docs(pilot): GL-6 Phase 6 — appliance reinstall + drive re-enroll + backup green

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
2026-07-08 16:01:55 +02:00
parent 089fa70bbe
commit 3d91ce8fe3
+31 -1
View File
@@ -301,6 +301,36 @@ Real `--uninstall --vmid 9201` (typed confirm), no busy prop this time.
legacy naming) survive the `.bak-*` glob — historical cruft, not on a real customer box; a fix
could widen the glob to `.v*.bak`.
## Gate 5 — [Viktor]: <pending>
## Gate 5 — [Viktor]: **GO** — clean byo exit, data intact 2nd time.
**6b — return to normal.**
- **Drive re-enrolled (CC-driven UI):** `felhom-usb` → Adattárolók **Aktív**, ext4 /dev/sdd1
[/felhom-data]; **witness `7b00bc35…` intact** in-guest (additive, 3rd data-intact proof).
(First click collided with the in-progress snapshot backup and no-op'd; retry after the backup
registered it — minor UI race worth a note. Only felhom-usb re-enrolled; flash/teszt left for
Viktor's demo curation.)
- **Manual backup + restore-test GREEN:** `selftest=backup OK (crash-consistent=true)` →
restore-test **`mount_parity: ok`** (29s — small: fresh install, no apps/drive-data yet).
- Controller + traefik + cloudflared + filebrowser all Up healthy; dashboard HTTP 200; hub reporting.
**Observation:** during the snapshot vzdump the dashboard briefly flashed "Protected container not
running: traefik/cloudflared/filebrowser" — a transient false-positive of the container monitor
during the backup freeze (cosmetic; cleared when the backup finished).
- **Viktor's ongoing return-to-normal (not drill blockers):** redeploy the demo apps (his Phase-0
choice: fresh redeploy); set the dashboard password (deferred to GL-7); update/align LAN DNS
(the re-provision changed the guest IP .105→.139 — a manual Pi-hole entry goes stale; rely on the
appliance lan_resolver or a reserved DHCP lease — GL-7 note).
## Phase 6 — appliance-mode reinstall (the demo returns to normal life)
**6a — appliance install: SUCCESS, single-shot.** `--mode appliance … --allow-new-leaf`.
- **4b/8 break-glass RAN** (appliance): `root@pam password set + vaulted to the hub` + break-glass
layers 1+2 installed — the recovery credential is in the hub (operator-retrievable). (SSH key
access unaffected.)
- verify green: pool member, all 4 scoped-ACL grants (user+token), **`authz signers: 2`**, controller
Up healthy 0.103.0, Day-0 provision SUCCESS.
- **Bonus: this ran in ONE shot** (vs the byo install's 4 resumes on v1.11.2) — the **v1.11.3 F4 fix
live-proven on a real end-to-end install**, not just the dry proof.
*(Phases 36 appended as they run.)*