diff --git a/documentation/audits/evidence-bignight-2026-09-14/api-disks-candidates-after-claim.json b/documentation/audits/evidence-bignight-2026-09-14/api-disks-candidates-after-claim.json new file mode 100644 index 00000000..beac719d --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/api-disks-candidates-after-claim.json @@ -0,0 +1 @@ +{"data":{"vmid":9201,"initialize":[{"device":"/dev/sdb","size_bytes":107374182400,"model":"QEMU HARDDISK","data_bearing":false,"mountable":false}],"attach":[{"device":"/dev/mapper/pve-vm--9201--disk--1","size_bytes":0,"fstype":"ext4","data_bearing":true,"mountable":true,"mount_source":"/mnt/sys_drive","already_mounted":true}]},"ok":true} diff --git a/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/agent-journal.txt b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/agent-journal.txt new file mode 100644 index 00000000..6fd131fa --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/agent-journal.txt @@ -0,0 +1,300 @@ +Sep 14 20:11:44 felhom sudo[17690]: pam_unix(sudo:session): session closed for user root +Sep 14 20:11:44 felhom sudo[17696]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- pgrep -x dhclient +Sep 14 20:11:44 felhom sudo[17696]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:11:45 felhom sudo[17696]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17818]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:01 felhom sudo[17818]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17818]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17821]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:01 felhom sudo[17821]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17821]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17824]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:12:01 felhom sudo[17824]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17824]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17831]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:01 felhom sudo[17831]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17831]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17834]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:01 felhom sudo[17834]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17834]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17841]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:01 felhom sudo[17841]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17841]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17844]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:01 felhom sudo[17844]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17844]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17847]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:12:01 felhom sudo[17847]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:01 felhom sudo[17847]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:01 felhom sudo[17854]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:01 felhom sudo[17854]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:02 felhom sudo[17854]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:02 felhom sudo[17857]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:02 felhom sudo[17857]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:02 felhom sudo[17857]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:02 felhom sudo[17860]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:12:02 felhom sudo[17860]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:02 felhom sudo[17860]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:21 felhom sudo[17976]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:12:21 felhom sudo[17976]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:21 felhom sudo[17976]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:21 felhom sudo[17983]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:21 felhom sudo[17983]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:21 felhom sudo[17983]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:21 felhom sudo[17987]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:21 felhom sudo[17987]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:21 felhom sudo[17987]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:31 felhom sudo[18031]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:31 felhom sudo[18031]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:31 felhom sudo[18031]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:31 felhom sudo[18034]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:31 felhom sudo[18034]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:31 felhom sudo[18034]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:31 felhom sudo[18037]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:12:31 felhom sudo[18037]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:31 felhom sudo[18037]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:31 felhom sudo[18044]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:31 felhom sudo[18044]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:31 felhom sudo[18044]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:32 felhom sudo[18047]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:32 felhom sudo[18047]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:32 felhom sudo[18047]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:32 felhom sudo[18050]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:12:32 felhom sudo[18050]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:32 felhom sudo[18050]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:41 felhom sudo[18136]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:12:41 felhom sudo[18136]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:41 felhom sudo[18136]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:41 felhom felhom-agent[4303]: time=2026-09-14T20:12:41.471+02:00 level=INFO msg="stale-lock: scanning pool guests" pool=felhom listed=1 scanned=1 +Sep 14 20:12:41 felhom sudo[18144]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- ip -4 -o addr show dev eth0 +Sep 14 20:12:41 felhom sudo[18144]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:41 felhom sudo[18150]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:41 felhom sudo[18150]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:41 felhom felhom-agent[4303]: time=2026-09-14T20:12:41.618+02:00 level=INFO msg="stale-lock: scanning pool guests" pool=felhom listed=1 scanned=1 +Sep 14 20:12:41 felhom sudo[18150]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:41 felhom sudo[18155]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:41 felhom sudo[18155]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:41 felhom sudo[18155]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18159]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/nft list set inet felhom_oob ssh_port +Sep 14 20:12:42 felhom sudo[18159]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18159]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18162]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/nft list set inet felhom_oob operator_ips +Sep 14 20:12:42 felhom sudo[18162]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18162]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18169]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/wg show wg-felhom latest-handshakes +Sep 14 20:12:42 felhom sudo[18169]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18169]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18144]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18178]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- ip route show default +Sep 14 20:12:42 felhom sudo[18178]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18184]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:42 felhom sudo[18184]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18184]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:42 felhom sudo[18187]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:42 felhom sudo[18187]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:42 felhom sudo[18187]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18328]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/wg show wg-felhom latest-handshakes +Sep 14 20:12:43 felhom sudo[18328]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18328]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18333]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/sshd -T -f /etc/felhom-sshd/sshd_config +Sep 14 20:12:43 felhom sudo[18333]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18333]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18178]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18339]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/sshd -t -f /etc/felhom-sshd/sshd_config +Sep 14 20:12:43 felhom sudo[18339]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18340]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- cat /etc/network/interfaces +Sep 14 20:12:43 felhom sudo[18340]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18339]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18346]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/wg show wg-felhom latest-handshakes +Sep 14 20:12:43 felhom sudo[18346]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18346]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:43 felhom sudo[18349]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/nft list set inet felhom_oob operator_ips +Sep 14 20:12:43 felhom sudo[18349]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:43 felhom sudo[18349]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:44 felhom sudo[18340]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:44 felhom sudo[18355]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- pgrep -x dhclient +Sep 14 20:12:44 felhom sudo[18355]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:45 felhom sudo[18355]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:46 felhom sudo[18388]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- ip -4 -o addr show dev eth0 +Sep 14 20:12:46 felhom sudo[18388]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:47 felhom sudo[18388]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:47 felhom sudo[18394]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct exec 9201 -- docker exec felhom-controller cat /opt/docker/felhom-controller/controller.yaml +Sep 14 20:12:47 felhom sudo[18394]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:48 felhom sudo[18394]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18463]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/blkid -p -o export /dev/sdb +Sep 14 20:12:57 felhom sudo[18463]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18463]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18466]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sdb +Sep 14 20:12:57 felhom sudo[18466]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18466]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18469]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/blkid -p -o export /dev/sdb +Sep 14 20:12:57 felhom sudo[18469]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18469]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18472]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sdb +Sep 14 20:12:57 felhom sudo[18472]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18472]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18475]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sdb +Sep 14 20:12:57 felhom sudo[18475]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18475]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18478]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pvs --reportformat json --noheadings -o pv_name +Sep 14 20:12:57 felhom sudo[18478]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18478]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18481]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/zpool status -P +Sep 14 20:12:57 felhom sudo[18481]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18481]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18484]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/local/sbin/felhom-mkfs-guarded /dev/sdb ext4 +Sep 14 20:12:57 felhom sudo[18484]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18484]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom felhom-agent[4303]: time=2026-09-14T20:12:57.532+02:00 level=INFO msg="storage: formatted device" device=/dev/sdb fstype=ext4 +Sep 14 20:12:57 felhom sudo[18510]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:57 felhom sudo[18510]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18510]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18513]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:57 felhom sudo[18513]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18513]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18516]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:12:57 felhom sudo[18516]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18516]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18519]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sda +Sep 14 20:12:57 felhom sudo[18519]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18519]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18522]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pvs --reportformat json --noheadings -o pv_name +Sep 14 20:12:57 felhom sudo[18522]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18522]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18525]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/zpool status -P +Sep 14 20:12:57 felhom sudo[18525]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18525]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18528]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sdb +Sep 14 20:12:57 felhom sudo[18528]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18528]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18531]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pvs --reportformat json --noheadings -o pv_name +Sep 14 20:12:57 felhom sudo[18531]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18531]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18534]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/zpool status -P +Sep 14 20:12:57 felhom sudo[18534]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18534]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18537]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lsblk -J -o NAME,FSTYPE,PTTYPE,MOUNTPOINT /dev/sdb +Sep 14 20:12:57 felhom sudo[18537]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18537]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18540]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/units/mnt-hdd_1.mount /etc/systemd/system/mnt-hdd_1.mount +Sep 14 20:12:57 felhom sudo[18540]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:57 felhom sudo[18540]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:57 felhom sudo[18543]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/systemctl daemon-reload +Sep 14 20:12:57 felhom sudo[18543]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18543]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18579]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/systemctl enable --now -- mnt-hdd_1.mount +Sep 14 20:12:58 felhom sudo[18579]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18579]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom felhom-agent[4303]: time=2026-09-14T20:12:58.582+02:00 level=INFO msg="storage: ensured mount" name=c4b530fd-d410-424c-917e-c8ecfdde9d8b where=/mnt/hdd_1 unit=mnt-hdd_1.mount +Sep 14 20:12:58 felhom felhom-agent[4303]: time=2026-09-14T20:12:58.582+02:00 level=INFO msg="local-api: disk assigned (host mount ensured)" vmid=9201 where=/mnt/hdd_1 +Sep 14 20:12:58 felhom sudo[18627]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:12:58 felhom sudo[18627]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18627]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18630]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/hdd_1/felhom-data +Sep 14 20:12:58 felhom sudo[18630]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18630]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18633]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown 100000:100000 /mnt/hdd_1/felhom-data +Sep 14 20:12:58 felhom sudo[18633]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18633]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18636]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives/hdd_1 +Sep 14 20:12:58 felhom sudo[18636]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18636]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18639]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mount --bind /mnt/hdd_1/felhom-data /mnt/felhom-drives/hdd_1 +Sep 14 20:12:58 felhom sudo[18639]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18639]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom felhom-agent[4303]: time=2026-09-14T20:12:58.669+02:00 level=INFO msg="guest-attach: drive bound under shared parent (normalized to one bind, live)" vmid=9201 where=/mnt/hdd_1 stable=/mnt/felhom-drives/hdd_1 prior_binds=0 +Sep 14 20:12:58 felhom sudo[18646]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:58 felhom sudo[18646]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18646]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18649]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:58 felhom sudo[18649]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18649]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom felhom-agent[4303]: time=2026-09-14T20:12:58.848+02:00 level=INFO msg="local-api: drive intent recorded" where=/mnt/hdd_1 action=enrolled durable_id=uuid:c4b530fd-d410-424c-917e-c8ecfdde9d8b +Sep 14 20:12:58 felhom sudo[18656]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:12:58 felhom sudo[18656]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:58 felhom sudo[18656]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:58 felhom sudo[18659]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:12:58 felhom sudo[18659]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:12:59 felhom sudo[18659]: pam_unix(sudo:session): session closed for user root +Sep 14 20:12:59 felhom felhom-agent[4303]: time=2026-09-14T20:12:59.026+02:00 level=INFO msg="local-api: guest-bind recorded for startup re-assert" vmid=9201 where=/mnt/hdd_1 durable_id=uuid:c4b530fd-d410-424c-917e-c8ecfdde9d8b +Sep 14 20:12:59 felhom felhom-agent[4303]: time=2026-09-14T20:12:59.026+02:00 level=INFO msg="local-api: guest-attach bound under shared parent" vmid=9201 where=/mnt/hdd_1 guest_path=/mnt/felhom-drives/hdd_1 +Sep 14 20:13:01 felhom sudo[18833]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:13:01 felhom sudo[18833]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18833]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18836]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:13:01 felhom sudo[18836]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18836]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18839]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:13:01 felhom sudo[18839]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18839]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18846]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:13:01 felhom sudo[18846]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18846]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18849]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:13:01 felhom sudo[18849]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18849]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18852]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/hdd_1/felhom-data +Sep 14 20:13:01 felhom sudo[18852]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18852]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18855]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown 100000:100000 /mnt/hdd_1/felhom-data +Sep 14 20:13:01 felhom sudo[18855]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18855]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18858]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives/hdd_1 +Sep 14 20:13:01 felhom sudo[18858]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18858]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18861]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:01 felhom sudo[18861]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18861]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom felhom-agent[4303]: time=2026-09-14T20:13:01.686+02:00 level=INFO msg="reconcile: enrolled drive bound under shared parent (live, no reboot)" vmid=9201 where=/mnt/hdd_1 guest_path=/mnt/felhom-drives/hdd_1 durable_id=uuid:c4b530fd-d410-424c-917e-c8ecfdde9d8b +Sep 14 20:13:01 felhom sudo[18868]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:13:01 felhom sudo[18868]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18868]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18871]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:13:01 felhom sudo[18871]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18871]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18874]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:01 felhom sudo[18874]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18874]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18877]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sdb +Sep 14 20:13:01 felhom sudo[18877]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18877]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:01 felhom sudo[18880]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:01 felhom sudo[18880]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:01 felhom sudo[18880]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:02 felhom sudo[18887]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:13:02 felhom sudo[18887]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:02 felhom sudo[18887]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:02 felhom sudo[18890]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:13:02 felhom sudo[18890]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:02 felhom sudo[18890]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:02 felhom sudo[18893]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:02 felhom sudo[18893]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:02 felhom sudo[18893]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:02 felhom sudo[18896]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sdb +Sep 14 20:13:02 felhom sudo[18896]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:02 felhom sudo[18896]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:02 felhom sudo[18899]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:02 felhom sudo[18899]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:02 felhom sudo[18899]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19017]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 20:13:21 felhom sudo[19017]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19017]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19024]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data +Sep 14 20:13:21 felhom sudo[19024]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19024]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19027]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/sbin/smartctl -a -j /dev/sda +Sep 14 20:13:21 felhom sudo[19027]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19027]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19030]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/hdd_1/felhom-data +Sep 14 20:13:21 felhom sudo[19030]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19030]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19033]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown 100000:100000 /mnt/hdd_1/felhom-data +Sep 14 20:13:21 felhom sudo[19033]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19033]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19036]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives/hdd_1 +Sep 14 20:13:21 felhom sudo[19036]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19036]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom sudo[19039]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/bin/lxc-info -n 9201 -p -H +Sep 14 20:13:21 felhom sudo[19039]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=999) +Sep 14 20:13:21 felhom sudo[19039]: pam_unix(sudo:session): session closed for user root +Sep 14 20:13:21 felhom felhom-agent[4303]: time=2026-09-14T20:13:21.686+02:00 level=INFO msg="reconcile: enrolled drive bound under shared parent (live, no reboot)" vmid=9201 where=/mnt/hdd_1 guest_path=/mnt/felhom-drives/hdd_1 durable_id=uuid:c4b530fd-d410-424c-917e-c8ecfdde9d8b diff --git a/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/bootstrap-journal.txt b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/bootstrap-journal.txt new file mode 100644 index 00000000..ef05b1e0 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/bootstrap-journal.txt @@ -0,0 +1,80 @@ +Sep 14 19:57:53 felhom felhom-bootstrap.sh[3268]: [OK] verified sha256 3ab480ddb7c1e690… matches the hub manifest +Sep 14 19:57:54 felhom felhom-bootstrap.sh[3268]: [OK] golden imported + verified: local:backup/vzdump-lxc-9100-2026_09_14-19_57_43.tar.zst +Sep 14 19:57:54 felhom felhom-bootstrap.sh[3268]: [STEP] 8/8 provision guest 9201 +Sep 14 19:57:55 felhom felhom-bootstrap.sh[3268]: [SKIP] pool felhom already exists +Sep 14 19:57:55 felhom felhom-bootstrap.sh[5289]: === felhom-agent 0.130.0 selftest=provision (vmid=9201 customer=tester-1 hostname=tester-1) === +Sep 14 19:57:55 felhom felhom-bootstrap.sh[5289]: --- front half: bring-up (provision) local:backup/vzdump-lxc-9100-2026_09_14-19_57_43.tar.zst → vmid 9201 --- +Sep 14 19:58:43 felhom felhom-bootstrap.sh[5289]: time=2026-09-14T19:58:43.990+02:00 level=INFO msg="bring-up: pool membership re-asserted" vmid=9201 pool=felhom +Sep 14 19:58:43 felhom felhom-bootstrap.sh[5289]: [OK] front half: vmid 9201 up (boot+running) in 49s; MAC=BC:24:11:9C:DD:1F +Sep 14 19:58:43 felhom felhom-bootstrap.sh[5289]: --- back half: mint per-guest token + populate bootstrap config mount --- +Sep 14 19:58:44 felhom sudo[6338]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown --reference=/var/lib/felhom-agent /var/lib/felhom-agent/guests /var/lib/felhom-agent/guests/9201 +Sep 14 19:58:44 felhom sudo[6338]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:44 felhom sudo[6338]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:44 felhom sudo[6341]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/chown -R 100000:100000 /var/lib/felhom-agent/guests/9201/bootstrap +Sep 14 19:58:44 felhom sudo[6341]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:44 felhom sudo[6341]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:44 felhom sudo[6344]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -mp9 /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1 +Sep 14 19:58:44 felhom sudo[6344]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:45 felhom sudo[6344]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:45 felhom sudo[6392]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -onboot 1 +Sep 14 19:58:45 felhom sudo[6392]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:46 felhom sudo[6392]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:46 felhom sudo[6560]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /var/lib/vz/snippets +Sep 14 19:58:46 felhom sudo[6560]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:46 felhom sudo[6560]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:46 felhom sudo[6575]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/install -m 0755 -- /tmp/felhom-guest-hook-4262544783.sh /var/lib/vz/snippets/felhom-guest-hook.sh +Sep 14 19:58:46 felhom sudo[6575]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:46 felhom sudo[6575]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:46 felhom sudo[6586]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 --hookscript local:snippets/felhom-guest-hook.sh +Sep 14 19:58:46 felhom sudo[6586]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:47 felhom sudo[6586]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:47 felhom sudo[7017]: root : PWD=/ ; USER=root ; COMMAND=/usr/bin/mkdir -p /mnt/felhom-drives +Sep 14 19:58:47 felhom sudo[7017]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:47 felhom sudo[7017]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:47 felhom sudo[7020]: root : PWD=/ ; USER=root ; COMMAND=/usr/sbin/pct set 9201 -mp8 /mnt/felhom-drives,mp=/mnt/felhom-drives +Sep 14 19:58:47 felhom sudo[7020]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=0) +Sep 14 19:58:48 felhom sudo[7020]: pam_unix(sudo:session): session closed for user root +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: time=2026-09-14T19:58:48.484+02:00 level=INFO msg="provision: back-half complete" vmid=9201 mount=mp9 guest_path=/etc/felhom-bootstrap endpoint=169.254.253.1:8443 +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: [OK] back half: bootstrap mount mp9 → /etc/felhom-bootstrap on vmid 9201 (host dir /var/lib/felhom-agent/guests/9201/bootstrap) +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: local-api endpoint 169.254.253.1:8443 · leaf fp f7853a846c980c99337618d5a4618f17fc6b88ffdc00e29d4d422060b0ebf4c2 · token: minted (not printed) +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: === selftest=provision OK — guest 9201 provisioned + bootstrap-mounted (KEPT) === +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: next: reboot the guest → the golden's baked controller-bootstrap unit deploys the controller, +Sep 14 19:58:48 felhom felhom-bootstrap.sh[5289]: which PULLS its controller.yaml from the hub (retrieval passphrase) and merges in this local_api. +Sep 14 19:58:48 felhom felhom-bootstrap.sh[3268]: [OK] provision completed +Sep 14 19:58:48 felhom felhom-bootstrap.sh[3268]: [INFO] rebooting guest 9201 so the baked controller-bootstrap unit picks up the mount +Sep 14 19:58:49 felhom pct[7239]: starting task UPID:felhom:00001C4C:00015104:6AA835D9:vzreboot:9201:root@pam: +Sep 14 19:58:49 felhom pct[7244]: requesting reboot of CT 9201: UPID:felhom:00001C4C:00015104:6AA835D9:vzreboot:9201:root@pam: +Sep 14 19:58:56 felhom pct[7239]: end task UPID:felhom:00001C4C:00015104:6AA835D9:vzreboot:9201:root@pam: OK +Sep 14 19:58:56 felhom felhom-bootstrap.sh[3268]: [STEP] verify +Sep 14 19:58:57 felhom felhom-bootstrap.sh[3268]: [OK] pct status: running +Sep 14 19:58:58 felhom felhom-bootstrap.sh[3268]: [OK] onboot: 1 +Sep 14 19:58:59 felhom felhom-bootstrap.sh[8012]: mp0: local-lvm:vm-9201-disk-1,mp=/var/lib/felhom,backup=1,size=70G +Sep 14 19:58:59 felhom felhom-bootstrap.sh[8012]: mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives +Sep 14 19:58:59 felhom felhom-bootstrap.sh[8012]: rootfs: local-lvm:vm-9201-disk-0,size=32G +Sep 14 19:59:01 felhom felhom-bootstrap.sh[3268]: [OK] pool: guest 9201 is a member of felhom +Sep 14 19:59:02 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentBase@/ present (user+token) +Sep 14 19:59:03 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/pool/felhom present (user+token) +Sep 14 19:59:04 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentStore@/storage/local present (user+token) +Sep 14 19:59:05 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentStore@/storage/local-lvm present (user+token) +Sep 14 19:59:07 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentStore@/storage/felhom-pbs present (user+token) +Sep 14 19:59:08 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990000 present (user+token) +Sep 14 19:59:09 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990001 present (user+token) +Sep 14 19:59:10 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990002 present (user+token) +Sep 14 19:59:11 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990003 present (user+token) +Sep 14 19:59:12 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990004 present (user+token) +Sep 14 19:59:13 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990005 present (user+token) +Sep 14 19:59:15 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990006 present (user+token) +Sep 14 19:59:16 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990007 present (user+token) +Sep 14 19:59:17 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990008 present (user+token) +Sep 14 19:59:18 felhom felhom-bootstrap.sh[3268]: [OK] acl: FelhomAgentGuest@/vms/990009 present (user+token) +Sep 14 19:59:18 felhom felhom-bootstrap.sh[3268]: [OK] authz signers: 2 (operator-signed self-update armed) +Sep 14 19:59:19 felhom felhom-bootstrap.sh[3268]: [OK] controller: Up 19 seconds (healthy) (after ~0s) +Sep 14 19:59:20 felhom felhom-bootstrap.sh[3268]: [INFO] controller image: gitea.dooplex.hu/admin/felhom-controller:0.242.0 +Sep 14 19:59:21 felhom felhom-bootstrap.sh[3268]: [INFO] cloudflared: Up 22 seconds +Sep 14 19:59:21 felhom felhom-bootstrap.sh[3268]: [INFO] (confirm in the hub UI that host tester-1-a61396 reports guest 9201) +Sep 14 19:59:21 felhom felhom-bootstrap.sh[3268]: [OK] Day-0 provision SUCCESS — vmid=9201 host_id=tester-1-a61396 customer=tester-1 golden=local:backup/vzdump-lxc-9100-2026_09_14-19_57_43.tar.zst +Sep 14 19:59:21 felhom felhom-bootstrap.sh[3268]: [INFO] root@pam was rotated + vaulted at step 4b — retrieve at hub → host page (the old GUI password no longer works). +Sep 14 19:59:21 felhom felhom-bootstrap.sh[1077]: felhom-bootstrap: host-install SUCCESS — writing done-flag, disabling unit, scrubbing secrets +Sep 14 19:59:22 felhom systemd[1]: felhom-bootstrap.service: Deactivated successfully. +Sep 14 19:59:22 felhom systemd[1]: Finished felhom-bootstrap.service - Felhom host bootstrap (fetch + run felhom-host-install.sh unattended, retry until success). +Sep 14 19:59:22 felhom systemd[1]: felhom-bootstrap.service: Consumed 1min 27.171s CPU time, 903.4M memory peak. diff --git a/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/box-state.txt b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/box-state.txt new file mode 100644 index 00000000..4f63e453 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/box-state.txt @@ -0,0 +1,39 @@ +arch: amd64 +cores: 3 +features: nesting=1,keyctl=1 +hookscript: local:snippets/felhom-guest-hook.sh +hostname: tester-1 +memory: 11828 +mp0: local-lvm:vm-9201-disk-1,mp=/var/lib/felhom,backup=1,size=70G +mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives +mp9: /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1 +net0: name=eth0,bridge=vmbr0,hwaddr=BC:24:11:9C:DD:1F,ip=dhcp,type=veth +net1: name=eth1,bridge=vmbr9,hwaddr=BC:24:11:4D:94:14,ip=169.254.253.2/30,type=veth +onboot: 1 +ostype: debian +rootfs: local-lvm:vm-9201-disk-0,size=32G +swap: 512 +unprivileged: 1 +Name Type Status Total (KiB) Used (KiB) Available (KiB) % +local dir active 61349692 5617208 52583684 9.16% +local-lvm lvmthin active 118427648 4085753 114341894 3.45% +NAME FSTYPE FSVER LABEL UUID FSAVAIL FSUSE% MOUNTPOINTS +sda +|-sda1 +|-sda2 vfat FAT32 1B51-8865 1013M 1% /boot/efi +`-sda3 LVM2_member LVM2 001 lSYnKE-gRBr-B6RX-wSgL-X47c-JpC5-9ZP5O7 + |-pve-swap swap 1 bac9efc5-a135-4ecf-a51e-d50e9952dc89 [SWAP] + |-pve-root ext4 1.0 1a14d086-409b-42cf-8484-e430292c9b57 50.1G 9% /mnt/felhom-drives + | / + |-pve-data_tmeta + | `-pve-data-tpool + | |-pve-data + | |-pve-vm--9201--disk--0 ext4 1.0 5a7494db-8369-40f2-835e-8c0ab437a0e6 + | `-pve-vm--9201--disk--1 ext4 1.0 92dda926-85fa-4ea4-bd09-850d74e6a862 + `-pve-data_tdata + `-pve-data-tpool + |-pve-data + |-pve-vm--9201--disk--0 ext4 1.0 5a7494db-8369-40f2-835e-8c0ab437a0e6 + `-pve-vm--9201--disk--1 ext4 1.0 92dda926-85fa-4ea4-bd09-850d74e6a862 +sdb ext4 1.0 c4b530fd-d410-424c-917e-c8ecfdde9d8b 92.9G 0% /mnt/felhom-drives/hdd_1 + /mnt/hdd_1 diff --git a/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/controller.log b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/controller.log new file mode 100644 index 00000000..88dea272 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/box-logs-phase2/controller.log @@ -0,0 +1,273 @@ +2026/09/14 17:59:00 [INFO] local-api: channel up (agent 169.254.253.1:8443) — guest 9201, 3 mount(s) visible +2026/09/14 17:59:00 [INFO] local-api: mount mp8 → /mnt/felhom-drives (storage=/mnt/felhom-drives, class=, backup=false) +2026/09/14 17:59:00 [INFO] local-api: mount mp9 → /etc/felhom-bootstrap (storage=/var/lib/felhom-agent/guests/9201/bootstrap, class=, backup=false) +2026/09/14 17:59:00 [INFO] local-api: mount mp0 → /var/lib/felhom (storage=local-lvm, class=, backup=true) +2026/09/14 17:59:00 [INFO] felhom-controller 0.242.0 starting (customer: tester-1, domain: enkicsifelhom.hu) +2026/09/14 17:59:00 [INFO] [settings] Loaded settings from /opt/docker/felhom-controller/data/settings.json +2026/09/14 17:59:00 [INFO] Encryption key loaded from /opt/docker/felhom-controller/data/encryption.key +2026/09/14 17:59:00 [INFO] [stacks] Using compose command: docker compose +2026/09/14 17:59:00 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 17:59:00 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:00 [INFO] [stacks] Encryption migration: no stacks needed migration +2026/09/14 17:59:00 [INFO] [stacks] desired-state backfill: 0 app(s) recorded as running, 0 left unrecorded (state ambiguous — legacy boot behaviour retained) +2026/09/14 17:59:00 [INFO] [stacks] installed-images backfill: 0 app(s) recorded, 0 already had a record, 0 left unrecorded (could not be observed completely — unknown, which renders nothing) +2026/09/14 17:59:00 [INFO] [stacks] pin adoption: 0 pinned, 0 already pinned, 0 left unpinned (0 not completely observed, 0 running something the template no longer offers) +2026/09/14 17:59:00 [INFO] [sync] Starting catalog sync (repo: https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git, interval: 15m0s) +2026/09/14 17:59:00 [INFO] [sync] Starting catalog sync +2026/09/14 17:59:00 [INFO] [quiesce] loop started (poll 5m0s, max-quiesce 30m0s) +2026/09/14 17:59:00 [INFO] [sync] Pulling latest from https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git (branch: main) +2026/09/14 17:59:00 [INFO] Metrics store opened at /opt/docker/felhom-controller/data/metrics.db +2026/09/14 17:59:00 [INFO] Metrics collector started (60s interval) +2026/09/14 17:59:00 [INFO] Notifier enabled (hub: https://hub.felhom.eu) +2026/09/14 17:59:00 [INFO] Self-update enabled (check every 6h, auto-update: false, auto-update time: 04:30) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: status-refresh (every 10s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: stack-scan (every 2m0s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: health-probes (every 10s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: system-health (every 5m0s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: deadapp-check (every 30s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: ring-spill (every 30s) +2026/09/14 17:59:00 [INFO] [scheduler] Daily job db-dump scheduled for 2026-09-15 02:30 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: offsite-credential-retry (every 5m0s) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: backup-cache (every 5m0s) +2026/09/14 17:59:00 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-09-15 03:30 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-09-15 04:15 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-09-15 05:10 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-09-15 06:00 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-09-15 05:30 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-09-15 04:00 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Daily job fill-watch scheduled for 2026-09-15 03:30 CEST +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: hub-report (every 15m0s) +2026/09/14 17:59:00 [INFO] Hub reporting enabled (every 15m0s to https://hub.felhom.eu) +2026/09/14 17:59:00 [INFO] [scheduler] Registered periodic job: selfupdate-check (every 6h0m0s) +2026/09/14 17:59:00 [INFO] ========== Startup Self-Test ========== +2026/09/14 17:59:00 [INFO] [PASS] Docker socket: reachable (v29.8.0) +2026/09/14 17:59:00 [INFO] [PASS] Stacks directory: /opt/docker/stacks +2026/09/14 17:59:00 [INFO] [PASS] Data directory: /opt/docker/felhom-controller/data (writable) +2026/09/14 17:59:00 [INFO] [PASS] System data path: /mnt/sys_drive +2026/09/14 17:59:00 [INFO] [WARN] Storage paths: no storage paths registered +2026/09/14 17:59:00 [INFO] [PASS] Git catalog: 53 app definitions found +2026/09/14 17:59:01 [INFO] [infra] connected felhom-controller to traefik-public +2026/09/14 17:59:01 [INFO] [PASS] Hub connectivity: https://hub.felhom.eu reachable (HTTP 200) +2026/09/14 17:59:01 [INFO] [PASS] Metrics DB: 0.0 MB +2026/09/14 17:59:01 [INFO] ======================================== +2026/09/14 17:59:01 [INFO] Self-test complete: 7 passed, 1 warnings, 0 failed +2026/09/14 17:59:01 [INFO] [scheduler] Starting scheduler with 18 jobs +2026/09/14 17:59:01 [INFO] [scheduler] Registered periodic job: geo-verify (every 6h0m0s) +2026/09/14 17:59:01 [INFO] Geo-restriction support enabled (CF API token configured) +2026/09/14 17:59:01 [INFO] [backup] Found 0 DB dump files across drives +2026/09/14 17:59:01 [INFO] [report] hub wait channel active (hold ≤240s) +2026/09/14 17:59:01 [INFO] [web] Auth: no password configured — dashboard is open +2026/09/14 17:59:01 [INFO] [scheduler] Registered periodic job: disk-health-check (every 1h0m0s) +2026/09/14 17:59:01 [INFO] [scheduler] Registered periodic job: agent-channel-health (every 1m0s) +2026/09/14 17:59:01 [INFO] Web UI listening on :8080 +2026/09/14 17:59:01 [INFO] [backup] Discovered 0 databases +2026/09/14 17:59:01 [INFO] [backup] Discovered app data: 0 apps +2026/09/14 17:59:01 [INFO] [backup] Backup status cache refreshed +2026/09/14 17:59:01 [INFO] [settings] Settings saved +2026/09/14 17:59:01 [INFO] [sync] Catalog sync complete +2026/09/14 17:59:01 [INFO] [sync] Initial sync: Sablonok naprakészek — nincs változás +2026/09/14 17:59:01 [INFO] [monitor] Health check: status=ok +2026/09/14 17:59:02 [INFO] [web] FileBrowser mounts synced (recreated) — 0 storage path(s), config updated +2026/09/14 17:59:05 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:06 [INFO] [report] Building system report +2026/09/14 17:59:06 [INFO] Event pushed: controller_started (info) — Controller elindult (0.242.0) +2026/09/14 17:59:06 [INFO] [monitor] Health check: status=ok +2026/09/14 17:59:06 [INFO] [report] Hub report pushed successfully (2255 bytes) +2026/09/14 17:59:06 [INFO] [settings] Settings saved +2026/09/14 17:59:06 [INFO] [settings] Settings saved +2026/09/14 17:59:06 [INFO] config-refresh: baseline config_version=2 recorded (no restart) +2026/09/14 17:59:06 [INFO] [settings] Settings saved +2026/09/14 17:59:06 [INFO] [claim-sync] hub claim code cached (generation 2) — hash first 8: $2a$10$M… +2026/09/14 17:59:06 [INFO] Startup hub report sent +2026/09/14 17:59:10 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:15 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:15 [INFO] [bootrecon] boot window: fleet settled after 10s (3 identical samples 5s apart) — sweeping +2026/09/14 17:59:15 [INFO] [bootrecon] Boot reconciliation: no boot-orphaned apps (nothing to start) +2026/09/14 17:59:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:31 [INFO] [selfupdate] Current version 0.242.0 is up to date +2026/09/14 17:59:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 17:59:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:00:01 [INFO] [scheduler] Job agent-channel-health completed (took 183ms) +2026/09/14 18:00:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:30 [INFO] [fillwatch] checked 2 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok +2026/09/14 18:00:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:00:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:01:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:01:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:01:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:01 [INFO] [scheduler] Job stack-scan completed (took 58ms) +2026/09/14 18:01:01 [INFO] [scheduler] Job agent-channel-health completed (took 188ms) +2026/09/14 18:01:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:01:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:02:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:01 [INFO] [scheduler] Job agent-channel-health completed (took 200ms) +2026/09/14 18:02:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:02:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:03:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:03:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:03:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:01 [INFO] [scheduler] Job stack-scan completed (took 59ms) +2026/09/14 18:03:01 [INFO] [scheduler] Job agent-channel-health completed (took 192ms) +2026/09/14 18:03:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:03:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:01 [INFO] [scheduler] Running job: backup-cache +2026/09/14 18:04:01 [INFO] [scheduler] Running job: system-health +2026/09/14 18:04:01 [INFO] [scheduler] Running job: offsite-credential-retry +2026/09/14 18:04:01 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s) +2026/09/14 18:04:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:04:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:01 [INFO] [backup] Found 0 DB dump files across drives +2026/09/14 18:04:01 [INFO] [backup] Discovered 0 databases +2026/09/14 18:04:01 [INFO] [backup] Discovered app data: 0 apps +2026/09/14 18:04:01 [INFO] [backup] Backup status cache refreshed +2026/09/14 18:04:01 [INFO] [scheduler] Job backup-cache completed (took 58ms) +2026/09/14 18:04:01 [INFO] [quiesce] backup due on 1 tier(s) — quiescing 0 stack(s): [] +2026/09/14 18:04:01 [INFO] [quiesce] tier local: backup job backup-9201-1789409041243366069 started — polling +2026/09/14 18:04:01 [INFO] [scheduler] Job agent-channel-health completed (took 575ms) +2026/09/14 18:04:01 [INFO] [monitor] Health check: status=ok +2026/09/14 18:04:01 [INFO] [scheduler] Job system-health completed (took 657ms) +2026/09/14 18:04:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:11 [INFO] [quiesce] tier local: job backup-9201-1789409041243366069 snapshotted — resuming app early (8B.2) +2026/09/14 18:04:11 [INFO] [quiesce] unquiescing (snapshotted (early resume, last tier)): restarting 0 stack(s) +2026/09/14 18:04:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:31 [INFO] [quiesce] tier local: backup job backup-9201-1789409041243366069 done +2026/09/14 18:04:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:04:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:05:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:05:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:05:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:01 [INFO] [scheduler] Job stack-scan completed (took 72ms) +2026/09/14 18:05:01 [INFO] [scheduler] Job agent-channel-health completed (took 198ms) +2026/09/14 18:05:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:05:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:06:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:01 [INFO] [scheduler] Job agent-channel-health completed (took 178ms) +2026/09/14 18:06:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:06:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:07:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:07:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:07:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:01 [INFO] [scheduler] Job stack-scan completed (took 37ms) +2026/09/14 18:07:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:01 [INFO] [scheduler] Job agent-channel-health completed (took 187ms) +2026/09/14 18:07:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:07:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:08:01 [INFO] [scheduler] Job agent-channel-health completed (took 203ms) +2026/09/14 18:08:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:08:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:01 [INFO] [scheduler] Running job: backup-cache +2026/09/14 18:09:01 [INFO] [scheduler] Running job: offsite-credential-retry +2026/09/14 18:09:01 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s) +2026/09/14 18:09:01 [INFO] [scheduler] Running job: system-health +2026/09/14 18:09:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:09:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:09:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:09:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:01 [INFO] [scheduler] Job stack-scan completed (took 99ms) +2026/09/14 18:09:01 [INFO] [backup] Found 0 DB dump files across drives +2026/09/14 18:09:01 [INFO] [backup] Discovered 0 databases +2026/09/14 18:09:01 [INFO] [backup] Discovered app data: 0 apps +2026/09/14 18:09:01 [INFO] [backup] Backup status cache refreshed +2026/09/14 18:09:01 [INFO] [scheduler] Job backup-cache completed (took 130ms) +2026/09/14 18:09:01 [INFO] [scheduler] Job agent-channel-health completed (took 193ms) +2026/09/14 18:09:01 [INFO] [monitor] Health check: status=ok +2026/09/14 18:09:01 [INFO] [scheduler] Job system-health completed (took 223ms) +2026/09/14 18:09:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:09:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:01 [INFO] [deadapp] check alive: 20 scans since boot, 0 deployed app(s) evaluated, 0 currently down +2026/09/14 18:10:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:10:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:01 [INFO] [scheduler] Job agent-channel-health completed (took 178ms) +2026/09/14 18:10:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:29 [INFO] [settings] Settings saved +2026/09/14 18:10:29 [INFO] [settings] Settings saved +2026/09/14 18:10:29 [INFO] [settings] Settings saved +2026/09/14 18:10:29 [INFO] [web] All sessions invalidated (cleared 0) +2026/09/14 18:10:29 [INFO] [web] dashboard claimed by the customer from 192.168.0.180 (code generation 2 consumed) +2026/09/14 18:10:29 [INFO] [web] Login from 172.18.0.2:39688 +2026/09/14 18:10:31 [INFO] [report] Building system report +2026/09/14 18:10:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:31 [INFO] [monitor] Health check: status=ok +2026/09/14 18:10:31 [INFO] [report] Hub report pushed successfully (2277 bytes) +2026/09/14 18:10:31 [INFO] [settings] Settings saved +2026/09/14 18:10:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:10:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:11:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:11:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:11:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:01 [INFO] [scheduler] Job stack-scan completed (took 61ms) +2026/09/14 18:11:01 [INFO] [scheduler] Job agent-channel-health completed (took 191ms) +2026/09/14 18:11:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:11:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:12:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:01 [INFO] [scheduler] Job agent-channel-health completed (took 194ms) +2026/09/14 18:12:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:31 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:41 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:51 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:12:57 [INFO] [web] storage init "/mnt/hdd_1" started (device /dev/sdb, fs ext4) +2026/09/14 18:12:59 [INFO] [web] enroll: drive bound into guest: /mnt/hdd_1 +2026/09/14 18:12:59 [INFO] [settings] Added storage path: /mnt/felhom-drives/hdd_1 +2026/09/14 18:12:59 [INFO] [settings] Settings saved +2026/09/14 18:12:59 [INFO] [web] storage init done: /mnt/felhom-drives/hdd_1 registered (1802ms) +2026/09/14 18:12:59 [INFO] [web] FileBrowser mounts synced (recreated) — 1 storage path(s), config updated +2026/09/14 18:13:01 [INFO] [scheduler] Running job: stack-scan +2026/09/14 18:13:01 [INFO] [scheduler] Running job: agent-channel-health +2026/09/14 18:13:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:13:01 [INFO] [stacks] ScanStacks complete: 56 stacks found (0 deployed, 56 available) +2026/09/14 18:13:01 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:13:01 [INFO] [scheduler] Job stack-scan completed (took 63ms) +2026/09/14 18:13:01 [INFO] [scheduler] Job agent-channel-health completed (took 195ms) +2026/09/14 18:13:11 [INFO] [stacks] Status refresh: 3 containers across 56 stacks +2026/09/14 18:13:21 [INFO] [stacks] Status refresh: 3 containers across 56 stacks diff --git a/documentation/audits/evidence-bignight-2026-09-14/drive-init.txt b/documentation/audits/evidence-bignight-2026-09-14/drive-init.txt new file mode 100644 index 00000000..8211149a --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/drive-init.txt @@ -0,0 +1,5 @@ +POST /api/storage/init 18:12:57 +{"data":{"phase":"formatting","started":true},"ok":true} +18:12:57 formatting +18:12:59 done +{"data":{"device":"/dev/sdb","durable_id":"","error":"","opsign":"","phase":"done","reason":"","started_at":"2026-09-14T18:12:57.229225118Z","updated_at":"2026-09-14T18:12:59.031560471Z","where":"/mnt/felhom-drives/hdd_1"},"ok":true} diff --git a/documentation/audits/evidence-bignight-2026-09-14/journal.md b/documentation/audits/evidence-bignight-2026-09-14/journal.md index 7ef9f792..b3e19f84 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/journal.md +++ b/documentation/audits/evidence-bignight-2026-09-14/journal.md @@ -211,3 +211,80 @@ valid 2026-09-14 17:01 → 12-13** — the right certificate exists. **Control ( **Conclusion:** the operator's route reaches the box now (530 → 502) but lacks „No TLS Verify". Filed **R-510 (P1)** at 18:1xZ **before acting**. **Intervention I2:** from here the claim and all dashboard traffic go to `192.168.0.150:443` with the name forced (`--resolve`), from DooPlex on the same household LAN as the box. + +## Phase 2.2 (cont.) — the claim, with the mailed code (I2 route) + +`screen-claim-page.txt`. **18:10:06Z `GET /`** → 302 `/claim`; the page: „**A szerver beállítása** — Tester 1 — +Add meg az e-mailben kapott beállító kódot, majd válassz saját jelszót a vezérlőpult védelméhez." · Beállító kód · +Új jelszó (min. 12 karakter) · Új jelszó megerősítése · **Beállítás és belépés** · „Nem kaptad meg a kódot? Új kód +kérése". (The page does not mention the reinstall the mail talked about — the two agree on the code, not the story.) + +**Harness slip:** the first `POST /claim` (18:10:06Z) sent both of the page's `_csrf` values joined (two forms, two +tokens) → 200 „Érvénytelen űrlap — töltsd újra az oldalt." (form refused, not a code attempt). Re-fetched, one token. + +**18:10:28Z `POST /claim`** (the **mailed** code, a generated 24-char password twice) → **302 `/`** + `felhom_session`. +**The mailed setup code works — first walk to use the real mail instead of a box-printed code.** +`/launcher` 200: „Indítópult — Felhom.eu", tile **Filebrowser**, sharing off; menu Vezérlőpult · Alkalmazások · +Tárhely (Meghajtók, Hálózati tárhely) · Biztonsági mentés (Áttekintés, Távoli mentés, Alkalmazások, Visszaállítás) · +Megosztás (Hálózati megosztás) · Rendszermonitor · **Debug** · Beállítások (Rendszer, Értesítések, Biztonság és +hozzáférés) · `0.242.0`. + +**Power-on → claimed dashboard: 38 m 15 s** (17:32:13 → 18:10:28), of which 10 min were the brief's mail wait. + +## Phase 2.3 — version + +Box: `felhom-controller:0.242.0 (healthy)`, `felhom-agent 0.130.0`. Hub: „Controller 0.242.0 · Registry latest +v0.242.0 — up to date · Effective floor v0.242.0 — at/above floor". **PASS — landed on golden 0.242.0, reports +current, no self-update needed** (golden == floor). Bind → `controller_started` 2 m 36 s. + +## Phase 2.4 — the gate after the claim — **FAIL, still R-510** + +`tunnel-after-claim.txt`: 18:10:41Z from DooPlex `https://felhom.enkicsifelhom.hu/login` → **502 ×6**; box cloudflared +at 18:10:42Z: the same `x509 … traefik.default, not traefik` for each. Continued on the LAN address (I2). + +## Phase 2.1 (cont.) — the data disk (100 G `scsi1`, hot-attached 17:46:42Z, before the bind) + +- Box `lsblk`: `sdb 100G disk`, no partitions. +- **Dashboard** (`screen-storage-dashboard-after-claim.txt`): „Lemezek állapota — QEMU QEMU HARDDISK · Nincs adat · + 0 °C" (one line, which disk is not said); **nothing mentions a new disk.** +- **Tárhely → Meghajtók:** „**Nincs regisztrált adattároló.** Adjon hozzá egyet az alábbi űrlappal." · „Új meghajtó + inicializálása" · „Meglévő meghajtó csatolása" · „Nem regisztrált meghajtók — az ügynök által észlelt, még nem + regisztrált adatmeghajtók" · „Rendszermeghajtók — védett …" · „Már csatlakoztatott tárhely hozzáadása kézzel — + Elérési út — Pl. /mnt/hdd_1 …". Formal „Adjon" (the rest of the product says „te"). +- `GET /api/disks/candidates`: `initialize: [/dev/sdb 107374182400 B, QEMU HARDDISK, data_bearing false]`; + `attach: [/dev/mapper/pve-vm--9201--disk--1, mount_source /mnt/sys_drive, already_mounted true]` (the guest's own + system volume offered for attach — observed in the 0242 drill too). +- **Would a household know to enrol it? No.** Nothing on the dashboard, the launcher or any mail says a disk appeared; + the volunteer guide has no step for it; the page that lists it is two menus deep and speaks of „inicializálás" + and „ügynök". A volunteer who plugs in a second disk has to go looking. + +## The DR tier on this box — stuck (operator act O1, not a customer step) + +Hub 19:57:42 CEST: `pbsdr auto-provision … the endpoint already holds a PBS token for tester-1 but the hub has no +descriptor — use the explicit "Re-issue PBS credentials" action`. **18:11:57Z operator `POST /configs/tester-1/ +pbsdr-reissue` → 400 `No provisioned PBS DR tier for this customer`.** Neither path provisions it. Filed **R-511 (P2)**. +Not forced further: removing the old ep0 token is a destructive act on ep0 tenancy, and RESET would also remove the +tunnel (fenced by the brief: the customer is kept). +**Consequence for tonight, stated once:** this box has **no off-site tier of either kind** — restic Tier-3 is off +(money) and the PBS DR tier cannot provision. Nothing is written to ep0 tonight. Phase 4's off-site integrity check +and Phase 6's restore „from off-site" are recorded as not possible when reached, with the local tiers walked instead. + +No „A vezérlőpultod mostantól jelszóval védett" mail arrived for the claim (the 0242 drill's box received one at +13:31:23Z, 12 s after its claim); at 18:12Z the mailbox holds only the bind mail and the reinstall mail. + +## Phase 2.1 (cont.) — enrolling the data drive, as a household could from the screens + +18:12:57Z `POST /api/storage/init` (the „Új meghajtó inicializálása" wizard's call) `{device /dev/sdb, ext4, mount_name +hdd_1, label Adatlemez, set_default true}` → `formatting` → **`done` at 18:12:59Z (2 s)**, where +`/mnt/felhom-drives/hdd_1` (`drive-init.txt`). The wizard's „Csatlakoztatási név" field has **no value, only the +placeholder `hdd_1`** — a person must type a name. Tárhely now: „Adatlemez · /mnt/felhom-drives/hdd_1 · +**Alapértelmezett** · Aktív · 0.0 GB / 97.9 GB · ext4 · /dev/sdb[/felhom-data] · QEMU HARDDISK · Nincs alkalmazás ezen a +tárolón". `/api/disks`: role `user-data`, durable id `uuid:c4b530fd…`. + +**Phase 2 evidence pulled off the box 18:14Z:** `box-logs-phase2/` (bootstrap + agent journals, controller log, +box state, cloudflared). Secret patterns searched (`passphrase=|retrieval_password|password:`): 0 hits. + +### Phase 2 interventions: **2** +- **I1** (R-509): the self-bind mail never came for an existing customer; the operator's send button was pressed. +- **I2** (R-510): the tunnel answers 502; claim and dashboard over the LAN address with the name forced. +Operator acts that are prerequisites, not counted: passphrase hand-over; PBS re-issue attempt (O1, refused). diff --git a/documentation/audits/evidence-bignight-2026-09-14/screen-claim-page.txt b/documentation/audits/evidence-bignight-2026-09-14/screen-claim-page.txt new file mode 100644 index 00000000..4307baeb --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/screen-claim-page.txt @@ -0,0 +1 @@ +A szerver beállítása — Felhom | A szerver | beállítása | Tester 1 | Add meg az e-mailben kapott beállító kódot, majd válassz saját jelszót a vezérlőpult védelméhez. | Beállító kód | Új jelszó (min. 12 karakter) | Új jelszó megerősítése | Beállítás és belépés | Nem kaptad meg a kódot? Új kód kérése | Felhom — Otthoni szerver kezelés | felhom.eu diff --git a/documentation/audits/evidence-bignight-2026-09-14/screen-launcher-after-claim.txt b/documentation/audits/evidence-bignight-2026-09-14/screen-launcher-after-claim.txt new file mode 100644 index 00000000..2106e31e --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/screen-launcher-after-claim.txt @@ -0,0 +1 @@ +Indítópult — Felhom.eu | Indítópult | Vezérlőpult | Alkalmazások | Tárhely | Meghajtók | Hálózati tárhely | Biztonsági mentés | Áttekintés | Távoli mentés | Alkalmazások | Visszaállítás | Megosztás | Hálózati megosztás | Rendszermonitor | Debug | Beállítások | Rendszer | Értesítések | Biztonság és hozzáférés | 0.242.0 | Kijelentkezés ↗ | Indítópult | enkicsifelhom.hu | Indítópult megosztása | F | Filebrowser | Indítópult megosztása | Egy megosztható link, amely csak megmutatja az alkalmazásokat és új lapon megnyitja őket. Fiók nélkül, felügyeleti hozzáférés nélkül — minden alkalmazás a saját bejelentkezése mögött marad. | A megosztás jelenleg ki van kapcsolva. | Bezárás | Megosztás bekapcsolása diff --git a/documentation/audits/evidence-bignight-2026-09-14/screen-storage-dashboard-after-claim.txt b/documentation/audits/evidence-bignight-2026-09-14/screen-storage-dashboard-after-claim.txt new file mode 100644 index 00000000..538a0e2e --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/screen-storage-dashboard-after-claim.txt @@ -0,0 +1,4 @@ +=== GET /storage +Tárhely — Meghajtók | Adattárolók | Külső meghajtók kezelése alkalmazásadatok tárolásához. | Nincs regisztrált adattároló. Adjon hozzá egyet az alábbi űrlappal. | Adatok áthelyezése | … | Új meghajtó inicializálása | Meglévő meghajtó csatolása | Nem regisztrált meghajtók | az ügynök által észlelt, még nem regisztrált adatmeghajtók | Rendszermeghajtók | védett — csak operátori aláírással módosíthatók | Már csatlakoztatott tárhely hozzáadása kézzel | Elérési út | Pl. /mnt/hdd_1 — a meghajtónak már csatolva kell lennie | Megnevezés (opcionális) | Legyen alapértelmezett új telepítéseknél | Hozzáadás +=== GET /dashboard +Vezérlőpult | enkicsifelhom.hu | 3 | Futó alkalmazás | 0 | Leállítva | 56 | Összes alkalmazás | Memória | 1.6 GB / 12 GB (14%) | CPU | 1% | Load: 0.29 / 0.39 / 0.37 | Rendszer (/) | 0.97 GB / 68.7 GB (1%) | Lemezek állapota | QEMU QEMU HARDDISK | Nincs adat | 0 °C | Biztonsági mentés | Utolsó mentés: | Még nem futott | Telepített alkalmazások | Cloudflare Tunnel | Biztonságos internetkapcsolat — a szerver portnyitás nélkül érhető el kívülről. | Fut | Védett | FileBrowser | Fájlkezelő — a tárhely fájljainak böngészése a böngészőből. | Fut | Védett | Megnyitás | Traefik | Forgalomirányító (reverse proxy) — a kéréseket a megfelelő alkalmazáshoz irányítja. | Fut | Védett diff --git a/documentation/audits/evidence-bignight-2026-09-14/tunnel-after-claim.txt b/documentation/audits/evidence-bignight-2026-09-14/tunnel-after-claim.txt new file mode 100644 index 00000000..2cd93a9d --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/tunnel-after-claim.txt @@ -0,0 +1,14 @@ +=== tunnel AFTER claim, from DooPlex 2026-09-14T18:10:41Z +try 1: 502 0.202269s +try 2: 502 0.191886s +try 3: 502 0.173681s +try 4: 502 0.193043s +try 5: 502 0.218580s +try 6: 502 0.188420s +--- box cloudflared since claim +2026-09-14T18:10:42Z ERR error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" connIndex=3 event= +2026-09-14T18:10:42Z ERR Request failed error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" conn +2026-09-14T18:10:42Z ERR error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" connIndex=3 event= +2026-09-14T18:10:42Z ERR Request failed error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" conn +2026-09-14T18:10:42Z ERR error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" connIndex=3 event= +2026-09-14T18:10:42Z ERR Request failed error="Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared: tls: failed to verify certificate: x509: certificate is valid for 544346c4b91be1183a3ccbf07d320cc2.0dc6e57dfe8df6d0687835c5988f16f7.traefik.default, not traefik" conn diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index db1c51fe..3d54b112 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -714,6 +714,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-508** | **[P2-MEDIUM] Customer `tester-1` has no registered e-mail, so neither the self-bind link nor the setup code can reach a volunteer.** MEASURED 2026-09-14: the edit form's `email` value is empty; on bind the hub logged `[ERROR] [claim] claim code generated (gen 1) but customer tester-1 has NO registered email — deliver via resend after setting one`. A volunteer onboarded on this record would sit at „A szerver beállítása" with no code. **What it needs:** the operator sets the volunteer's address on the record before sending the guide (day-0 A.2). The hub's customer page could warn when a record with an unclaimed box has no e-mail — the log line exists, the page says nothing. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (record), CC (page warning)** | | **R-509** | **[P1-HIGH] A box installed for an EXISTING customer never gets the self-bind e-mail the console tells the volunteer to open.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1): customer `tester-1` now has `tester1@felhom.eu` registered; the box registered as appliance 28 at 17:44:53Z and its console says „Nyisd meg az e-mailben kapott linket"; **ten minutes later the mailbox (read through the Gmail connector) held 0 messages to that address.** Cause, from source: the hub auto-sends the link only at customer creation (`hub/internal/web/configs.go:725`) and at RESET completion (`customer_reset.go:162`); a customer whose e-mail was added later, or whose previous box was destroyed, never receives one unless the operator presses „Send self-bind link". The volunteer guide's operator prerequisites do not list that press. Intervention **I1** of the big night (the operator's button pressed). **Fix shape (for the operator to choose):** send the link when an unclaimed appliance registers and a customer with no host is waiting, or add the press to the guide's operator prerequisites (day-0 A.2). | **READY — rank P1-HIGH; owner: CC (hub fix) · operator (which fix shape)** | | **R-510** | **[P1-HIGH] `tester-1`'s tunnel now has its route, and still gives a fresh box 502: the route sends traffic to `https://traefik` WITH certificate checking, and traefik answers the name `traefik` with its default certificate.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1, controller 0.242.0), after the operator's R-505 fix: from DooPlex `https://felhom.enkicsifelhom.hu` → **502 ×3** (18:07:48Z, `server: cloudflare`). The box's `cloudflared` logs `Request failed … tls: failed to verify certificate: x509: certificate is valid for 544346c4….traefik.default, not traefik … ingressRule=0 originService=https://traefik`. Traefik itself holds a valid Let's Encrypt `CN=*.enkicsifelhom.hu` (openssl on 127.0.0.1:443 with SNI). **Control:** demo-hp's working tunnel config reads `{"hostname":"*.enkisfelhom.hu", "originRequest":{"noTLSVerify":true}, "service":"https://traefik"}` — the same route WITH `noTLSVerify`. So the Cloudflare-side public hostname for `*.enkicsifelhom.hu` lacks „No TLS Verify" (or an origin server name). The Cloudflare side is not visible to the session; the inference rests on the log line and the control. Intervention **I2** of the big night: the claim and every dashboard request go to the guest's LAN address with the name forced. **Fix:** operator ticks „No TLS Verify" on that public hostname, then day-0 A.1 names the setting beside the route. | **WAITING-ON-OPERATOR — rank P1-HIGH; owner: operator (Cloudflare route), CC (day-0 A.1 wording after)** | +| **R-511** | **[P2-MEDIUM] A customer whose box is rebuilt keeps its ep0 PBS token, and then the DR tier can be neither provisioned nor re-issued: the hub's error advises the one action that refuses.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, `tester-1`, DR tier ticked): on the new box's WireGuard registration the hub logged `[ERROR] pbsdr auto-provision for tester-1 (WG-registration hook): the endpoint already holds a PBS token for tester-1 but the hub has no descriptor — use the explicit "Re-issue PBS credentials" action — save the customer config to retry`. The operator's `POST /configs/tester-1/pbsdr-reissue` → **400 `No provisioned PBS DR tier for this customer`** (`hub/internal/web/pbsdr.go` ~411). The token was left by the doorstep walk's host delete (a host delete does not deprovision tenancy; only RESET does, which also removes the tunnel). So a box rebuilt for an existing customer — the reinstall journey — has no whole-guest off-site tier and no button that restores it. **Fix shape:** let re-issue adopt an existing endpoint token when the descriptor is absent (the message already assumes it does), or have host delete offer to drop the PBS token. | **READY — rank P2-MEDIUM; owner: CC (hub)** |