27:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:27:53.617636479Z 2026/09/14 13:27:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:53.618541388Z 2026/09/14 13:27:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:27:53.633489672Z 2026/09/14 13:27:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:27:53.653654259Z 2026/09/14 13:27:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:27:53.653687803Z 2026/09/14 13:27:53 [INFO] [scheduler] Job stack-scan completed (took 58ms)
2026-09-14T13:27:53.819388098Z 2026/09/14 13:27:53 [INFO] [scheduler] Job agent-channel-health completed (took 201ms)
2026-09-14T13:28:03.619017049Z 2026/09/14 13:28:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:13.615747132Z 2026/09/14 13:28:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:23.616923458Z 2026/09/14 13:28:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:33.617390233Z 2026/09/14 13:28:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:43.619549357Z 2026/09/14 13:28:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:53.595873865Z 2026/09/14 13:28:53 [INFO] [scheduler] Running job: backup-cache
2026-09-14T13:28:53.595903100Z 2026/09/14 13:28:53 [INFO] [scheduler] Running job: system-health
2026-09-14T13:28:53.595906316Z 2026/09/14 13:28:53 [INFO] [backup] Found 0 DB dump files across drives
2026-09-14T13:28:53.600907183Z 2026/09/14 13:28:53 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T13:28:53.600964091Z 2026/09/14 13:28:53 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T13:28:53.618436240Z 2026/09/14 13:28:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:28:53.621721938Z 2026/09/14 13:28:53 [INFO] [backup] Discovered 0 databases
2026-09-14T13:28:53.631110926Z 2026/09/14 13:28:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:28:53.631192892Z 2026/09/14 13:28:53 [INFO] [backup] Discovered app data: 0 apps
2026-09-14T13:28:53.631232425Z 2026/09/14 13:28:53 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:28:53.631257544Z 2026/09/14 13:28:53 [INFO] [scheduler] Job backup-cache completed (took 36ms)
2026-09-14T13:28:53.782516020Z 2026/09/14 13:28:53 [INFO] [quiesce] backup due on 1 tier(s) — quiescing 0 stack(s): []
2026-09-14T13:28:53.784133055Z 2026/09/14 13:28:53 [INFO] [quiesce] tier local: backup job backup-9201-1789392533783189813 started — polling
2026-09-14T13:28:53.800563206Z 2026/09/14 13:28:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:28:53.800593002Z 2026/09/14 13:28:53 [INFO] [scheduler] Job system-health completed (took 205ms)
2026-09-14T13:28:53.806140423Z 2026/09/14 13:28:53 [INFO] [scheduler] Job agent-channel-health completed (took 187ms)
2026-09-14T13:28:53.860650226Z 2026/09/14 13:28:53 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:29:03.631038238Z 2026/09/14 13:29:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:03.786853895Z 2026/09/14 13:29:03 [INFO] [quiesce] tier local: job backup-9201-1789392533783189813 snapshotted — resuming app early (8B.2)
2026-09-14T13:29:03.786880194Z 2026/09/14 13:29:03 [INFO] [quiesce] unquiescing (snapshotted (early resume, last tier)): restarting 0 stack(s)
2026-09-14T13:29:13.637151256Z 2026/09/14 13:29:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:23.619519483Z 2026/09/14 13:29:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:33.616573727Z 2026/09/14 13:29:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:33.791741576Z 2026/09/14 13:29:33 [INFO] [quiesce] tier local: backup job backup-9201-1789392533783189813 done
2026-09-14T13:29:43.621940797Z 2026/09/14 13:29:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:53.596091441Z 2026/09/14 13:29:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:29:53.613634424Z 2026/09/14 13:29:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:29:53.619336997Z 2026/09/14 13:29:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:29:53.635365740Z 2026/09/14 13:29:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:53.635399865Z 2026/09/14 13:29:53 [INFO] [scheduler] Job stack-scan completed (took 39ms)
2026-09-14T13:29:53.658133785Z 2026/09/14 13:29:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:29:53.824586397Z 2026/09/14 13:29:53 [INFO] [scheduler] Job agent-channel-health completed (took 206ms)
2026-09-14T13:30:03.618316557Z 2026/09/14 13:30:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:13.617986421Z 2026/09/14 13:30:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:23.617233003Z 2026/09/14 13:30:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:33.616235146Z 2026/09/14 13:30:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:43.617884673Z 2026/09/14 13:30:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:53.615272336Z 2026/09/14 13:30:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:30:53.618286669Z 2026/09/14 13:30:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:30:53.804995075Z 2026/09/14 13:30:53 [INFO] [scheduler] Job agent-channel-health completed (took 187ms)
2026-09-14T13:31:03.617332092Z 2026/09/14 13:31:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:13.620040193Z 2026/09/14 13:31:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:20.718001754Z 2026/09/14 13:31:20 [INFO] [settings] Settings saved
2026-09-14T13:31:20.718685275Z 2026/09/14 13:31:20 [INFO] [settings] Settings saved
2026-09-14T13:31:20.719133030Z 2026/09/14 13:31:20 [INFO] [settings] Settings saved
2026-09-14T13:31:20.719155273Z 2026/09/14 13:31:20 [INFO] [web] All sessions invalidated (cleared 0)
2026-09-14T13:31:20.719160222Z 2026/09/14 13:31:20 [INFO] [web] dashboard claimed by the customer from 192.168.0.104 (code generation 3 consumed)
2026-09-14T13:31:22.720614503Z 2026/09/14 13:31:22 [INFO] [report] Building system report
2026-09-14T13:31:22.931244682Z 2026/09/14 13:31:22 [INFO] [monitor] Health check: status=ok
2026-09-14T13:31:23.364000531Z 2026/09/14 13:31:23 [INFO] [report] Hub report pushed successfully (2306 bytes)
2026-09-14T13:31:23.364730821Z 2026/09/14 13:31:23 [INFO] [settings] Settings saved
2026-09-14T13:31:23.619152533Z 2026/09/14 13:31:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:33.617082159Z 2026/09/14 13:31:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:43.617044173Z 2026/09/14 13:31:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:53.596105875Z 2026/09/14 13:31:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:31:53.612927153Z 2026/09/14 13:31:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:31:53.618522050Z 2026/09/14 13:31:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:31:53.636310864Z 2026/09/14 13:31:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:53.636357373Z 2026/09/14 13:31:53 [INFO] [scheduler] Job stack-scan completed (took 40ms)
2026-09-14T13:31:53.658020955Z 2026/09/14 13:31:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:31:53.805017458Z 2026/09/14 13:31:53 [INFO] [scheduler] Job agent-channel-health completed (took 187ms)
2026-09-14T13:32:03.617533318Z 2026/09/14 13:32:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:13.615798100Z 2026/09/14 13:32:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:23.620779603Z 2026/09/14 13:32:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:33.620110546Z 2026/09/14 13:32:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:43.620433242Z 2026/09/14 13:32:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:53.618797151Z 2026/09/14 13:32:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:32:53.618840393Z 2026/09/14 13:32:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:32:53.791892395Z 2026/09/14 13:32:53 [INFO] [scheduler] Job agent-channel-health completed (took 173ms)
2026-09-14T13:33:03.617727550Z 2026/09/14 13:33:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:13.619929756Z 2026/09/14 13:33:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:23.622738874Z 2026/09/14 13:33:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:33.618479312Z 2026/09/14 13:33:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:43.620215406Z 2026/09/14 13:33:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:53.596527849Z 2026/09/14 13:33:53 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T13:33:53.596605424Z 2026/09/14 13:33:53 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T13:33:53.596613829Z 2026/09/14 13:33:53 [INFO] [scheduler] Running job: system-health
2026-09-14T13:33:53.596618789Z 2026/09/14 13:33:53 [INFO] [scheduler] Running job: backup-cache
2026-09-14T13:33:53.596623227Z 2026/09/14 13:33:53 [INFO] [backup] Found 0 DB dump files across drives
2026-09-14T13:33:53.597785135Z 2026/09/14 13:33:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:33:53.619080785Z 2026/09/14 13:33:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:33:53.634678743Z 2026/09/14 13:33:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:53.634926200Z 2026/09/14 13:33:53 [INFO] [backup] Discovered 0 databases
2026-09-14T13:33:53.659752936Z 2026/09/14 13:33:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (0 deployed, 55 available)
2026-09-14T13:33:53.692804694Z 2026/09/14 13:33:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:33:53.692989712Z 2026/09/14 13:33:53 [INFO] [scheduler] Job stack-scan completed (took 95ms)
2026-09-14T13:33:53.693221519Z 2026/09/14 13:33:53 [INFO] [backup] Discovered app data: 0 apps
2026-09-14T13:33:53.694065627Z 2026/09/14 13:33:53 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:33:53.694083390Z 2026/09/14 13:33:53 [INFO] [scheduler] Job backup-cache completed (took 98ms)
2026-09-14T13:33:53.808369252Z 2026/09/14 13:33:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:33:53.808576412Z 2026/09/14 13:33:53 [INFO] [scheduler] Job system-health completed (took 213ms)
2026-09-14T13:33:53.835495026Z 2026/09/14 13:33:53 [INFO] [scheduler] Job agent-channel-health completed (took 216ms)
2026-09-14T13:33:53.862493912Z 2026/09/14 13:33:53 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:34:03.619683617Z 2026/09/14 13:34:03 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:13.619988019Z 2026/09/14 13:34:13 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:23.620364296Z 2026/09/14 13:34:23 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:33.619114014Z 2026/09/14 13:34:33 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:38.685928189Z 2026/09/14 13:34:38 [INFO] [api] Deploy requested for stack: bookstack
2026-09-14T13:34:38.815278378Z 2026/09/14 13:34:38 [INFO] [stacks] Memory check: total=4096MB, reserved=384MB, usable=3712MB, committed_used=0MB, new_req=150MB, remaining=3562MB
2026-09-14T13:34:38.815310388Z 2026/09/14 13:34:38 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 2 encrypted, 2 sensitive fields
2026-09-14T13:34:38.816159190Z 2026/09/14 13:34:38 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:34:38.816162456Z 2026/09/14 13:34:38 [INFO] [stacks] Deploying stack bookstack with 4 env vars: [DOMAIN, SUBDOMAIN, APP_KEY, DB_PASSWORD]
2026-09-14T13:34:38.886807846Z 2026/09/14 13:34:38 [INFO] Event pushed: app_deployed (info) — Alkalmazás telepítve: BookStack
2026-09-14T13:34:40.818422351Z 2026/09/14 13:34:40 [INFO] [report] Building system report
2026-09-14T13:34:41.088679487Z 2026/09/14 13:34:41 [INFO] [monitor] Health check: status=ok
2026-09-14T13:34:41.140582225Z 2026/09/14 13:34:41 [INFO] [report] Hub report pushed successfully (2372 bytes)
2026-09-14T13:34:41.141082378Z 2026/09/14 13:34:41 [INFO] [settings] Settings saved
2026-09-14T13:34:43.637900864Z 2026/09/14 13:34:43 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:53.595953811Z 2026/09/14 13:34:53 [INFO] [deadapp] check alive: 20 scans since boot, 0 deployed app(s) evaluated, 0 currently down
2026-09-14T13:34:53.618477354Z 2026/09/14 13:34:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:34:53.691911234Z 2026/09/14 13:34:53 [INFO] [stacks] Status refresh: 2 containers across 55 stacks
2026-09-14T13:34:53.807104049Z 2026/09/14 13:34:53 [INFO] [scheduler] Job agent-channel-health completed (took 189ms)
2026-09-14T13:35:03.623820838Z 2026/09/14 13:35:03 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:13.620335299Z 2026/09/14 13:35:13 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:16.972971683Z 2026/09/14 13:35:16 [INFO] [stacks] Stack bookstack deployed successfully (took 38.2s)
2026-09-14T13:35:16.973242835Z 2026/09/14 13:35:16 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 2 encrypted, 2 sensitive fields
2026-09-14T13:35:16.973773044Z 2026/09/14 13:35:16 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:35:17.146242278Z 2026/09/14 13:35:17 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 0 encrypted, 2 sensitive fields
2026-09-14T13:35:17.146707015Z 2026/09/14 13:35:17 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:35:17.146881605Z 2026/09/14 13:35:17 [INFO] [stacks] installed-images bookstack: recorded 2 service(s) (bookstack=lscr.io/linuxserver/bookstack:26.05.2 (sha256:3db259db5828…), bookstack-db=mariadb:12.3 (sha256:ab1c3dd38194…))
2026-09-14T13:35:17.149186792Z 2026/09/14 13:35:17 [INFO] [stacks] pin bookstack: bookstack=lscr.io/linuxserver/bookstack:26.05.2, bookstack-db=mariadb:12.3
2026-09-14T13:35:17.149234162Z 2026/09/14 13:35:17 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 0 encrypted, 2 sensitive fields
2026-09-14T13:35:17.149239162Z 2026/09/14 13:35:17 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:35:17.177313652Z 2026/09/14 13:35:17 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:20.250277538Z 2026/09/14 13:35:20 [INFO] [stacks] Stack bookstack post-start status:
2026-09-14T13:35:20.250316552Z 2026/09/14 13:35:20 [INFO] [stacks] bookstack lscr.io/linuxserver/bookstack:26.05.2 running Up 3 seconds (health: starting)
2026-09-14T13:35:20.250322162Z 2026/09/14 13:35:20 [INFO] [stacks] bookstack-db mariadb:12.3 running Up 19 seconds (healthy)
2026-09-14T13:35:23.619217244Z 2026/09/14 13:35:23 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:33.619474014Z 2026/09/14 13:35:33 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:43.618243979Z 2026/09/14 13:35:43 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:35:47.266060715Z 2026/09/14 13:35:47 [INFO] [api] Deploy requested for stack: privatebin
2026-09-14T13:35:47.367395762Z 2026/09/14 13:35:47 [INFO] [stacks] Memory check: total=4096MB, reserved=384MB, usable=3712MB, committed_used=150MB, new_req=30MB, remaining=3532MB
2026-09-14T13:35:47.367762745Z 2026/09/14 13:35:47 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/privatebin — 2 env vars, 0 encrypted, 0 sensitive fields
2026-09-14T13:35:47.367960688Z 2026/09/14 13:35:47 [INFO] [stacks] Deploying stack privatebin with 2 env vars: [DOMAIN, SUBDOMAIN]
2026-09-14T13:35:47.367973953Z 2026/09/14 13:35:47 [INFO] [stacks] SaveAppConfig: saved config for privatebin
2026-09-14T13:35:47.378637685Z 2026/09/14 13:35:47 [INFO] Event pushed: app_deployed (info) — Alkalmazás telepítve: PrivateBin
2026-09-14T13:35:49.369335100Z 2026/09/14 13:35:49 [INFO] [report] Building system report
2026-09-14T13:35:49.608402855Z 2026/09/14 13:35:49 [INFO] [monitor] Health check: status=ok
2026-09-14T13:35:50.085241480Z 2026/09/14 13:35:50 [INFO] [report] Hub report pushed successfully (4629 bytes)
2026-09-14T13:35:50.085258063Z 2026/09/14 13:35:50 [INFO] [settings] Settings saved
2026-09-14T13:35:51.347010483Z 2026/09/14 13:35:51 [INFO] [stacks] Stack privatebin deployed successfully (took 4.0s)
2026-09-14T13:35:51.347262608Z 2026/09/14 13:35:51 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/privatebin — 2 env vars, 0 encrypted, 0 sensitive fields
2026-09-14T13:35:51.347638156Z 2026/09/14 13:35:51 [INFO] [stacks] SaveAppConfig: saved config for privatebin
2026-09-14T13:35:51.477830633Z 2026/09/14 13:35:51 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/privatebin — 2 env vars, 0 encrypted, 0 sensitive fields
2026-09-14T13:35:51.478317972Z 2026/09/14 13:35:51 [INFO] [stacks] installed-images privatebin: recorded 1 service(s) (privatebin=privatebin/pdo:2.0.5 (sha256:8a2cac16eff6…))
2026-09-14T13:35:51.478339833Z 2026/09/14 13:35:51 [INFO] [stacks] SaveAppConfig: saved config for privatebin
2026-09-14T13:35:51.478737923Z 2026/09/14 13:35:51 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/privatebin — 2 env vars, 0 encrypted, 0 sensitive fields
2026-09-14T13:35:51.479072916Z 2026/09/14 13:35:51 [INFO] [stacks] SaveAppConfig: saved config for privatebin
2026-09-14T13:35:51.479108743Z 2026/09/14 13:35:51 [INFO] [stacks] pin privatebin: privatebin=privatebin/pdo:2.0.5
2026-09-14T13:35:51.499621111Z 2026/09/14 13:35:51 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:35:53.596155785Z 2026/09/14 13:35:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:35:53.618442390Z 2026/09/14 13:35:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:35:53.622495164Z 2026/09/14 13:35:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:35:53.644947120Z 2026/09/14 13:35:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (2 deployed, 53 available)
2026-09-14T13:35:53.674129832Z 2026/09/14 13:35:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:35:53.674160159Z 2026/09/14 13:35:53 [INFO] [scheduler] Job stack-scan completed (took 77ms)
2026-09-14T13:35:53.678405275Z 2026/09/14 13:35:53 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:35:53.808803791Z 2026/09/14 13:35:53 [INFO] [scheduler] Job agent-channel-health completed (took 190ms)
2026-09-14T13:35:54.596800651Z 2026/09/14 13:35:54 [INFO] [stacks] Stack privatebin post-start status:
2026-09-14T13:35:54.596840716Z 2026/09/14 13:35:54 [INFO] [stacks] privatebin privatebin/pdo:2.0.5 running Up 3 seconds (health: starting)
2026-09-14T13:36:03.620051589Z 2026/09/14 13:36:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:13.634810800Z 2026/09/14 13:36:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:13.634844944Z 2026/09/14 13:36:13 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:36:23.620812050Z 2026/09/14 13:36:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:33.621793044Z 2026/09/14 13:36:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:43.620315736Z 2026/09/14 13:36:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:53.618565014Z 2026/09/14 13:36:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:36:53.618604008Z 2026/09/14 13:36:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:36:53.796866895Z 2026/09/14 13:36:53 [INFO] [scheduler] Job agent-channel-health completed (took 178ms)
2026-09-14T13:37:03.623612262Z 2026/09/14 13:37:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:13.621383613Z 2026/09/14 13:37:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:23.617783617Z 2026/09/14 13:37:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:33.624423734Z 2026/09/14 13:37:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:43.620473427Z 2026/09/14 13:37:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:53.596130941Z 2026/09/14 13:37:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:37:53.618320804Z 2026/09/14 13:37:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:37:53.620205242Z 2026/09/14 13:37:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:53.642611885Z 2026/09/14 13:37:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (2 deployed, 53 available)
2026-09-14T13:37:53.665877298Z 2026/09/14 13:37:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:37:53.665912014Z 2026/09/14 13:37:53 [INFO] [scheduler] Job stack-scan completed (took 70ms)
2026-09-14T13:37:53.795906985Z 2026/09/14 13:37:53 [INFO] [scheduler] Job agent-channel-health completed (took 177ms)
2026-09-14T13:38:03.619683921Z 2026/09/14 13:38:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:13.622042937Z 2026/09/14 13:38:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:23.625053077Z 2026/09/14 13:38:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:33.620557152Z 2026/09/14 13:38:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:43.622389071Z 2026/09/14 13:38:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:53.392262159Z 2026/09/14 13:38:53 [INFO] [sync] Starting catalog sync
2026-09-14T13:38:53.392304909Z 2026/09/14 13:38:53 [INFO] [sync] Pulling latest from https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git (branch: main)
2026-09-14T13:38:53.549563004Z 2026/09/14 13:38:53 [INFO] [sync] Catalog sync complete
2026-09-14T13:38:53.549592090Z 2026/09/14 13:38:53 [INFO] [sync] Periodic sync: Sablonok naprakészek — nincs változás
2026-09-14T13:38:53.598090707Z 2026/09/14 13:38:53 [INFO] [scheduler] Running job: backup-cache
2026-09-14T13:38:53.598165919Z 2026/09/14 13:38:53 [INFO] [scheduler] Running job: hub-report
2026-09-14T13:38:53.598172602Z 2026/09/14 13:38:53 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T13:38:53.598176329Z 2026/09/14 13:38:53 [INFO] [report] Building system report
2026-09-14T13:38:53.598179865Z 2026/09/14 13:38:53 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T13:38:53.598182931Z 2026/09/14 13:38:53 [INFO] [scheduler] Running job: system-health
2026-09-14T13:38:53.598185827Z 2026/09/14 13:38:53 [INFO] [backup] Found 0 DB dump files across drives
2026-09-14T13:38:53.618527384Z 2026/09/14 13:38:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:38:53.658936913Z 2026/09/14 13:38:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:38:53.684224245Z 2026/09/14 13:38:53 [INFO] [backup] Discovered 1 databases
2026-09-14T13:38:53.685542073Z 2026/09/14 13:38:53 [INFO] [backup] Discovered app data: 2 apps
2026-09-14T13:38:53.688496219Z 2026/09/14 13:38:53 [INFO] [backup] Recovery unit captured for bookstack → /mnt/sys_drive/felhom-data/backups/primary/bookstack (images=2, secrets-referenced=2, data_keys=0, portable-carried=2/2, withheld=0)
2026-09-14T13:38:53.692475491Z 2026/09/14 13:38:53 [INFO] [backup] Recovery unit captured for privatebin → /mnt/sys_drive/felhom-data/backups/primary/privatebin (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
2026-09-14T13:38:53.692521688Z 2026/09/14 13:38:53 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:38:53.692524944Z 2026/09/14 13:38:53 [INFO] [scheduler] Job backup-cache completed (took 97ms)
2026-09-14T13:38:53.796708754Z 2026/09/14 13:38:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:38:53.796858306Z 2026/09/14 13:38:53 [INFO] [scheduler] Job system-health completed (took 201ms)
2026-09-14T13:38:53.822539954Z 2026/09/14 13:38:53 [INFO] [scheduler] Job agent-channel-health completed (took 204ms)
2026-09-14T13:38:53.857315918Z 2026/09/14 13:38:53 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:38:53.877226633Z 2026/09/14 13:38:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:38:54.039590074Z 2026/09/14 13:38:54 [INFO] [report] Hub report pushed successfully (5039 bytes)
2026-09-14T13:38:54.040304764Z 2026/09/14 13:38:54 [INFO] [settings] Settings saved
2026-09-14T13:38:54.040339390Z 2026/09/14 13:38:54 [INFO] [scheduler] Job hub-report completed (took 445ms)
2026-09-14T13:39:03.621848584Z 2026/09/14 13:39:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:13.621013578Z 2026/09/14 13:39:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:23.622592278Z 2026/09/14 13:39:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:33.619375336Z 2026/09/14 13:39:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:43.616229067Z 2026/09/14 13:39:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:53.596228235Z 2026/09/14 13:39:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:39:53.612757406Z 2026/09/14 13:39:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (2 deployed, 53 available)
2026-09-14T13:39:53.619126549Z 2026/09/14 13:39:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:39:53.636369607Z 2026/09/14 13:39:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:53.636399604Z 2026/09/14 13:39:53 [INFO] [scheduler] Job stack-scan completed (took 40ms)
2026-09-14T13:39:53.658951243Z 2026/09/14 13:39:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:39:53.807063304Z 2026/09/14 13:39:53 [INFO] [scheduler] Job agent-channel-health completed (took 188ms)
2026-09-14T13:40:03.620032712Z 2026/09/14 13:40:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:13.629380658Z 2026/09/14 13:40:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:23.627590731Z 2026/09/14 13:40:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:33.621430673Z 2026/09/14 13:40:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:43.622136394Z 2026/09/14 13:40:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:53.618106519Z 2026/09/14 13:40:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:40:53.618381599Z 2026/09/14 13:40:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:40:53.822053610Z 2026/09/14 13:40:53 [INFO] [scheduler] Job agent-channel-health completed (took 204ms)
2026-09-14T13:41:03.629821126Z 2026/09/14 13:41:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:03.639540407Z 2026/09/14 13:41:03 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:41:13.618690655Z 2026/09/14 13:41:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:21.573190912Z 2026/09/14 13:41:21 [INFO] [api] Manual app-data backup (DB dump) triggered
2026-09-14T13:41:21.573510887Z 2026/09/14 13:41:21 [INFO] [backup] Starting database dump run
2026-09-14T13:41:21.621228007Z 2026/09/14 13:41:21 [INFO] [backup] Discovered 1 databases
2026-09-14T13:41:21.621260238Z 2026/09/14 13:41:21 [INFO] [backup] Discovered 1 database(s): bookstack-db(mariadb)
2026-09-14T13:41:21.897309518Z 2026/09/14 13:41:21 [INFO] [backup] DB dump: bookstack-db → bookstack-mariadb.sql (59.0 KB, 274ms, 41 tables)
2026-09-14T13:41:21.897776050Z 2026/09/14 13:41:21 [INFO] [settings] Settings saved
2026-09-14T13:41:21.903154626Z 2026/09/14 13:41:21 [INFO] [backup] Stopping bookstack for safe volume dump
2026-09-14T13:41:21.903173793Z 2026/09/14 13:41:21 [INFO] [stacks] Stopping stack: bookstack
2026-09-14T13:41:23.618596572Z 2026/09/14 13:41:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:23.618626919Z 2026/09/14 13:41:23 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:41:26.574902404Z 2026/09/14 13:41:26 [INFO] [stacks] Stack bookstack stopped successfully (took 4.7s)
2026-09-14T13:41:26.596365512Z 2026/09/14 13:41:26 [INFO] [stacks] Status refresh: 3 containers across 55 stacks
2026-09-14T13:41:28.747117578Z 2026/09/14 13:41:28 [INFO] [backup] Volume dump: bookstack/bookstack_bookstack_config → 748.5 KB
2026-09-14T13:41:29.584738845Z 2026/09/14 13:41:29 [INFO] [backup] Volume dump: bookstack/bookstack_bookstack_db_data → 153.4 MB
2026-09-14T13:41:29.584775344Z 2026/09/14 13:41:29 [INFO] [backup] Restarting bookstack after volume dump
2026-09-14T13:41:29.584781766Z 2026/09/14 13:41:29 [INFO] [stacks] Starting stack: bookstack
2026-09-14T13:41:33.618654346Z 2026/09/14 13:41:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:35.804944803Z 2026/09/14 13:41:35 [INFO] [stacks] Stack bookstack started successfully (took 6.2s)
2026-09-14T13:41:35.967703222Z 2026/09/14 13:41:35 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:35.984601031Z 2026/09/14 13:41:35 [INFO] [backup] Stopping privatebin for safe volume dump
2026-09-14T13:41:35.984631388Z 2026/09/14 13:41:35 [INFO] [stacks] Stopping stack: privatebin
2026-09-14T13:41:36.317890582Z 2026/09/14 13:41:36 [INFO] [stacks] Stack privatebin stopped successfully (took 0.3s)
2026-09-14T13:41:36.339346986Z 2026/09/14 13:41:36 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:41:36.791629175Z 2026/09/14 13:41:36 [INFO] [backup] Volume dump: privatebin/privatebin_privatebin_data → 8.5 KB
2026-09-14T13:41:36.791659221Z 2026/09/14 13:41:36 [INFO] [backup] Restarting privatebin after volume dump
2026-09-14T13:41:36.791681453Z 2026/09/14 13:41:36 [INFO] [stacks] Starting stack: privatebin
2026-09-14T13:41:37.196592144Z 2026/09/14 13:41:37 [INFO] [stacks] Stack privatebin started successfully (took 0.4s)
2026-09-14T13:41:37.325325834Z 2026/09/14 13:41:37 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:37.325575677Z 2026/09/14 13:41:37 [INFO] [backup] App-data backup completed: 1 databases (59.0 KB total), 2 volume dump(s) (15.752s)
2026-09-14T13:41:37.327382662Z 2026/09/14 13:41:37 [INFO] [backup] Recovery unit captured for bookstack → /mnt/sys_drive/felhom-data/backups/primary/bookstack (images=2, secrets-referenced=2, data_keys=0, portable-carried=2/2, withheld=0)
2026-09-14T13:41:37.328610092Z 2026/09/14 13:41:37 [INFO] [backup] Recovery unit captured for privatebin → /mnt/sys_drive/felhom-data/backups/primary/privatebin (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
2026-09-14T13:41:39.067273178Z 2026/09/14 13:41:39 [INFO] [stacks] Stack bookstack post-start status:
2026-09-14T13:41:39.067306912Z 2026/09/14 13:41:39 [INFO] [stacks] bookstack lscr.io/linuxserver/bookstack:26.05.2 running Up 3 seconds (health: starting)
2026-09-14T13:41:39.067310138Z 2026/09/14 13:41:39 [INFO] [stacks] bookstack-db mariadb:12.3 running Up 9 seconds (healthy)
2026-09-14T13:41:40.441520121Z 2026/09/14 13:41:40 [INFO] [stacks] Stack privatebin post-start status:
2026-09-14T13:41:40.441551751Z 2026/09/14 13:41:40 [INFO] [stacks] privatebin privatebin/pdo:2.0.5 running Up 3 seconds (health: starting)
2026-09-14T13:41:43.619667527Z 2026/09/14 13:41:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:53.596367830Z 2026/09/14 13:41:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:41:53.617436763Z 2026/09/14 13:41:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:53.618261231Z 2026/09/14 13:41:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:41:53.642862500Z 2026/09/14 13:41:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (2 deployed, 53 available)
2026-09-14T13:41:53.667394729Z 2026/09/14 13:41:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:41:53.667682322Z 2026/09/14 13:41:53 [INFO] [scheduler] Job stack-scan completed (took 72ms)
2026-09-14T13:41:53.670806076Z 2026/09/14 13:41:53 [INFO] Health probes: 2 ok (of 2 probed)
2026-09-14T13:41:53.806275126Z 2026/09/14 13:41:53 [INFO] [scheduler] Job agent-channel-health completed (took 188ms)
2026-09-14T13:42:03.617656913Z 2026/09/14 13:42:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:13.618109091Z 2026/09/14 13:42:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:23.621191533Z 2026/09/14 13:42:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:33.620394542Z 2026/09/14 13:42:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:43.627351055Z 2026/09/14 13:42:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:53.616838865Z 2026/09/14 13:42:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:42:53.618834613Z 2026/09/14 13:42:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:42:53.818363131Z 2026/09/14 13:42:53 [INFO] [scheduler] Job agent-channel-health completed (took 199ms)
2026-09-14T13:43:03.619528338Z 2026/09/14 13:43:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:13.620424634Z 2026/09/14 13:43:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:23.621832798Z 2026/09/14 13:43:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:33.622110930Z 2026/09/14 13:43:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:36.217030766Z 2026/09/14 13:43:36 [INFO] [api] Remove requested for stack: privatebin
2026-09-14T13:43:36.217306237Z 2026/09/14 13:43:36 [ERROR] [api] Remove failed for privatebin: stack "privatebin" is still running — stop it first before removing
2026-09-14T13:43:43.619458600Z 2026/09/14 13:43:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:53.596129235Z 2026/09/14 13:43:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:43:53.596161407Z 2026/09/14 13:43:53 [INFO] [scheduler] Running job: backup-cache
2026-09-14T13:43:53.596166636Z 2026/09/14 13:43:53 [INFO] [scheduler] Running job: system-health
2026-09-14T13:43:53.596179250Z 2026/09/14 13:43:53 [INFO] [scheduler] Running job: offsite-credential-retry
2026-09-14T13:43:53.596231619Z 2026/09/14 13:43:53 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026-09-14T13:43:53.620195649Z 2026/09/14 13:43:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:43:53.623294028Z 2026/09/14 13:43:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (2 deployed, 53 available)
2026-09-14T13:43:53.665567184Z 2026/09/14 13:43:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:53.665594705Z 2026/09/14 13:43:53 [INFO] [scheduler] Job stack-scan completed (took 69ms)
2026-09-14T13:43:53.696939269Z 2026/09/14 13:43:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:43:53.697326380Z 2026/09/14 13:43:53 [INFO] [backup] Found 1 DB dump files across drives
2026-09-14T13:43:53.762674197Z 2026/09/14 13:43:53 [INFO] [backup] Discovered 1 databases
2026-09-14T13:43:53.764463625Z 2026/09/14 13:43:53 [INFO] [backup] Discovered app data: 2 apps
2026-09-14T13:43:53.768277384Z 2026/09/14 13:43:53 [INFO] [backup] Backup status cache refreshed
2026-09-14T13:43:53.768501348Z 2026/09/14 13:43:53 [INFO] [scheduler] Job backup-cache completed (took 172ms)
2026-09-14T13:43:53.818814371Z 2026/09/14 13:43:53 [INFO] [monitor] Health check: status=ok
2026-09-14T13:43:53.818842694Z 2026/09/14 13:43:53 [INFO] [scheduler] Job system-health completed (took 223ms)
2026-09-14T13:43:53.828120800Z 2026/09/14 13:43:53 [INFO] [scheduler] Job agent-channel-health completed (took 208ms)
2026-09-14T13:43:53.871057137Z 2026/09/14 13:43:53 [INFO] [infra] cloudflared skipped — no cf_tunnel_token configured (LAN-only node)
2026-09-14T13:44:03.621615798Z 2026/09/14 13:44:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:13.620886366Z 2026/09/14 13:44:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:13.781754340Z 2026/09/14 13:44:13 [WARN] [web] Restore requested (async): stack=bookstack, snapshot=helyi from 172.18.0.2:38062
2026-09-14T13:44:13.783061848Z 2026/09/14 13:44:13 [INFO] [backup] Restoring bookstack from recovery unit /mnt/sys_drive/felhom-data/backups/primary/bookstack: images=2, secrets recovered=2/2, data_keys=0
2026-09-14T13:44:13.783534581Z 2026/09/14 13:44:13 [INFO] [stacks] Stopping stack: bookstack
2026-09-14T13:44:17.600506449Z 2026/09/14 13:44:17 [INFO] [stacks] Stack bookstack stopped successfully (took 3.8s)
2026-09-14T13:44:17.622150109Z 2026/09/14 13:44:17 [INFO] [stacks] Status refresh: 3 containers across 55 stacks
2026-09-14T13:44:17.622398538Z 2026/09/14 13:44:17 [INFO] [backup] Restoring Docker volume bookstack_bookstack_config for bookstack
2026-09-14T13:44:18.102122282Z 2026/09/14 13:44:18 [INFO] [backup] Restoring Docker volume bookstack_bookstack_db_data for bookstack
2026-09-14T13:44:18.791871030Z 2026/09/14 13:44:18 [INFO] [backup] Restored 2 Docker volume(s) for bookstack
2026-09-14T13:44:18.792322643Z 2026/09/14 13:44:18 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 2 encrypted, 2 sensitive fields
2026-09-14T13:44:18.792734350Z 2026/09/14 13:44:18 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:44:18.792792860Z 2026/09/14 13:44:18 [INFO] [stacks] Redeploying bookstack from recovery unit with 4 env vars
2026-09-14T13:44:18.793474508Z 2026/09/14 13:44:18 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 0 encrypted, 2 sensitive fields
2026-09-14T13:44:18.793820351Z 2026/09/14 13:44:18 [INFO] [stacks] pin bookstack: bookstack=lscr.io/linuxserver/bookstack:26.05.2, bookstack-db=mariadb:12.3
2026-09-14T13:44:18.793835699Z 2026/09/14 13:44:18 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:44:18.793973940Z 2026/09/14 13:44:18 [INFO] [stacks] Starting stack bookstack services only: [bookstack-db]
2026-09-14T13:44:19.245160290Z 2026/09/14 13:44:19 [INFO] [stacks] Stack bookstack services [bookstack-db] started (took 0.5s)
2026-09-14T13:44:19.265718130Z 2026/09/14 13:44:19 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:44:19.310066583Z 2026/09/14 13:44:19 [INFO] [backup] Discovered 1 databases
2026-09-14T13:44:19.310147496Z 2026/09/14 13:44:19 [INFO] [backup] Restore bookstack: replaying DB dump into bookstack-db (mariadb)
2026-09-14T13:44:23.620668229Z 2026/09/14 13:44:23 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:44:25.083906937Z 2026/09/14 13:44:25 [INFO] [backup] Imported DB dump bookstack-mariadb.sql into bookstack-db (mariadb)
2026-09-14T13:44:25.083948255Z 2026/09/14 13:44:25 [INFO] [backup] Restore bookstack: replayed 1 DB dump(s)
2026-09-14T13:44:25.083953375Z 2026/09/14 13:44:25 [INFO] [stacks] Starting stack: bookstack
2026-09-14T13:44:25.953147868Z 2026/09/14 13:44:25 [INFO] [stacks] Stack bookstack started successfully (took 0.9s)
2026-09-14T13:44:26.117621879Z 2026/09/14 13:44:26 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 4 env vars, 0 encrypted, 2 sensitive fields
2026-09-14T13:44:26.117656485Z 2026/09/14 13:44:26 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026-09-14T13:44:26.117668888Z 2026/09/14 13:44:26 [INFO] [stacks] installed-images bookstack: recorded 2 service(s) (bookstack=lscr.io/linuxserver/bookstack:26.05.2 (sha256:3db259db5828…), bookstack-db=mariadb:12.3 (sha256:ab1c3dd38194…))
2026-09-14T13:44:26.144397677Z 2026/09/14 13:44:26 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:29.167565319Z 2026/09/14 13:44:29 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:29.220551188Z 2026/09/14 13:44:29 [INFO] [stacks] Stack bookstack post-start status:
2026-09-14T13:44:29.220582626Z 2026/09/14 13:44:29 [INFO] [stacks] bookstack lscr.io/linuxserver/bookstack:26.05.2 running Up 3 seconds (health: starting)
2026-09-14T13:44:29.220585823Z 2026/09/14 13:44:29 [INFO] [stacks] bookstack-db mariadb:12.3 running Up 10 seconds (healthy)
2026-09-14T13:44:33.618714837Z 2026/09/14 13:44:33 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:34.189122538Z 2026/09/14 13:44:34 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:39.216775545Z 2026/09/14 13:44:39 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:39.216818515Z 2026/09/14 13:44:39 [INFO] [backup] Restore-from-unit completed: bookstack — 2 volume(s) of 2 listed, 1 database(s) of 1 listed
2026-09-14T13:44:39.216824937Z 2026/09/14 13:44:39 [INFO] [web] Restore completed (async): stack=bookstack in 25.435002741s (volumes 2/2, dbs 1/1)
2026-09-14T13:44:43.619462494Z 2026/09/14 13:44:43 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:43.650191084Z 2026/09/14 13:44:43 [INFO] Health probes: 1 ok (of 1 probed)
2026-09-14T13:44:53.597106486Z 2026/09/14 13:44:53 [INFO] [deadapp] check alive: 40 scans since boot, 2 deployed app(s) evaluated, 0 currently down
2026-09-14T13:44:53.620052054Z 2026/09/14 13:44:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:44:53.621270234Z 2026/09/14 13:44:53 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:44:53.815227816Z 2026/09/14 13:44:53 [INFO] [scheduler] Job agent-channel-health completed (took 196ms)
2026-09-14T13:45:03.619203304Z 2026/09/14 13:45:03 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:45:13.616686861Z 2026/09/14 13:45:13 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:45:23.618163561Z 2026/09/14 13:45:23 [INFO] [stacks] Status refresh: 5 containers across 55 stacks
2026-09-14T13:45:26.717091528Z 2026/09/14 13:45:26 [INFO] [api] stop requested for stack: privatebin
2026-09-14T13:45:26.717547800Z 2026/09/14 13:45:26 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/privatebin — 2 env vars, 0 encrypted, 0 sensitive fields
2026-09-14T13:45:26.717990466Z 2026/09/14 13:45:26 [INFO] [stacks] desired state for privatebin recorded as "stopped" (was "running")
2026-09-14T13:45:26.718009021Z 2026/09/14 13:45:26 [INFO] [stacks] Stopping stack: privatebin
2026-09-14T13:45:26.718021986Z 2026/09/14 13:45:26 [INFO] [stacks] SaveAppConfig: saved config for privatebin
2026-09-14T13:45:26.990905792Z 2026/09/14 13:45:26 [INFO] [stacks] Stack privatebin stopped successfully (took 0.3s)
2026-09-14T13:45:27.015383863Z 2026/09/14 13:45:27 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:33.624600793Z 2026/09/14 13:45:33 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:33.965769897Z 2026/09/14 13:45:33 [INFO] [api] Remove requested for stack: privatebin
2026-09-14T13:45:33.966223363Z 2026/09/14 13:45:33 [INFO] Removing deployed stack: privatebin (removeHDDData=false, hddDeclared=false, backupPaths=2)
2026-09-14T13:45:34.128131495Z 2026/09/14 13:45:34 [INFO] [stacks] RemoveStack privatebin: removed volume(s) [privatebin_privatebin_data]
2026-09-14T13:45:34.129582827Z 2026/09/14 13:45:34 [INFO] Removed backup data: /mnt/sys_drive/felhom-data/backups/primary/privatebin (40K)
2026-09-14T13:45:34.129620598Z 2026/09/14 13:45:34 [INFO] Stack privatebin removed successfully (took 0.2s)
2026-09-14T13:45:34.145587801Z 2026/09/14 13:45:34 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:45:34.166969754Z 2026/09/14 13:45:34 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:34.228237766Z 2026/09/14 13:45:34 [INFO] Event pushed: app_removed (info) — Alkalmazás eltávolítva: privatebin
2026-09-14T13:45:36.168882135Z 2026/09/14 13:45:36 [INFO] [report] Building system report
2026-09-14T13:45:36.383520600Z 2026/09/14 13:45:36 [INFO] [monitor] Health check: status=ok
2026-09-14T13:45:36.480824157Z 2026/09/14 13:45:36 [INFO] [report] Hub report pushed successfully (4750 bytes)
2026-09-14T13:45:36.481253578Z 2026/09/14 13:45:36 [INFO] [settings] Settings saved
2026-09-14T13:45:43.618129179Z 2026/09/14 13:45:43 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:53.596513788Z 2026/09/14 13:45:53 [INFO] [scheduler] Running job: stack-scan
2026-09-14T13:45:53.615642043Z 2026/09/14 13:45:53 [INFO] [stacks] ScanStacks complete: 55 stacks found (1 deployed, 54 available)
2026-09-14T13:45:53.619239038Z 2026/09/14 13:45:53 [INFO] [scheduler] Running job: agent-channel-health
2026-09-14T13:45:53.638034575Z 2026/09/14 13:45:53 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:53.638107243Z 2026/09/14 13:45:53 [INFO] [scheduler] Job stack-scan completed (took 42ms)
2026-09-14T13:45:53.662707516Z 2026/09/14 13:45:53 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:45:53.813945760Z 2026/09/14 13:45:53 [INFO] [scheduler] Job agent-channel-health completed (took 195ms)
2026-09-14T13:46:03.620675324Z 2026/09/14 13:46:03 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:46:13.617043744Z 2026/09/14 13:46:13 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:46:23.622573058Z 2026/09/14 13:46:23 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
2026-09-14T13:46:33.622103563Z 2026/09/14 13:46:33 [INFO] [stacks] Status refresh: 4 containers across 55 stacks
@@ -0,0 +1,482 @@
# Journal — DRILL fresh install 0.242.0, 2026-09-14
Every observable in the order taken. Times are **UTC** unless marked. Hub log lines print **CEST**
(UTC+2). Screens are in `screens/`, named by step.
## Baselines (re-verified 12:5x UTC)
| repo | main | version |
|---|---|---|
| felhom-controller | `406755fa8fba` | v0.242.0 |
| felhom-agent | `4586f0f7f6d1` | v0.130.0 |
| felhom.eu | `41590f8ee618` | hub v0.112.0 |
Hub, before the bake: agent `0.130.0` vouched · golden `0.236.0` vouched · `min_agent 0.129.0` ·
floor `min_controller_version 0.242.0`. Highest register id **R-492**.
## Phase 0.1 — golden 0.242.0
Baked 13:01:04 → finished before 13:06:42 · round-trip verified · vouched **13:08:41**.
Full record: `documentation/tests/golden-0.242.0-2026-09-14/README.md`.
## Phase 0.2 — what a volunteer receives
Searched, with what was searched:
| source | what was looked for | result |
|---|---|---|
| `website/*.html` (9 pages) | `iso.felhom`, `iso`, `letolt`, `telepit` | **no mention of the installer, of `iso.felhom.eu`, or of any install step** (only `technologiak.html` "comparison" and two FAQ answers on power loss / backups matched the loose pattern) |
| `https://iso.felhom.eu/` | the root, `index.html` | **HTTP 404** both. Only a named object answers: `felhom-installer-1.26.1-pve9.2-1.iso` (200, 1 705 322 496 B, last-modified 2026-07-31) |
| `RUNBOOK-onboarding-draft-v4.md` | customer steps | **operator document**, operator present at the visit ("operator narrates"); C7 marked never executed |
| `email.md` in the workspace | `find /mnt/5_hdd/felhom.eu -maxdepth 5 -iname '*email*.md'` | **absent** (only `audits/FINDING-app-email-rollout-2026-06-29.md`, unrelated) |
| the R-11 tester one-pager | `find … -iname '*one-pager*'`, register | **never written** — ROADMAP-HISTORY: "RULED 2026-07-21 (channel); doc is the architect's" |
| hub e-mails to a new customer | `hub/internal/notify/templates.go` | two: **„Kösd össze a Felhom dobozodat"** (self-bind link, at customer creation) and **„Elindult a Felhom szervered — beállító kód"** (claim code, after day-0). Neither says how to get or install the software |
## Harness limits, declared before the walk (not interventions — the volunteer is not limited this way)
- **H1 — no mailbox.** Both customer mails go only to the registered address. The hub stores
hashes; the Resend key on DooPlex is send-only (`401 restricted_api_key … only send emails`,
probed 13:00). A volunteer reads their inbox; this harness cannot.
- **H2 — keyboard.** `qm sendkey` emits US scancodes; the installer defaults to **Hungarian**. The
layout was switched to U.S. English (as walk 5). A volunteer keeps Hungarian.
- **H3 — the USB stick.** Auto-reboot was unticked so the VM does not re-enter the installer from the
still-attached ISO; the ISO is detached by `qm set` after the install. A volunteer pulls the stick.
- **H4 — the Terminal UI entry** was chosen over the graphical default for key-drivability. Both
entries were release-gated.
## Scope choice
- Customer created **with the DR tier OFF** (the form defaults it ON). The DR tier provisions an
**ep0** namespace and token; the brief fences ep0. Offsite is OFF by default and stayed OFF.
## Step 1 — download
13:01:27 on demo-hp: `curl https://iso.felhom.eu/felhom-installer-1.26.1-pve9.2-1.iso` → rc 0,
**32 s**, 1 705 322 496 B, sha256 `f3cc86d5f0ec68bba4155c994b4fa84e208d50209bb6e815636c99e5441059a6`
= the published `.sha256` exactly. (No release report records a sha for 1.26.1; walk 5 recorded
"same sha256" without the value.) **A volunteer must already know the exact file name** — the site
lists nothing.
## Hub side — the operator's steps
13:03:03 `POST /configs/new` customer `drill0242`, name "Drill 0.242 first hour", domain
`drill0242.felhom.eu`, e-mail `drill0242@felhom.eu`, DR tier off → **303** 13:03:04. Hub log (CEST):
```
15:03:04 [INFO] Customer config created: drill0242
15:03:04 [INFO] self-bind link (hash 4270bdd2…, valid 7 days) emailed to the registered address of drill0242
15:03:04 [INFO] self-bind link auto-minted for drill0242 on customer creation (the console banner's promised email now exists)
```
The 5-word **Tulajdonosi jelmondat** was read from the customer page into a `0600` file on DooPlex
(shape: 5 words, 42 chars). **The operator must hand it to the volunteer out of band — nothing sends
it.** (The self-bind mail says „amelyet a beállításkor kaptál" — "which you received at setup".)
## Step 2 — install
VM **330 `drill0242-fresh-install`** on demo-hp: q35/OVMF (`pre-enrolled-keys=0`), 4 cores, 8 GB,
`cpu=host`, `scsi0` 200 G · `scsi1` 50 G · `scsi2` 50 G qcow2 on **`nvme-scratch`** (dir at
`/mnt/hdd_1`, the mount root), MAC `bc:24:11:0c:23:cc`.
| UTC | screen | what it said / what was done |
|---|---|---|
| 13:03:43 | power on | — |
| 13:03:49 | GRUB (`s01`, `s02`) | Felhom logo, „Saját felhőd, saját szabályaid"; entries **„Felhom telepítés"** / **„Felhom telepítés (szöveges mód)"** — the only Hungarian the installer shows |
| 13:05:09 | `s04` | **English** Proxmox EULA, „I agree" |
| 13:05:27 | `s05` | „Target harddisk: /dev/sda (QEMU HARDDISK) (200.00 GiB)" — default is the right disk here; **three disks present, no guidance which** |
| 13:05:43 | `s06` | Country Hungary · Timezone Europe/Budapest · **Keyboard Hungarian** (H2: changed to U.S. English) |
| 13:09:18 | `s13` | Root password [at least 8 characters] · Confirm · **Administrator email prefilled `mail@example.invalid`** — the volunteer must decide what to type; set `drill0242@felhom.eu` |
| 13:12:01 | `s16` | nic0 `bc:24:11:0c:23:cc` · **Hostname `pve.example.invalid`** · IP `192.168.0.134/24` (the DHCP lease, frozen as static) · GW `192.168.0.1` · DNS `192.168.0.250` |
| 13:12:21 | `s17` | Next on the defaults → **„Invalid values: hostname does not look valid"**. The default is refused; the volunteer must invent a hostname. Set `drill0242.felhom.eu` |
| 13:14:40 | `s22` | Summary: `ext4` · `/dev/sda` · `Europe/Budapest` · `U.S. English` · `drill0242@felhom.eu` · `nic0` · `drill0242.felhom.eu` · `192.168.0.134/24` · `192.168.0.1` · `192.168.0.250` · „[X] Automatically reboot" (H3: unticked, `s25`) |
| 13:15:54 | Install pressed | — |
| ≤13:19:18 | `s28` | „Success — Installation finished - reboot now?" (**≤ 3 m 24 s** of copying; disk 4.0 G) |
| 13:19:44 | first boot | H3: `qm stop`, `--delete ide2`, `--boot order=scsi0` in its own `qm set` (verified `boot: order=scsi0`, ide2 lines 0), `qm start` |
## Step 3 — the first screen and the claim
**13:21:10 — the hub lists an Unclaimed appliance (86 s after first power-on):** appliance 25,
pairing code `***-***` (redacted), MAC `bc:24:11:0c:23:cc`, "Standard PC (Q35 + ICH9, 2009)", 7.7 GB,
three SSH host keys.
**The console (`s29`, code redacted), verbatim:**
```
Welcome to the Proxmox Virtual Environment. Please use your web browser to
configure this server - connect to:
https://192.168.0.134:8006/
drill0242 login:
Felhom — a doboz készen áll, és a párosításra vár.
Párosító kód: ***-***
Nyisd meg az e-mailben kapott linket, és add meg
ezt a kódot és a jelszavadat.
Ez a képernyő magától frissül — nincs teendő a
doboznál, és nyugodtan itt hagyhatod bekapcsolva.
```
Two things a stranger meets here: **an English line telling them to open the Proxmox admin page**,
above the Felhom text; and **„a jelszavadat" ("your password")** for the secret the self-bind mail
calls **„Tulajdonosi jelmondat"** (R-323 renamed the mail, not the console).
**The bind (H1 consequence).** The volunteer's route is the self-bind link, which is in a mailbox this
harness cannot read. The operator's documented fallback was used: `POST /appliances/25/bind`
(`customer_id=drill0242`) at **13:21:43** → 303 `flash=appliance_bound`. **The self-bind page itself
was therefore NOT exercised.**
Hub log (CEST = UTC+2):
```
15:21:44 appliance 25 BOUND to customer drill0242 (mode=appliance) — delivery staged for its next poll
15:21:45 appliance credentials DELIVERED once to appliance 25 (… passphrase withheld)
15:21:52 [claim] claim code (gen 1) emailed to the registered address of drill0242
15:22:21 host enrolled: drill0242-3f4b42 (customer drill0242)
15:22:21 vaulted break-glass recovery credential for host drill0242-3f4b42 (user=root@pam, secret 32 chars)
15:22:22 Artifact manifest served for customer drill0242 (agent=0.130.0 golden=0.242.0)
15:22:38 wg registered: host=drill0242-3f4b42 … ip=10.77.0.5/32 changed=true gen=1 sync=ok
15:22:39 DR-recipe host-half stored for customer drill0242 (host drill0242-3f4b42, v1)
15:23:58 Event from drill0242: controller_started (info) — Controller elindult (0.242.0)
15:23:58 managed floor SERVED for drill0242: floor 0.242.0, agent requirement "0.129.0" from manifest (golden 0.242.0)
```
**Note on ep0:** `wg registered … sync=ok` is a WireGuard peer written on ep0 by enrolment itself,
with the DR tier OFF. The brief fenced ep0; the product touches it on every enrolment. Teardown owes
its removal.
## Step 4 — "ready", and the version
| | vouched | landed |
|---|---|---|
| agent | 0.130.0 | **0.130.0** (`felhom-agent --version`) |
| controller | golden 0.242.0 | **0.242.0** (`docker ps`: `felhom-controller:0.242.0 … (healthy)`) |
**No self-update happened because none was needed** — golden == floor. Power-on → controller running
**4 m 14 s**; bind → controller **2 m 15 s**. Infra: `traefik:v3.6.7`, `gtstef/filebrowser:1.3.3-stable`.
First local whole-guest backup ran unaided 15:28:53–15:29:23 CEST, OK (seen as a `backup` lock).
**The console still shows the pairing banner and the stale code after bind** (`s30`, 13:24:38) —
R-214, still open.
## Intervention I1 — the dashboard has no address (R-494, filed 13:2x BEFORE acting)
The claim mail says `https://felhom.drill0242.felhom.eu`. Measured:
```
felhom.drill0242.felhom.eu @1.1.1.1 A: (none) AAAA: (none)
control felhom.enkisfelhom.hu @1.1.1.1 A: 104.21.3.175 172.67.130.252
https://felhom.drill0242.felhom.eu curl rc 6 (cannot resolve)
@192.168.0.1 (router) (none)
@192.168.0.250 (installer-offered DNS) (none)
@192.168.0.134 (the box) 13:27:39Z (none) — google.com resolves: the resolver is alive
agent 15:27:44 CEST lanresolver: applied split-horizon record vmid=9201 domain=drill0242.felhom.eu ip=192.168.0.158
@192.168.0.134 (the box) 13:29:18Z 192.168.0.158
```
The hub has no tunnel/DNS creation code; `cf_tunnel_token` is an optional pasted field. **Act:** the
dashboard is reached at the guest LAN address with the name forced (`--resolve
felhom.drill0242.felhom.eu:443:192.168.0.158`), from demo-hp — which is where a browser on the
household LAN would be. `GET /` → 302 `/claim`; the page, verbatim:
> **A szerver beállítása** — Drill 0.242 first hour — „Add meg az e-mailben kapott beállító kódot,
> majd válassz saját jelszót a vezérlőpult védelméhez." · Beállító kód (`szó-szó-szó`) · Új jelszó
> (min. 12 karakter) · Új jelszó megerősítése · **Beállítás és belépés** · „Nem kaptad meg a kódot?
> **Új kód kérése**"
## H1 — the setup code (harness substitution, not a volunteer act)
The code is in the mail. Observe access to the appliance: `POST /hosts/drill0242-3f4b42/reveal-recovery-credential`
→ 200 (the designed operator path; it emits an audit event), stored `0600`, never printed. Then
`pct exec 9201 -- docker exec felhom-controller … --print-reset-code`.
**Harness slip, recorded:** the first mint at 13:29:28 (**generation 2**) was captured with a
pattern `[a-z-]*` that does not match accented letters, and the raw output was shredded before the
capture was checked — **that code was lost unseen**. Re-minted (generation 3) with a byte-agnostic
capture. Both mints supersede the mailed generation-1 code.
## Step 3 (cont.) — the claim, through the front door
All dashboard requests from here are made **from demo-hp** (the household LAN) to the guest's traefik
on `192.168.0.158:443` with the dashboard name forced — intervention I1, once, for the whole walk.
Secrets travel on stdin to curl, never on a command line; the dashboard password is a generated
24-character value in a `0600` file on DooPlex.
| UTC | request | result |
|---|---|---|
| 13:31:19 | `GET /claim` | 200; `felhom_claim_csrf` cookie (82 B) + form token (64 hex) |
| 13:31:20 | `POST /claim` `_csrf, code, new_password, confirm_password` | **302 → `/`**, `Set-Cookie: felhom_session` |
| 13:31:2x | `GET /launcher` | **200** — „Indítópult — drill0242.felhom.eu", one tile **Filebrowser**, „Indítópult megosztása … A megosztás jelenleg ki van kapcsolva." Menu: Vezérlőpult · Alkalmazások · Tárhely (Meghajtók, Hálózati tárhely) · Biztonsági mentés (Áttekintés, Távoli mentés, Alkalmazások, Visszaállítás) · Megosztás · Rendszermonitor · **Debug** · Beállítások · version `0.242.0` |
**Power-on → claimed dashboard: 27 m 37 s** (13:03:43 → 13:31:20), of which the harness's own
keyboard driving is most of the install phase.
## Step 5 — the app list
`GET /stacks` → 200, „Alkalmazások — drill0242.felhom.eu", filters Mind / Futó / Leállítva /
Telepíthető, **52** „Telepítés" links. `GET /stacks/bookstack/deploy` and `/stacks/privatebin/deploy`
→ 200. Both pages, verbatim in the parts a stranger reads:
> **BookStack — Telepítés** · „Egyszerű, könyv-szerű wiki és dokumentáció platform" · ~150M · Pi
> kompatibilis · Memória 1058 MB / 3712 MB (28%) · **„Hol lesznek az adatok: ennél az alkalmazásnál
> nincs külön adatmeghajtó-választás, ezért az adatai a rendszermeghajtóra kerülnek (/mnt/sys_drive).
> A mentései így is elkészülnek."** · „Automatikusan generált értékek … Jegyezze fel a szükséges
> jelszavakat!" (Alkalmazás kulcs, Adatbázis jelszó — Megjelenítés) · Aldomain `wiki` · „Az aldomain
> telepítés után nem módosítható…"
> **PrivateBin — Telepítés** · „Titkosított jegyzet és szöveg megosztás" · ~30M · Memória 1089 MB /
> 3712 MB (29%) · same data sentence · Aldomain `paste`
Observation, not yet a row: the drive page's „Meglévő meghajtó csatolása" candidate list
(`GET /api/disks/candidates`) offers **the guest's own system volume**
`/dev/mapper/pve-vm--9201--disk--1` (`mount_source /mnt/sys_drive`, `already_mounted: true`,
`data_bearing: true`) beside the two blank 50 G disks.
## Step 5 (cont.) — deploy
Both through the deploy page's own call: every named input of `#deploy-form` →
`POST /api/stacks/<app>/deploy {"values":{…}}`, then `GET /api/stacks/<app>` every 5 s (the page
polls every 3 s). Generated secrets travelled on stdin and were shredded.
| app | fields sent | POST | state transitions | running after |
|---|---|---|---|---|
| bookstack | `APP_KEY, DB_PASSWORD, SUBDOMAIN=wiki` | 13:34:38 → **202** „Telepítés elindítva – az állapot a kártyán követhető" | +6 s `deploying` · **+26 s `degraded`** · +42 s `starting` · +68 s `running` | **68 s** |
| privatebin | `SUBDOMAIN=paste` | 13:35:47 → **202** | +5 s `starting` · +21 s `running` | **21 s** |
Observation: the deploy page's poll handles `deploying / running / starting / unhealthy / exited /
stopped` and has **no `degraded` branch** (`deploy.html` ~1040–1095), so for those 16 s the page keeps
showing its previous step. Harmless here; recorded.
**App pages** (`/apps/bookstack`, `/apps/privatebin`): „Fut" · **„Naprakész"** · „Megnyitás ↗".
BookStack's „Első lépések": „Nyisd meg a **wiki.DOMAIN** címet a böngészőben · Jelentkezz be:
admin@admin.com / password · Változtasd meg azonnal az admin jelszót és email címet …" and a box
„Alapértelmezett belépés admin@admin.com / password — Az első bejelentkezés után azonnal változtasd
meg!". PrivateBin: „Nyisd meg a **paste.DOMAIN** címet …" → **R-498** (52 of 53 templates).
## Step 6 — using both, through their front doors
Front doors from demo-hp: `wiki.drill0242.felhom.eu` → 302 `/login`; `paste.drill0242.felhom.eu` →
200, 22 896 B, PrivateBin UI (English).
**BookStack** (over HTTPS, so its `secure` cookies work — R-460's 419 was a plain-HTTP effect):
| UTC | act | result |
|---|---|---|
| 13:37:18 | log in `admin@admin.com / password` (the page's own instruction) | 302 → `/`; logged-in markers 3 |
| 13:37:19 | change password via `POST /users/1` | **405 — harness wrong route** (BookStack ≥23 is `/settings/users/1`) |
| 13:37:52 | change admin e-mail + password via `POST /settings/users/1` `_method=PUT` | 302 → `/settings/users`; **old default login now → `/login` (refused); new → `/` (accepted)** |
| 13:38:44 | create book „Családi receptek DRILL0242" | 302 → `/books/csaladi-receptek-drill0242` |
| 13:38:4x | save a draft with `_method=PUT` | **405 — harness** (the route is POST) |
| 13:39:35 | new draft 3 → `POST` name „Töltött káposzta", body `DRILL0242-OLDAL Töltött káposzta: árvíztűrő tükörfúrógép 2026-09-14` | 302 → `/books/csaladi-receptek-drill0242/page/toltott-kaposzta` |
| 13:39:3x | upload attachment `nagymama-recept.bin`, 262 144 B random, sha256 `2e252913844f8931…` | 200, attachment id 1 |
| 13:39:3x | read back | page 200, sentence present **2** (negative control **0**); attachment listed 1; `GET /attachments/1` 200 262 144 B, **sha256 equal: YES** |
**PrivateBin** — the browser's own v2 format (AES-256-GCM, PBKDF2-SHA256 100 000, zlib), key only in
the fragment, as a browser does:
| UTC | act | result |
|---|---|---|
| 13:38:08 | `POST /` a paste „DRILL-0242 privatebin sentinel … — árvíztűrő tükörfúrógép", expire 1 week | 200 `{"status":0,"id":"3963448c37a87005",…}` |
| 13:38:08 | `GET /?pasteid=3963448c37a87005`, decrypt | 200, 471 B, **decrypted == sent: True** (sha256 `5920d11290cca367…`); **wrong key → `InvalidTag`** |
## Step 7 — the backups pages, read as a first-timer (13:38:55)
`/backups` verbatim, in order: „Csak egy másolat készül (nincs második meghajtó) — a 3-2-1 mentéshez
csatlakoztasson egy második meghajtót vagy offsite tárolót." · „A rendszermentés jelenleg ugyanazon a
lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem. …" · Rendszer (/)
1.96 GB / 68.7 GB (3%) · DB mentések – · **Utolsó teljes mentés 2026-09-14 15:28 (10 perce) 624.3 MB
Helyi tároló (local) Naprakész** · **„Következő mentés — 0 órája — a mentési ablakon belül"** ·
Visszaállítás ellenőrizve „Még nem futott" · Mentés most · window 02:30 / 03:30 / 04:15 / 04:30–08:30
· Távoli rendszermentés „nincs beállítva".
- **Honest:** both warnings; the whole-box backup's date and target.
- **Confusing:** „Következő mentés" (next backup) with „0 órája" ("0 hours ago") under it — the value is
the age of the LAST backup (`backups.html:101-102`, `.AgeHours`).
`/backups/apps`: „Utolsó adatbázis mentés: Még nem futott"; BookStack „Konfig + DB + Adatok" and
PrivateBin „Konfig + Adatok", each „1. mentés Auto helyi **Utolsó: most**" · „Nincs 2. (off-drive)
másolat" · „3. mentés Nincs beállítva".
**„Utolsó: most" was checked, not assumed:** `timeAgoStr` renders „most" only for a parseable time
under a minute old (an empty value renders nothing, `funcmap.go:283-296`), and
`GET /api/backup/snapshots?stack=…` returned for both apps
`{"time":"2026-09-14T13:38:53Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}` —
3 s before the page was read. **True.** (That unit predates the BookStack content of 13:39:35.)
`/stacks/bookstack/backup` → **R-499**: „… már szerepelnek a teljes rendszermentésben (PBS) … ehhez
az alkalmazáshoz nincs külön teendő." — this box has no PBS.
`/backups/restore`: app select BookStack / PrivateBin, „Pillanatkép: — Válasszon alkalmazást —",
„Még nincs mentés felhasználói adattal."
## Step 8 — „Mentés most" (the app-backups page's button, `POST /api/backup/run`)
| UTC | observable |
|---|---|
| 13:41:21 | pressed → `{"ok":true,"message":"Mentés elindítva"}` |
| +5 s | `{"enabled":true,"running":true}` |
| +21 s | `{"db_dump":{"count":1,"duration":"15.752362463s","last_run":"2026-09-14T13:41:37.325510764Z","success":true},"enabled":true,"running":false}` |
| 13:41:42 | both apps' restore points: `{"time":"2026-09-14T13:41:37Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}` — **one entry each; the 13:38:53 unit is gone** (one local point kept) |
| 13:41:4x | `/backups/apps`: „Utolsó adatbázis mentés: **2026-09-14 15:41 (most)**"; Adatbázisok: `bookstack · MariaDB · 59.0 KB · 15:41 · 41 tábla · OK` |
**The date moved, to the true time, on both pages (R-476 class: holds).** 21 s end to end.
## Step 9 — version labels and Update
Both app pages: „Fut · **Naprakész**". `GET /api/stacks/<app>` at 13:42:28:
```
bookstack template_images {bookstack: lscr.io/linuxserver/bookstack:26.05.2, bookstack-db: mariadb:12.3}
catalog_images {bookstack: lscr.io/linuxserver/bookstack:26.05.2, bookstack-db: mariadb:12.3}
privatebin template_images {privatebin: privatebin/pdo:2.0.5} catalog_images {privatebin: privatebin/pdo:2.0.5}
```
**The catalog offers no newer version of either app, so there was nothing to press. Skipped, per the
brief.** „Naprakész" is true on this evidence (installed == catalog).
## Step 10 — removal: what the dialog shows for PrivateBin
The app page's delete opens `removeStack()` (`layout.html:396`), which loads
`/api/stacks/privatebin/hdd-data` → `{"hdd_paths":null,"has_hdd_data":false}` and
`/backup-data` → `[{"path":"/mnt/sys_drive/felhom-data/backups/primary/privatebin","size_human":"40K","exists":true}]`.
Rendered text, in order:
> **Alkalmazás eltávolítása: privatebin** · „Az alkalmazás visszaáll "Nincs telepítve" állapotba. A
> sablon megmarad, újratelepíthető." · „Ez a művelet nem visszavonható!" · **Mindig törlődik:** Docker
> kötetek (adatbázis, alkalmazás konfiguráció) · Telepítési konfiguráció (app.yaml) · Másodlagos mentés
> ütemezése · **Mentési adatok:** /mnt/sys_drive/felhom-data/backups/primary/privatebin (40K) ·
> ☐ **Mentési adatok törlése** · „Az éjszakai restic pillanatképek nem törölhetők egyenként — a
> megőrzési szabályok szerint automatikusan elavulnak." · Mégsem · Eltávolítás
**No „delete my data" box appears** — PrivateBin has no drive data; its data is in a Docker volume,
which the dialog says is **always** deleted. „Delete my data too" was therefore performed as **every
delete box ticked**: `remove_backups: true` (the only box), `remove_hdd_data: false` (no box shown).
Observation: the sentence about „éjszakai restic pillanatképek" appears on a box with no restic
configured at all.
## Step 11 prep — the household loses a recipe (13:43:07)
Through BookStack's own delete: `GET …/page/toltott-kaposzta/delete` → token; `POST …/page/toltott-kaposzta`
`_method=DELETE` → 302 to the book. Then: page **404**, `/attachments/1` **404**, the book page lists
the title **0** times. The last backup containing both is the 13:41:37 unit (step 8).
## Step 11 — restore BookStack from its backup, through the restore page
The page's own submit: `POST /backup/restore` `_csrf` (from the page meta), `stack_name=bookstack`,
`snapshot_id=helyi` (the only point, 13:41:37 — step 8).
| UTC | observable |
|---|---|
| 13:44:13 | **302** → `/backups/restore?flash=Visszaállítás elindult — az állapot itt frissül.` |
| +6 s | app `stopped` |
| +11 s | `starting` |
| +26 s | `running` (probe pending) |
| +32 s (13:44:45) | `running`, `health_probe.healthy: true` |
| 13:45:09 | **read back through the front door** — login with the post-change password → `/`; page `…/page/toltott-kaposzta` **200**; sentence present **2** (negative control **0**); `árvíztűrő tükörfúrógép` present **2**; `/attachments/1` **200, 262 144 B, sha256 equal to the pre-backup upload: YES** |
**DATA: PASS.** The recipe the household deleted at 13:43:07 is back, with its attachment
byte-identical and its Hungarian text intact, 32 s after pressing restore.
Reading the page at 13:45:11, after completion: the one-shot flash is gone and the page shows the
empty form again („Pillanatkép: — Válasszon alkalmazást — · Még nincs mentés felhasználói adattal.").
**CORRECTED 13:46 — the first reading here was wrong.** The page's script polls
`/api/backup/restore-status`, which at 13:46:03 returned `"last":{"op":"restore","stack":"bookstack","ok":true,
"message":"A(z) bookstack: 2 adatkötet és az adatbázis visszaállítva — az alkalmazás újraindult.",
"finished_at":"2026-09-14T13:44:39Z"},"last_recent":true`. So a Hungarian finish message exists and
names what came back; **whether the page shows it is script-rendered and was not observed** (no browser
here). The server-rendered HTML alone shows only the empty form.
## Step 10 — removal, done the way the screens lead
**Harness shortcut, withdrawn as a finding.** At 13:43:36 the harness called
`POST /api/stacks/privatebin/remove` on a **running** app and got **409** `stack "privatebin" is still
running — stop it first before removing` (English). The screens never offer that: for an operational
app `stacks.html:99-102` shows **Frissítés · Újraindítás · Leállítás** and no „Eltávolítás"; the app
page shows none either. Nothing changed on the box (before/after identical, `step10-remove-observe.txt`).
| UTC | act | result |
|---|---|---|
| 13:45:26 | „Leállítás" → `POST /api/stacks/privatebin/stop` | `{"ok":true,"message":"Stack privatebin stop completed"}` (English message; the UI shows its own text) · `stopped` at +6 s |
| 13:45:32 | observe before | volume `privatebin_privatebin_data` ×1 · containers 0 · `/opt/docker/stacks/privatebin/.felhom.yml` · backup dir **40K** |
| 13:45:33 | „Eltávolítás" with every box ticked → `POST …/remove {"remove_hdd_data":false,"remove_backups":true}` | **200** `{"removed":"privatebin","volumes_removed":["privatebin_privatebin_data"],"hdd_paths_removed":[],"hdd_paths_preserved":[],"backup_paths_removed":["/mnt/sys_drive/felhom-data/backups/primary/privatebin (40K)"]}` |
| 13:45:39 | observe after | volumes **0** · containers **0** · backup dir **No such file or directory** · only the catalog template `.felhom.yml` remains (the dialog: „A sablon megmarad") |
| 13:45:4x | front door / API | `paste.` → **404** · restore points `[]` · state `not_deployed`, `deployed=false` |
**PASS — the drive is clean of the app's data and its backups, and the response names each thing it
removed.** (`volumes_removed` is populated here; R-489 recorded `null` over removed volumes on
demo-hp — this box did not reproduce it.)
## Step 12 — status pages, read as a customer would a week later (13:46)
- `/launcher`: tiles **BookStack**, **Filebrowser** (PrivateBin gone — correct).
- `/dashboard`: „3 Futó alkalmazás · 0 Leállítva · 55 Összes alkalmazás" · Memória 1.0 GB / 4.0 GB ·
Rendszer (/) 2.11 GB / 68.7 GB · **Lemezek állapota: QEMU QEMU HARDDISK „Nincs adat" „0 °C"** ·
**„Utolsó mentés: 2026-09-14 13:41"** while `/backups/apps` says **15:41** for the same run → **R-500**
(`dashboard.html:154` formats without the box zone).
- `/monitoring`: „Hub kapcsolat — Kapcsolódva … Utolsó sikeres jelentés: most"; graphs „Még nincsenek
adatok…". The banner „A gazdagép metrikái jelenleg nem elérhetők" appeared in my text extraction,
**but it is `display:none` by default and shown only by script** (`monitoring.html:15`) — **not
evidence; withdrawn.** Whether the host card fills in was not observable without a browser.
- Observation, not filed: „0 °C" beside „Nincs adat" on a virtual disk.
## Evidence off the machine, end of Phase 1 (13:46)
`box-logs-phase1/`: `controller.log` (526 lines), `agent-journal.log` (2461), `bootstrap-journal.log`
(173, pairing code **redacted**), `box-state.txt`. Secret sweep over the copies for the claim code,
passphrase, dashboard password, BookStack password, break-glass credential and installer root password:
**0 each**; control (passphrase planted in a throwaway copy) **1**.
## Accident A1 — power cut (`A1-power-cut.txt`)
| UTC | observable |
|---|---|
| 13:47:31 | before: `felhom-controller:0.242.0` · `bookstack:26.05.2` · `mariadb:12.3` · `filebrowser:1.3.3-stable` · `traefik:v3.6.7`, all healthy · agent 0.130.0 |
| 13:47:33 | `qm stop 330` (hard) |
| 13:48:36 | `qm start 330` (60 s dark) |
| +37 s | appliance answers SSH |
| +2 m 07 s (13:50:43) | hub: `Event from drill0242: controller_started (info) — Controller elindult (0.242.0)` |
| +2 m 9 s | dashboard `/api/health` 200 |
| 13:58:11 | the dashboard session did not survive: `/api/stacks/bookstack` → **401 `authentication required`** (the customer logs in again; the harness loop misread this as unparseable for 8 min — harness fault, stopped) |
| 13:58:33 | after re-login: bookstack **running, healthy**, template images **unchanged**; every container `Up 7 minutes (healthy)`, **same five image tags**; agent 0.130.0 |
| 13:58:36 | BookStack front door: page 200, sentence **2** (control 0), Hungarian **2**, attachment **262 144 B, sha256 equal: YES** |
Hub log across the cut (non-routine lines only): `DR-recipe host-half stored` 15:49:04 CEST,
`controller_started` 15:50:43, `DR-recipe app-half stored` 15:50:44. **No alarm, no warning, no
customer mail event.**
**A1: PASS — every app back on the same version (Slice 3 holds), data intact, no false alarm, ≈2 min
to a working dashboard. Cost to the household: one re-login.**
## Accident A2 — a typo in the code
**Where it can be tried.** The setup code is single-use and this box is already claimed, so the
first-claim screen cannot be re-entered. The login page's „Elfelejtett jelszó" opens the **same
`/claim` form and the same code gate**, titled „Jelszó visszaállítása — Felhom · Add meg az e-mailben
kapott beállító kódot, majd válassz új jelszót." A2 was run there, on the same box. **The pairing-code
typo on the hub's self-bind page was NOT exercised** (H1: no link).
Code: generation 4, minted by H1 at 13:59:30. The typo is the real code with its last letter changed
— exactly one character different, same length (checked, never printed). Limiter, from source
(`claim.go:32-33`, `:170-200`): **5 failures → 15-minute lock, counted per source AND globally.**
| UTC | attempt | result |
|---|---|---|
| 14:00:09 | **typo** | **200**, form re-rendered (not accepted) |
| 14:00:10 | **the right code**, new 24-char password | **302 → `/`** — accepted after the typo |
| 14:00:10 | log in with the new password / the old one | **302** / **200** (old refused) |
| 14:00:10–12 | four more wrong codes (the spent code) | 200 each |
| 14:00:12 | the 5th failure | box: `[WARN] [web] claim: code lockout tripped (source 192.168.0.104) — 15 min` · `Event pushed: claim_lockout (warning) — Túl sok hibás beállító kód — a beállító oldal 15 percre zárolva` |
| 14:00:12 | a 6th attempt, during the lock | 200 |
| 14:00:16 | hub | `Event from drill0242: claim_lockout (warning) …` · **`Operator email sent for drill0242/claim_lockout`** |
**Harness note:** the text filter used on these replies missed the refusal wording, so the on-screen
messages are taken from the reply bodies below, and the plain „Hibás vagy lejárt kód" reading is
repeated after the lock expires.
| 14:15:26 | a wrong code **after** the 15-minute window | **200**, error box **„Hibás vagy lejárt kód"** — the form accepts attempts again |
On-screen wording, read from the reply bodies: during the lock **„Túl sok próbálkozás — próbáld újra
15 perc múlva."**; after it **„Hibás vagy lejárt kód"**. Both Hungarian, both true.
**A2: PASS** — a one-letter typo is refused without harm, the right code is accepted right after it,
the lock is honest about its length and lifts on time. Two properties recorded, not filed: the lock is
**global** as well as per source (`claim.go:188-200`) — five wrong guesses from anywhere lock the real
household out for 15 minutes, by design against guessing; and the lockout e-mail went to the
**operator only** (`Operator email sent for drill0242/claim_lockout`), while the screen tells the
customer.
Binary file not shown.

After

Width:  |  Height:  |  Size: 90 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 89 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 12 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 21 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 6.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.3 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 7.4 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.2 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.2 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.2 KiB

@@ -0,0 +1,47 @@
=== BEFORE 13:43:34
volumes:
privatebin_privatebin_data
containers:
privatebin
stack-dir:
/opt/docker/stacks/privatebin
/opt/docker/stacks/privatebin
/opt/docker/stacks/privatebin
backup-dir:
40K /mnt/sys_drive/felhom-data/backups/primary/privatebin
=== AFTER 13:43:41
volumes:
privatebin_privatebin_data
containers:
privatebin
stack-dir:
/opt/docker/stacks/privatebin
/opt/docker/stacks/privatebin
/opt/docker/stacks/privatebin
backup-dir:
40K /mnt/sys_drive/felhom-data/backups/primary/privatebin
=== BEFORE remove (stopped) 13:45:32
volumes: 1
privatebin_privatebin_data
containers: 0
stack-dir:
total 24
drwxr-xr-x 2 root root 4096 Sep 14 13:45 .
drwxr-xr-x 57 root root 4096 Sep 14 13:23 ..
-rw-r--r-- 1 root root 1914 Sep 14 13:23 .felhom.yml
backup-dir:
40K /mnt/sys_drive/felhom-data/backups/primary/privatebin
other-privatebin-dirs:
/opt/docker/stacks/privatebin
=== AFTER remove 13:45:39
volumes: 0
containers: 0
stack-dir:
total 20
drwxr-xr-x 2 root root 4096 Sep 14 13:45 .
drwxr-xr-x 57 root root 4096 Sep 14 13:23 ..
-rw-r--r-- 1 root root 1914 Sep 14 13:23 .felhom.yml
backup-dir:
du: cannot access '/mnt/sys_drive/felhom-data/backups/primary/privatebin': No such file or directory
other-privatebin-dirs:
/opt/docker/stacks/privatebin
@@ -0,0 +1,40 @@
=== TEARDOWN BEFORE 2026-09-14T14:14:28Z
--- qm list
VMID NAME STATUS MEM(MB) BOOTDISK(GB) PID
330 drill0242-fresh-install running 8192 200.00 2582858
--- pct list
VMID Status Lock Name
9201 running demo-hp
9202 running demo-hp-scratch
--- pvesm status
Name Type Status Total (KiB) Used (KiB) Available (KiB) %
felhom-pbs pbs active 0 0 0 0.00%
local dir active 40453376 24768200 13598060 61.23%
local-lvm lvmthin active 56487936 24950721 31537214 44.17%
nvme-scratch dir active 983379700 19059372 914293716 1.94%
--- /mnt/hdd_1/images
total 16
drwxr-xr-x 4 root root 4096 Sep 14 15:03 .
drwxr-xr-x 9 root root 4096 Sep 13 22:16 ..
drwxr----- 2 root root 4096 Sep 14 15:03 330
drwxr----- 2 root root 4096 Sep 13 22:18 9202
8.6G /mnt/hdd_1/images/330
--- df /mnt/hdd_1
/dev/nvme0n1 1006980812800 19516796928 936236765184 3% /mnt/hdd_1
--- ISO
total 1665368
drwxr-xr-x 2 root root 4096 Sep 14 15:01 .
drwxr-xr-x 4 root root 4096 Aug 21 17:42 ..
-rw-r--r-- 1 root root 1705322496 Sep 14 15:01 felhom-installer-1.26.1-pve9.2-1.iso
--- scratch dir
40
--- vmbr bridges
vmbr0 UP 7c:d3:0a:77:d9:76 <BROADCAST,MULTICAST,UP,LOWER_UP>
vmbr9 UP fe:3f:ab:99:a8:9c <BROADCAST,MULTICAST,UP,LOWER_UP>
--- hub delete-impact
{"deletable":false,"escrow_present":false,"guests":1,"log_bundles":0,"pbs_secret_present":false,"recovery_present":true,"reports":4,"status":"ok","wg_peer_bound":true}
--- hub customers list rows for drill
drill0242
drill0242'">
drill0242.felhom.eu
@@ -0,0 +1,9 @@
VMID NAME STATUS MEM(MB) BOOTDISK(GB) PID
330 drill0242-fresh-install running 8192 200.00 2582858
purging VM 330 from related configurations..
--- after
total 12
drwxr-xr-x 3 root root 4096 Sep 14 16:16 .
drwxr-xr-x 9 root root 4096 Sep 13 22:16 ..
drwxr----- 2 root root 4096 Sep 13 22:18 9202
ls: cannot access '/mnt/hdd_1/images/330': No such file or directory
@@ -0,0 +1,13 @@
ISO present: 0
scratch dir present: 0
Name Type Status Total (KiB) Used (KiB) Available (KiB) %
felhom-pbs pbs active 0 0 0 0.00%
local dir active 40453376 23013832 15352428 56.89%
local-lvm lvmthin active 56487936 24950721 31537214 44.17%
nvme-scratch dir active 983379700 10130532 923222556 1.03%
/dev/nvme0n1 1006980812800 10373664768 945379897344 2% /mnt/hdd_1
VMID Status Lock Name
9201 running demo-hp
9202 running demo-hp-scratch
vmbr0 UP 7c:d3:0a:77:d9:76 <BROADCAST,MULTICAST,UP,LOWER_UP>
vmbr9 UP fe:3f:ab:99:a8:9c <BROADCAST,MULTICAST,UP,LOWER_UP>
+8
View File
@@ -696,6 +696,14 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server`
| **R-488** | **[P3-LOW] `go test ./internal/backup` takes 5½ minutes: 89 off-site tests wait on real clocks.** MEASURED 2026-09-13 (`-v` timings, run alone: 581 tests, 333 s in total, 89 of them ≥ 1 s — `TestOffbox*`, `TestOffbox3a*`, `TestOffboxRun*`, `TestR4xx*` reconstitute fixtures at 3–8 s each). The controller's per-commit gate is therefore ~6 minutes, most of it sleeping, and two concurrent runs of the package looked like a hang. **Fix shape:** the waits are `waitForHealthy`-style polls and retry back-offs with fixed durations; make them seams the fixtures shorten (the R-457 rule: one clock). Not a correctness defect. | **READY — rank P3-LOW; owner: CC** |
| **R-489** | **[P3-LOW] `POST /api/stacks/{name}/remove` reports `volumes_removed: null` over named volumes it DID remove.** MEASURED 2026-09-13 on demo-hp five times (gokapi, actualbudget, adventurelog ×2, glance): `docker compose down --volumes` removed the app's named volumes (`docker volume ls` count 2 → 0) and the response carried `"volumes_removed":null`. The customer's confirmation dialog therefore cannot say what it deleted. Split out of R-474 (closed in v0.240.0 for the backups half). **Fix shape:** list the volumes before `down --volumes`, diff after, and report the difference (`[]` when none, never `null`). **PARTLY SHIPPED in v0.242.0 (`d698ce3`), measured live on 9202 the same night:** the difference is computed and a fresh compose-created volume IS reported (`["opengist_opengist_data"]`), but the listing filters on the compose project LABEL and a volume recreated by a unit restore (`docker volume create <name>`, `restore.go:154`) carries no labels — compose still removes it and the response says `[]` (`audits/v0242-2026-09-14/19-R489-cause.txt`). **Remaining fix:** list by the `<project>_` name prefix as well (union), or label the recreated volume as compose would. | **READY — rank P3-LOW; owner: CC (residual)** |
| **R-492** | **[P3-LOW] `cfg.Paths.HDDPath` is empty on every box and still has readers; delete it.** R-465 audited its six readers and found every one falling back; R-490 (v0.242.0) gave the last one, `systemInfo`, the same fallback. The global now carries no information on any box and its deletion was deferred twice. **Fix shape:** remove the field, its env binding and the readers' fallback branches; a build proves nothing reads it. Next controller release. | **READY — rank P3-LOW; owner: CC** |
| **R-493** | **[P1-HIGH] There are NO customer-facing install instructions, so a volunteer cannot begin — this blocks inviting anyone.** MEASURED 2026-09-14 (drill `audits/DRILL-fresh-install-0242-2026-09-14.md`, Phase 0.2), each source with what was searched: the website's 9 pages carry no mention of the installer, of `iso.felhom.eu`, or of any install step (`iso`, `letolt`, `telepit`); `https://iso.felhom.eu/` and `/index.html` both return **404** — only the exact object name `felhom-installer-1.26.1-pve9.2-1.iso` answers, so the file cannot be found without being told its name; `RUNBOOK-onboarding-draft-v4.md` is an operator-attended script; the R-11 tester one-pager was ruled 2026-07-21 and never written; no `email.md` exists in the workspace; the two hub mails a new customer receives (`Kösd össze a Felhom dobozodat`, `Elindult a Felhom szervered — beállító kód`) assume the box is already installed. **Stopgap written by the drill:** `documentation/runbooks/VOLUNTEER-first-hour.md` (Hungarian, the steps the product really needs, each addition over today listed at its top). **What it needs:** the operator to choose the channel and approve the text. | **WAITING-ON-OPERATOR — rank P1-HIGH; owner: operator (channel + text), CC (draft)** |
| **R-494** | **[P1-HIGH] A new customer's dashboard has NO reachable address unless the operator hand-makes a Cloudflare tunnel — the link in the setup-code mail is dead.** MEASURED 2026-09-14 on a fresh install from the public ISO (drill intervention **I1**): the claim mail points at `https://felhom.drill0242.felhom.eu`; that name has **no A and no AAAA** record (`dig @1.1.1.1`, control `felhom.enkisfelhom.hu` resolves); the hub has **no tunnel- or DNS-creation code** (`hub/internal/cloudflare/` holds only geo-rule removal; `cf_tunnel_token` is a pasted, optional form field, `configs.go:1478`) — day-0 runbook A.1 makes it a manual Cloudflare-dashboard step that nothing on the customer-create page asks for; the box's own split-horizon resolver on the appliance LAN IP answered `google.com` but not the dashboard name at 13:27:39Z; the agent applied the record at **13:27:44Z** (`lanresolver: applied split-horizon record … ip=192.168.0.158`, 3 m 46 s after the controller started), so the box CAN answer the name — **but only to a device that uses the box as its DNS server, and no document, screen or mail tells a household to do that**; the router and the installer-offered DNS answer nothing. The page was reachable only at the guest's LAN address with the name forced (`curl --resolve …:443:192.168.0.158`). **A volunteer could not have done that.** **What it needs:** an operator ruling — the hub creates the tunnel and DNS at customer creation, or the product gives a household a LAN address that works with no DNS change. | **WAITING-ON-OPERATOR — rank P1-HIGH; owner: operator (ruling), CC (build)** |
| **R-495** | **[P2-MEDIUM] The public installer asks a stranger four questions nothing answers, and REFUSES its own default on one of them.** MEASURED 2026-09-14 on `felhom-installer-1.26.1` (drill screens `s04`–`s22`): every screen after the GRUB menu is **English** Proxmox (EULA, disk, locale, password, network, summary); **three disks are offered with no guidance which is the system disk** (the default happened to be right); the administrator e-mail is prefilled `mail@example.invalid`; the hostname is prefilled `pve.example.invalid` and pressing Next on it returns **„Invalid values: hostname does not look valid”** — a volunteer who accepts the defaults cannot continue; at the end, with the stick still in, the default-ticked auto-reboot boots back into the installer. None of this is wrong for Proxmox; all of it is unanswered for a Felhom household. **Fix shape (cheap first):** the volunteer instructions answer each question (done in `runbooks/VOLUNTEER-first-hour.md`); later, prefill hostname and e-mail from the ISO build. | **READY — rank P2-MEDIUM; owner: CC (ISO prefill), operator (instruction text via R-493)** |
| **R-496** | **[P2-MEDIUM] The box's console tells a stranger, in English and FIRST, to open the Proxmox admin page — and calls the owner passphrase „a jelszavadat”.** MEASURED 2026-09-14 (drill screen `s29`): above the Hungarian pairing banner the console prints Proxmox's own `Welcome to the Proxmox Virtual Environment. Please use your web browser to configure this server - connect to: https://192.168.0.134:8006/` — the operator admin UI, which a household must never be sent to; the Felhom banner below says „add meg ezt a kódot és **a jelszavadat**”, while the self-bind mail and page name the same secret **„Tulajdonosi jelmondat”** (R-323 renamed the mail; `scripts/iso/felhom-bootstrap.sh:71-72` was not renamed). **Fix shape:** replace the Proxmox `/etc/issue` block on appliance installs; rename the console word. Both live in `felhom-bootstrap.sh`, a frozen ISO payload (G9), so it ships with the next ISO. | **READY — rank P2-MEDIUM; owner: CC** |
| **R-497** | **[P2-MEDIUM] No product channel ever gives the customer the „Tulajdonosi jelmondat”, yet the self-bind mail says they received it at setup.** MEASURED 2026-09-14: the 5-word phrase is minted at customer creation (`hub/internal/web/configs.go`, `RandomPassphrase(5)`) and shown **only on the operator's customer page**; the self-bind mail (`FormatSelfBindEmail`) says „amelyet a beállításkor kaptál” and the console asks for it; nothing sends it. Day-0 runbook A.2 says the operator must dictate or hand it over — a step that exists only in an operator document. A volunteer whose operator forgets cannot bind the box and is told they already have the phrase. **Fix shape:** the operator's customer-create confirmation says, in one line, to hand this phrase to the customer now; the volunteer instructions say where it comes from (done in `VOLUNTEER-first-hour.md`). | **READY — rank P2-MEDIUM; owner: operator (process), CC (hub copy)** |
| **R-498** | **[P3-LOW] The „Első lépések" on 52 of 53 app pages tell a customer to open a literal `wiki.DOMAIN` — the placeholder is never filled in.** MEASURED 2026-09-14 on a fresh 0.242.0 box (drill step 5): BookStack's app page renders „Nyisd meg a **wiki.DOMAIN** címet a böngészőben", PrivateBin's „Nyisd meg a **paste.DOMAIN** címet". `grep -rl '\.DOMAIN c[íi]m' app-catalog-felhom.eu/templates/*/.felhom.yml` → **52 of 53** templates carry it in `first_steps`; the controller renders the string as text (`internal/stacks/metadata.go`). A stranger reading their first instruction meets a word that is not an address. **Fix shape:** substitute the stack's real `SUBDOMAIN.DOMAIN` at render time (one place in the controller), with a render test per template that fails on a literal `DOMAIN`. | **READY — rank P3-LOW; owner: CC** |
| **R-499** | **[P2-MEDIUM] Every app without a data drive is told its data is „already in the full system backup (PBS)" and there is „nothing to do" — on a box with no PBS, whose only whole-box copy sits on the same disk.** MEASURED 2026-09-14 on a fresh 0.242.0 box with the DR tier off (drill step 7): `GET /stacks/bookstack/backup` renders „Ennek az alkalmazásnak az adatai a belső rendszerlemezen vannak, amelyek **már szerepelnek a teljes rendszermentésben (PBS)** … ehhez az alkalmazáshoz nincs külön teendő." The sentence sits under `{{if not .IsHDDApp}}` in `controller/internal/web/templates/tier2_config.html:20-26` and consults nothing about where the whole-guest backup goes. On the same box `/backups` says, correctly, „Helyi tároló (local)" and „A rendszermentés jelenleg ugyanazon a lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem." **Two pages of one product contradict each other, and the reassuring one is the false one.** **Fix shape:** branch the sentence on the box's actual whole-guest target (PBS vs local, same-disk flag the overview already computes); a render test per branch. | **READY — rank P2-MEDIUM; owner: CC** |
| **R-500** | **[P3-LOW] The dashboard shows the last backup in UTC while every backup page shows it in local time — two different clock times for one backup.** MEASURED 2026-09-14 on a fresh 0.242.0 box (drill step 12): the same backup (`last_run 2026-09-14T13:41:37Z`) reads „Utolsó mentés: **2026-09-14 13:41**" on `/dashboard` and „Utolsó adatbázis mentés: **2026-09-14 15:41** (most)" on `/backups/apps`. Cause, from source: `controller/internal/web/templates/dashboard.html:154` renders `{{.BackupStatus.LastRun.Format "2006-01-02 15:04"}}` with no conversion to the box's zone, while the backup pages go through the zone-aware helpers in `funcmap.go`. A household comparing the two screens sees a backup two hours apart from itself. **Fix shape:** format through the same zone-aware helper; a render test that pins a non-UTC zone and asserts the local hour. | **READY — rank P3-LOW; owner: CC** |
<!-- DUE-CHECKS-BEGIN — machine-readable. Parsed by scripts/due_checks_gate.py.
One row per dated check. The R-number must have a row above. Dates are UTC.
@@ -0,0 +1,158 @@
# Felhom — az első óra (önkéntes tesztelőknek)
> **STOPGAP, written by the 2026-09-14 drill (R-493) — NOT yet sent to anyone.** No customer-facing
> install instruction existed when the drill started, so this is the minimal honest one, built from
> what the product really shows on 0.242.0. The operator chooses the channel and approves the text.
> Hungarian below; this header is for the operator.
>
> **Every step this document adds beyond what exists today** (none of these is written anywhere a
> volunteer can see):
>
> 1. **Where the installer is, by exact file name** — `iso.felhom.eu` has no index page (R-493).
> 2. **That the installer screens are English Proxmox screens**, and what to type on each.
> 3. **A hostname to type** — the installer refuses its own default `pve.example.invalid`.
> 4. **An e-mail to type** — the installer prefills `mail@example.invalid`.
> 5. **To remove the USB stick** at „Installation finished — reboot now?".
> 6. **To ignore the English „Please use your web browser … https://…:8006/" block** on the console —
> that is the Proxmox admin page, not Felhom.
> 7. **That „a jelszavadat" on the console means the 5-word „Tulajdonosi jelmondat"**, and that it
> comes from the operator, not by mail.
> 8. **How to reach the dashboard** — **UNRESOLVED**: the setup-code mail's link does not resolve for
> a new customer unless the operator made a Cloudflare tunnel by hand (R-494). Step 5 below says
> what the operator must do before sending this document.
>
> Operator prerequisites this document silently depends on (§ „Az üzemeltető előtte"):
> create the customer; **hand over the Tulajdonosi jelmondat out of band**; **create the Cloudflare
> tunnel and paste its token** (day-0 runbook A.1) — until R-494 is ruled.
---
## Az üzemeltető előtte (nem az önkéntes feladata)
1. Létrehozza az ügyfelet a hubon (név, e-mail, domain).
2. **Létrehozza a Cloudflare tunnelt és beírja a tokent** az ügyfél adatlapján — enélkül a
vezérlőpult címe nem nyílik meg (R-494).
3. **Személyesen vagy üzenetben átadja a 5 szóból álló „Tulajdonosi jelmondatot".** Ezt semmilyen
e-mail nem tartalmazza.
## Mire lesz szükséged
- Egy gép, amelyen **minden adat törlődik** (a telepítés a kiválasztott lemezt teljesen felülírja).
- Egy legalább 2 GB-os USB-kulcs.
- Hálózati kábel a routeredhez.
- A Felhomtól kapott **Tulajdonosi jelmondat** (5 szó).
- Az e-mail fiókod, amelyet a Felhomnak megadtál.
## 1. A telepítő letöltése (~1 perc)
Töltsd le ezt a fájlt (kb. 1,7 GB):
`https://iso.felhom.eu/felhom-installer-1.26.1-pve9.2-1.iso`
Ellenőrző összeg (SHA-256), ha szeretnéd ellenőrizni:
`f3cc86d5f0ec68bba4155c994b4fa84e208d50209bb6e815636c99e5441059a6`
Írd ki USB-kulcsra (Windows: Rufus, **„DD" módban**; Mac/Linux: balenaEtcher).
## 2. Telepítés (~15 perc, ebből ~3 perc másolás)
Indítsd a gépet az USB-kulcsról. **A telepítő képernyői angolul vannak** — ez rendben van.
| Képernyő | Mit csinálj |
|---|---|
| Felhom logó, két sor | Válaszd a **„Felhom telepítés"** sort (vagy várj, magától elindul) |
| END USER LICENSE AGREEMENT | **I agree** |
| Target harddisk | Válaszd azt a lemezt, **amelyre a rendszer kerüljön**. Ha több lemez van, a legnagyobb nem feltétlenül a jó — a külső adatlemezeket ne válaszd. |
| Country / Timezone / Keyboard | Hagyd így: Hungary, Europe/Budapest, Hungarian |
| Root password | Adj meg egy legalább 8 karakteres jelszót kétszer. **Nem kell megjegyezned** — a Felhom az első indulás után lecseréli. |
| Administrator email | Írd be a saját e-mail címedet (a `mail@example.invalid` helyett) |
| Hostname (FQDN) | **Írd át**, mert az alapértelmezettet nem fogadja el. Írd be: `felhom.<a-te-domained>` (a Felhomtól kapott domain) |
| IP address, Gateway, DNS | Hagyd, ahogy van |
| Summary | **Install** |
| „Installation finished — reboot now?" | **Húzd ki az USB-kulcsot**, majd **Reboot now** |
## 3. Az első indulás (~2 perc)
A képernyőn **először egy angol szöveg** jelenik meg („Welcome to the Proxmox Virtual Environment…
connect to: https://…:8006/"). **Ezzel nincs teendőd — ne nyisd meg.**
Alatta megjelenik a Felhom:
> Felhom — a doboz készen áll, és a párosításra vár.
> Párosító kód: XXX-XXX
Írd fel a **Párosító kódot**.
## 4. A doboz összekötése a fiókoddal (~2 perc)
1. Nyisd meg a **„[Felhom] Kösd össze a Felhom dobozodat"** tárgyú e-mailt, és kattints a benne lévő
hivatkozásra (7 napig érvényes).
2. Add meg:
- a **Párosító kódot** a doboz képernyőjéről;
- a **Tulajdonosi jelmondatot** (5 szó). A doboz képernyője ezt „jelszónak" hívja — ugyanaz.
3. Hagyd bekapcsolva a dobozt. **Kb. 3 perc** múlva megérkezik a következő e-mail.
*(Megjegyzés: a doboz képernyője az összekötés után is a párosító kódot mutatja — ez ismert hiba,
nem kell újra összekötni.)*
## 5. A vezérlőpult beállítása (~1 perc)
1. Nyisd meg a **„[Felhom] Elindult a Felhom szervered — beállító kód"** tárgyú e-mailt.
2. Kattints a benne lévő címre (`https://felhom.<a-te-domained>`).
**⚠ Ha a cím nem nyílik meg, szólj az üzemeltetőnek** — ez most ismert akadály (R-494).
3. „A szerver beállítása" oldalon add meg a **Beállító kódot** (3 szó, pl. `szó-szó-szó`), és válassz
**legalább 12 karakteres** jelszót. Ez lesz a vezérlőpult jelszava.
4. Ha nem jött meg a kód: **„Új kód kérése"** — mindig ugyanarra az e-mail címre érkezik.
## 6. Az első két alkalmazás telepítése (~2 perc)
1. A vezérlőpulton: **Alkalmazások**. Keresd meg például a **BookStack**-et (családi wiki) és a
**PrivateBin**-t (titkosított jegyzet), és nyomd meg a **Telepítés** gombot.
2. A telepítő oldalon csak az **aldomain** a kérdés — hagyd az alapértelmezettet (`wiki`, `paste`).
Az „Automatikusan generált értékek" részt nem kell felírnod.
3. **Telepítés indítása.** A BookStack kb. 1 perc, a PrivateBin kb. 20 másodperc.
## 7. Első belépés az alkalmazásokba
- **BookStack:** az alkalmazás oldalán az „Első lépések" rész a címet `wiki.DOMAIN` alakban írja —
a DOMAIN helyére a saját domained kerül (ismert hiba). Belépés: `admin@admin.com` / `password`.
**Azonnal** változtasd meg: jobb felül a profilod → Beállítások → jelszó és e-mail.
- **PrivateBin:** nincs belépés. Írj be szöveget, **Küldés**, és a kapott linket oszd meg — a kulcs a
linkben van, a szerver nem látja a tartalmat.
## 8. Mentések
- **Biztonsági mentés → Áttekintés:** két sárga figyelmeztetést látsz („Csak egy másolat készül",
„ugyanazon a lemezen van") — **ezek igazak**: amíg nincs második meghajtó vagy távoli mentés, egy
lemezhiba ellen nem véd.
- **Biztonsági mentés → Alkalmazások → Mentés most:** kb. 20 másodperc, utána a dátum frissül.
- *Az egyes alkalmazások „2. mentés beállítása" oldala azt írhatja, hogy az adatok „már szerepelnek a
teljes rendszermentésben (PBS)" — ez nem minden dobozra igaz (ismert hiba). Az Áttekintés oldal a
pontos.*
## 9. Visszaállítás
**Biztonsági mentés → Visszaállítás:** válaszd az alkalmazást és a mentést, pipáld be a „Megértettem"
négyzetet, **Visszaállítás indítása**. Az alkalmazás kb. fél percre leáll, majd az utolsó mentés
állapotával indul újra.
## 10. Alkalmazás eltávolítása
**Alkalmazások:** előbb **Leállítás**, utána megjelenik az **Eltávolítás**. A párbeszédablak felsorolja,
mi törlődik mindenképp, és bepipálhatod a mentések törlését is.
## 11. Áramszünet
Ha elmegy az áram, a doboz magától visszaindul, kb. 2 perc múlva minden alkalmazás ugyanazon a
verzión fut, amelyen előtte. A vezérlőpultba újra be kell jelentkezned.
## 12. Ha elgépelted a kódot
A beállító oldal „Hibás vagy lejárt kód" üzenettel visszadobja — írd be újra. **Öt** hibás próbálkozás
után 15 percre zárol („Túl sok próbálkozás — próbáld újra 15 perc múlva."). Új kódot a
„Nem kaptad meg a kódot? Új kód kérése" linkkel kérhetsz, és a bejelentkező oldal
„Elfelejtett jelszó" linkje ugyanide vezet.
## Ha elakadsz
Írj a **support@felhom.eu** címre, és ha tudsz, küldj képernyőképet.
@@ -0,0 +1 @@
pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve)
@@ -0,0 +1,21 @@
=== preconditions 2026-09-14T12:58:57Z ===
/dev/sda1 9.1T 3.1T 5.5T 37% /mnt/5_hdd
/dev/sdb1 445G 218G 205G 52% /
felhom-controller clean=[] HEAD=406755f origin=406755f
felhom.eu clean=[?? documentation/tests/golden-0.242.0-2026-09-14/;] HEAD=41590f8 origin=41590f8
felhom-agent clean=[?? scripts/__pycache__/;] HEAD=4586f0f origin=4586f0f
controller CHANGELOG top: ## v0.242.0 — a removed app is listed with its kept backup, and five small ones (2026-09-13/14, R-487 / R-49
MinAgent line in the top entry: MinAgent: 0.129.0** (unchanged)
controller image 0.242.0 in registry: HTTP 200
404 pre-gate on the golden package: HTTP 404
control — the 0.236.0 package that DOES exist: HTTP 200
=== drill VM ===
Snapshot list:
ID TAG VM_SIZE DATE VM_CLOCK ICOUNT
1 virgin 0 B 2026-07-03 14:12:15 0000:00:00.000 0
no qemu running
=== bake script fingerprint on DooPlex ===
7b0fb5cf082fa3301a45578d1624e375d205b4e538d602e7d198a015e573b6a1 felhom-agent/configs/build-golden.sh
v3.0.0
@@ -0,0 +1,15 @@
=== pveam update (the virgin snapshot's INDEX is stale too) ===
update successful
debian-13-standard_13.6-1_arm64.tar.zst
calculating checksum...OK, checksum verified
download of 'http://download.proxmox.com/images/system/debian-13-standard_13.6-1_arm64.tar.zst' to '/var/lib/vz/template/cache/debian-13-standard_13.6-1_arm64.tar.zst' finished
=== bake script + token, file -> file ===
in the VM: 7b0fb5cf082fa3301a45578d1624e375d205b4e538d602e7d198a015e573b6a1
DooPlex : 7b0fb5cf082fa3301a45578d1624e375d205b4e538d602e7d198a015e573b6a1
=== CORRECTION: my first pick (sort -V | tail -1) selected the ARM64 template. Fetched amd64 explicitly, arm64 removed ===
system debian-13-standard_13.6-1_amd64.tar.zst
system debian-13-standard_13.6-1_arm64.tar.zst
download of 'http://download.proxmox.com/images/system/debian-13-standard_13.6-1_amd64.tar.zst' to '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst' finished
debian-13-standard_13.6-1_amd64.tar.zst
@@ -0,0 +1,6 @@
Running as unit: golden-bake.service; invocation ID: 698cd39c9c444febb262cdd8c42f1142
=== token-leak check on the unit properties (must be 0) ===
0
=== and the grep is PROVEN to work (must be 1) ===
1
active
@@ -0,0 +1,18 @@
=== acceptance markers, counted on the COMMITTED log ===
docker OK (overlay2 : 1
including mount point rootfs : 1
including mount point mp0 : 1
upload OK (HTTP 201) : 1
--- must be ZERO ---
excluding : 0
FATAL : 0
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
GOLDEN_VERSION=0.242.0
GOLDEN_SHA256=3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8
=== token-leak grep on the committed log (must be 0) ===
0
=== control: token appended to a throwaway copy (must be 1) ===
1
copy shredded: yes
@@ -0,0 +1,5 @@
Logical volume "vm-9100-disk-1" successfully removed.
purging CT 9100 from related configurations..
leftovers in the VM: 0
qemu exited
1 virgin 0 B 2026-07-03 14:12:15 0000:00:00.000 0
@@ -0,0 +1,8 @@
=== READER 2: the ROUND TRIP — hash the DOWNLOADED bytes, not the bake's printout ===
http=200 bytes=653288425
downloaded sha256: 3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8
bake printed : 3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8
=== THE DELIVERED ARTIFACT MUST NAME ITS OWN CONTROLLER ===
gitea.dooplex.hu/admin/felhom-controller:0.242.0
docker store entries in the archive: 19382
@@ -0,0 +1,7 @@
=== READER 3: the hub Day-0 dropdown (reads Gitea on its own path) 2026-09-14T13:08:02Z ===
0.242.0 sha=3ab480ddb7c1e690492db1a5
=== current vouch before the change ===
selected>0.130.0
selected>0.236.0
name="min_agent" value="0.129.0"
min_controller_version" value="0.242.0"
@@ -0,0 +1,11 @@
=== VOUCH: the THREE fields, moved together 2026-09-14T13:08:41Z ===
golden_version 0.236.0 -> 0.242.0 (this bake carries SIX releases: 0.237.0..0.242.0 were never baked)
agent_version 0.130.0 -> 0.130.0 UNCHANGED, already >= MinAgent
min_agent 0.129.0 -> 0.129.0 UNCHANGED — v0.242.0's header states MinAgent 0.129.0 (unchanged)
min_agent (0.129.0) <= agent_version (0.130.0): NOT the R-216 shape
golden_sha256 sent = 3ab480ddb7c1e690… (must equal the bake's 3ab480ddb7c1e690…)
wrapper_sha256 and agent_sha256 re-sent exactly as the page rendered them
POST HTTP/1.1 303 See Other
Location: /configuration?flash=artifacts_set
(read from -D, never %{redirect_url} — R-132)
@@ -0,0 +1,7 @@
=== RE-READ after the vouch 2026-09-14T13:09:01Z ===
selected 0.130.0 sha=a56a92a7bd68f5b4…
selected 0.242.0 sha=3ab480ddb7c1e690…
name="min_agent" value="0.129.0"
min_controller_version" value="0.242.0"
R-120 refusal banner (golden_behind_fleet) present: 0
floor-above-golden hint still naming 0.236.0: 0
@@ -0,0 +1,66 @@
# Golden bake 0.242.0 — 2026-09-14
Baked, published, round-trip verified and **vouched**. The fleet floor was already 0.242.0 (raised by
the v0.242.0 release under hub v0.112.0's declared-MinAgent rule), so it did not move.
**This bake carries SIX releases: 0.237.0 … 0.242.0 were never baked.** It was baked because the
cadence rule says a golden comes **before any drill or fresh install** (R-468, `RUNBOOK-manual-build.md`
§4.2) — the drill it precedes is `audits/DRILL-fresh-install-0242-2026-09-14.md`.
| | |
|---|---|
| `GOLDEN_SHA256` | `3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8` |
| size | **653 288 425 B** |
| baked controller | `gitea.dooplex.hu/admin/felhom-controller:0.242.0` |
| `MinAgent` | **0.129.0** — stated in v0.242.0's own header ("unchanged") |
| script | `build-golden.sh v3.0.0`, sha `7b0fb5cf…73b6a1`, **compared across the hop** (`02-template.txt`) |
| template | `debian-13-standard_13.6-1_amd64.tar.zst`, after `pveam update` |
## Acceptance markers — counted on the COMMITTED log (`04-markers.txt`)
```
docker OK (overlay2 : 1
including mount point rootfs : 1
including mount point mp0 : 1
upload OK (HTTP 201) : 1
--- must be ZERO ---
excluding : 0
FATAL : 0
```
## Three independent readers agreed before anything was vouched
1. **The bake** printed `GOLDEN_SHA256=3ab480dd…e6d8`.
2. **The round trip** (`07-roundtrip.txt`) — `HTTP 200`, **653 288 425 B**, sha `3ab480dd…e6d8`, hashed
from the **downloaded** bytes. The archive's `./etc/felhom-controller-image` reads
`gitea.dooplex.hu/admin/felhom-controller:0.242.0`, with **19 382** entries under `var/lib/felhom/docker/`.
3. **The hub's Day-0 dropdown** (`08-hub-before-vouch.txt`): `0.242.0 sha=3ab480ddb7c1e690492db1a5`.
## Pre-gates, each proven able to see something first (`01-preconditions.txt`, `03-bake-launch.txt`)
| gate | result | control |
|---|---|---|
| 404 pre-gate | `HTTP 404` for 0.242.0 before the bake | the 0.236.0 package returns `HTTP 200` on the same URL shape |
| token-leak grep on the committed log | **0** | token appended to a throwaway copy greps **1**; copy `shred -u`'d |
| token off every command line | unit properties grep **0** | the same seeded control returns **1** |
## A slip, recorded (`02-template.txt`)
My first template pick (`pveam available | … | sort -V | tail -1`) selected the **arm64** image, which
sorts after amd64. Caught on read-back before the bake started; amd64 fetched by exact name, arm64
deleted. **The runbook's step 2 says "list the current one" — list and pick by the `_amd64` suffix.**
## The vouch — three fields, only one moved (`09-vouch.txt`, `11-vouch-verified.txt`)
| field | before | after |
|---|---|---|
| `golden_version` | 0.236.0 | **0.242.0** |
| `agent_version` | 0.130.0 | 0.130.0 |
| `min_agent` | 0.129.0 | 0.129.0 |
`POST /configuration/artifacts` → `303 flash=artifacts_set`; re-read: golden `0.242.0` selected with
sha `3ab480dd…`, R-120 refusal banner **absent**, floor `0.242.0`.
## Teardown (`05-teardown.txt`)
`pct destroy 9100 --purge`; token, runner, script and log `shred -u`'d **after** the log was copied
out (leftovers 0); `poweroff`; qemu confirmed exited with `ps -eo comm`; `qemu-img snapshot -a virgin`.
@@ -0,0 +1,327 @@
[golden] build-golden.sh v3.0.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.242.0
[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) …
Logical volume "vm-9100-disk-0" created.
Logical volume pve/vm-9100-disk-0 changed.
Creating filesystem with 8388608 4k blocks and 2097152 inodes
Filesystem UUID: 8d241ac1-a7a5-4afc-b535-cdffbf45a7f6
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
4096000, 7962624
Logical volume "vm-9100-disk-1" created.
Logical volume pve/vm-9100-disk-1 changed.
Creating filesystem with 6291456 4k blocks and 1572864 inodes
Filesystem UUID: 4c854580-82f6-47ac-a175-58097f5b8ce8
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst'
Total bytes read: 553512960 (528MiB, 126MiB/s)
Detected container architecture: amd64
Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ...
done: SHA256:UaX849k5SF+Yd4VvG6WRI9mvCgXU4ws/vmioJ476F6s root@felhom-golden
Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ...
done: SHA256:FjLrA0XCrZSWPHlW7qFlhqUGVeIP8j4AuGih9DvQr9g root@felhom-golden
Creating SSH host key 'ssh_host_rsa_key' - this may take some time ...
done: SHA256:BYjK6pA/0gZgIGG/Wt85qHV5njWqC5/yA137BnEXilk root@felhom-golden
[golden] starting + installing Docker (official repo, trixie channel) …
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation …
[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds …
[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) …
Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
4f55086f7dd0: Pulling fs layer
4f55086f7dd0: Verifying Checksum
4f55086f7dd0: Download complete
4f55086f7dd0: Pull complete
Digest: sha256:5e23090353324d887c48ad5e5c56d294eab81588df9605b07d1afe895f9cc8f8
Status: Downloaded newer image for hello-world:latest
docker OK (overlay2; data-root /var/lib/docker)
/var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4
/mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4
both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576
[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.242.0 (no registry cred at deploy) …
WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'.
Configure a credential helper to remove this warning. See
https://docs.docker.com/go/credential-store/
0.242.0: Pulling from admin/felhom-controller
a8ac7f6c67ab: Pulling fs layer
bf30769d36e7: Pulling fs layer
044b66fbe46c: Pulling fs layer
b5c41a28e83f: Pulling fs layer
12b862854588: Pulling fs layer
117a0628e10f: Pulling fs layer
b5c41a28e83f: Waiting
12b862854588: Waiting
117a0628e10f: Waiting
a8ac7f6c67ab: Verifying Checksum
a8ac7f6c67ab: Download complete
b5c41a28e83f: Verifying Checksum
b5c41a28e83f: Download complete
044b66fbe46c: Verifying Checksum
044b66fbe46c: Download complete
12b862854588: Verifying Checksum
12b862854588: Download complete
117a0628e10f: Verifying Checksum
117a0628e10f: Download complete
bf30769d36e7: Verifying Checksum
bf30769d36e7: Download complete
a8ac7f6c67ab: Pull complete
bf30769d36e7: Pull complete
044b66fbe46c: Pull complete
b5c41a28e83f: Pull complete
12b862854588: Pull complete
117a0628e10f: Pull complete
Digest: sha256:4dc1b2a95c9f4b15395b897c74393e57dc6c33ff1f2a20d8adec01ce9b99d5e2
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.242.0
gitea.dooplex.hu/admin/felhom-controller:0.242.0
[golden] asking the controller which infra images it manages …
[golden] baking infra images (4): traefik:v3.6.7 cloudflare/cloudflared:2026.6.0 gtstef/filebrowser:1.3.3-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 …
v3.6.7: Pulling from library/traefik
589002ba0eae: Pulling fs layer
ef63511ea6cc: Pulling fs layer
0738e5cb835e: Pulling fs layer
3e6813f70c64: Pulling fs layer
3e6813f70c64: Waiting
589002ba0eae: Verifying Checksum
589002ba0eae: Download complete
ef63511ea6cc: Verifying Checksum
ef63511ea6cc: Download complete
3e6813f70c64: Verifying Checksum
3e6813f70c64: Download complete
0738e5cb835e: Verifying Checksum
0738e5cb835e: Download complete
589002ba0eae: Pull complete
ef63511ea6cc: Pull complete
0738e5cb835e: Pull complete
3e6813f70c64: Pull complete
Digest: sha256:a9890c898f379c1905ee5b28342f6b408dc863f08db2dab20e46c267d1ff463a
Status: Downloaded newer image for traefik:v3.6.7
docker.io/library/traefik:v3.6.7
2026.6.0: Pulling from cloudflare/cloudflared
47de5dd0b812: Pulling fs layer
c172f21841df: Pulling fs layer
99515e7b4d35: Pulling fs layer
99ba982a9142: Pulling fs layer
d6b1b89eccac: Pulling fs layer
2780920e5dbf: Pulling fs layer
7c12895b777b: Pulling fs layer
3214acf345c0: Pulling fs layer
52630fc75a18: Pulling fs layer
dd64bf2dd177: Pulling fs layer
b839dfae01f6: Pulling fs layer
ebddc55facdc: Pulling fs layer
bdfd7f7e5bf6: Pulling fs layer
2d4d7adf6272: Pulling fs layer
40008157d8d2: Pulling fs layer
bd8962e29291: Pulling fs layer
cac2ae0193cb: Pulling fs layer
74d1dac84ecc: Pulling fs layer
99ba982a9142: Waiting
d6b1b89eccac: Waiting
2780920e5dbf: Waiting
7c12895b777b: Waiting
3214acf345c0: Waiting
52630fc75a18: Waiting
dd64bf2dd177: Waiting
b839dfae01f6: Waiting
ebddc55facdc: Waiting
bdfd7f7e5bf6: Waiting
2d4d7adf6272: Waiting
40008157d8d2: Waiting
bd8962e29291: Waiting
cac2ae0193cb: Waiting
74d1dac84ecc: Waiting
47de5dd0b812: Verifying Checksum
47de5dd0b812: Download complete
99515e7b4d35: Verifying Checksum
99515e7b4d35: Download complete
c172f21841df: Verifying Checksum
c172f21841df: Download complete
99ba982a9142: Download complete
d6b1b89eccac: Verifying Checksum
d6b1b89eccac: Download complete
2780920e5dbf: Verifying Checksum
2780920e5dbf: Download complete
7c12895b777b: Verifying Checksum
7c12895b777b: Download complete
47de5dd0b812: Pull complete
3214acf345c0: Verifying Checksum
3214acf345c0: Download complete
52630fc75a18: Verifying Checksum
52630fc75a18: Download complete
dd64bf2dd177: Verifying Checksum
dd64bf2dd177: Download complete
b839dfae01f6: Verifying Checksum
b839dfae01f6: Download complete
ebddc55facdc: Verifying Checksum
ebddc55facdc: Download complete
bdfd7f7e5bf6: Verifying Checksum
bdfd7f7e5bf6: Download complete
c172f21841df: Pull complete
40008157d8d2: Verifying Checksum
40008157d8d2: Download complete
bd8962e29291: Verifying Checksum
bd8962e29291: Download complete
cac2ae0193cb: Verifying Checksum
cac2ae0193cb: Download complete
74d1dac84ecc: Verifying Checksum
74d1dac84ecc: Download complete
2d4d7adf6272: Verifying Checksum
2d4d7adf6272: Download complete
99515e7b4d35: Pull complete
99ba982a9142: Pull complete
d6b1b89eccac: Pull complete
2780920e5dbf: Pull complete
7c12895b777b: Pull complete
3214acf345c0: Pull complete
52630fc75a18: Pull complete
dd64bf2dd177: Pull complete
b839dfae01f6: Pull complete
ebddc55facdc: Pull complete
bdfd7f7e5bf6: Pull complete
2d4d7adf6272: Pull complete
40008157d8d2: Pull complete
bd8962e29291: Pull complete
cac2ae0193cb: Pull complete
74d1dac84ecc: Pull complete
Digest: sha256:ba461b8aa9c042156dbd39c38657fe7431bafa063220eab8d5330a523863da9f
Status: Downloaded newer image for cloudflare/cloudflared:2026.6.0
docker.io/cloudflare/cloudflared:2026.6.0
1.3.3-stable: Pulling from gtstef/filebrowser
6a0ac1617861: Pulling fs layer
ef8806083e82: Pulling fs layer
b74107c861c7: Pulling fs layer
adc935def003: Pulling fs layer
4f4fb700ef54: Pulling fs layer
18695ccc900a: Pulling fs layer
45d119d5c397: Pulling fs layer
dac52db4fc51: Pulling fs layer
6d598f86b2f2: Pulling fs layer
8aa349c8396c: Pulling fs layer
dac52db4fc51: Waiting
6d598f86b2f2: Waiting
8aa349c8396c: Waiting
adc935def003: Waiting
4f4fb700ef54: Waiting
18695ccc900a: Waiting
45d119d5c397: Waiting
6a0ac1617861: Download complete
adc935def003: Verifying Checksum
adc935def003: Download complete
4f4fb700ef54: Verifying Checksum
4f4fb700ef54: Download complete
b74107c861c7: Verifying Checksum
b74107c861c7: Download complete
45d119d5c397: Verifying Checksum
45d119d5c397: Download complete
6a0ac1617861: Pull complete
dac52db4fc51: Verifying Checksum
dac52db4fc51: Download complete
18695ccc900a: Verifying Checksum
18695ccc900a: Download complete
6d598f86b2f2: Verifying Checksum
6d598f86b2f2: Download complete
ef8806083e82: Verifying Checksum
ef8806083e82: Download complete
8aa349c8396c: Verifying Checksum
8aa349c8396c: Download complete
ef8806083e82: Pull complete
b74107c861c7: Pull complete
adc935def003: Pull complete
4f4fb700ef54: Pull complete
18695ccc900a: Pull complete
45d119d5c397: Pull complete
dac52db4fc51: Pull complete
6d598f86b2f2: Pull complete
8aa349c8396c: Pull complete
Digest: sha256:eb3733681db8757412632c61a99ad656f0d94ed6781bb2ea114b4d70babab78c
Status: Downloaded newer image for gtstef/filebrowser:1.3.3-stable
docker.io/gtstef/filebrowser:1.3.3-stable
1.1.0: Pulling from admin/felhom-samba
897d797d2723: Pulling fs layer
3051591aa250: Pulling fs layer
ce57a3f93416: Pulling fs layer
fb94eeec2fe1: Pulling fs layer
fb94eeec2fe1: Waiting
ce57a3f93416: Verifying Checksum
ce57a3f93416: Download complete
fb94eeec2fe1: Verifying Checksum
fb94eeec2fe1: Download complete
897d797d2723: Verifying Checksum
897d797d2723: Download complete
3051591aa250: Verifying Checksum
3051591aa250: Download complete
897d797d2723: Pull complete
3051591aa250: Pull complete
ce57a3f93416: Pull complete
fb94eeec2fe1: Pull complete
Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0
gitea.dooplex.hu/admin/felhom-samba:1.1.0
[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'.
[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'.
[golden] baking the first-boot SSH host-key regeneration unit (F3) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'.
[golden] identity-clean + minimize …
[golden] stop + archive …
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
INFO: archive file size: 623MB
INFO: Finished Backup of VM 9100 (00:00:38)
[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_09_14-15_05_26.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive)
[golden] publishing golden (653288425 bytes, sha256 3ab480ddb7c1e690…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.242.0/golden.tar.zst
[golden] pre-delete existing: HTTP 404 (404/204 expected)
[golden] upload OK (HTTP 201)
GOLDEN_VERSION=0.242.0
GOLDEN_SHA256=3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8
[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.242.0 / 3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8
[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge)