hub v0.137.0 source + burn-down round 2 in felhom.eu: R-277 R-581 R-600 R-544 R-855 R-134 R-92 R-292 R-599 R-725 R-728 (hub), R-819 R-857 R-555 R-364 R-587 (gates/tools), R-571 R-129 R-124-runbook (docs); 28 rows closed incl. catalog + agent v0.147.0 rows, R-350 merged into R-132, R-888 opened, R-887 mechanism (249 -> 222)
gates / gates (push) Successful in 2m3s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 19:43:37 +02:00
parent e0d884565f
commit 557629d2bf
65 changed files with 2680 additions and 122 deletions
+8 -5
View File
@@ -107,12 +107,15 @@ was left in its working island configuration. It is a throwaway: destroy with `q
historical golden-bake `drill.qcow2` still lives on **DooPlex** (`/mnt/5_hdd/felhom.eu/drill/`, ~18G,
powered off) and is unrelated. The build-PIPELINE relocation to the t740 remains unbuilt.
### Access — there is no baked SSH key
### Access — DooPlex's key, and the G1 password as the fallback
`ssh demo-hp` resolves to the tailnet address, but **no operator public key is on this box** — the
HP profile deliberately left `FELHOM_ROOT_SSH_KEY` blank. Authentication is the **G1 break-glass
root password vaulted in the hub**, `host_recovery` row `demo-hp-bb76ea` (set at day-0,
2026-07-21 16:24 UTC).
**`ssh demo-hp` from DooPlex authenticates BY KEY** (corrected 2026-10-05, R-129; measured with
`ssh -o BatchMode=yes demo-hp`). The day-0 HP profile left `FELHOM_ROOT_SSH_KEY` blank, so no key was
baked — the key was added later: root's `authorized_keys` (last changed 2026-08-21) holds DooPlex's
own `~/.ssh/id_ed25519` (fingerprint `SHA256:pgQh228R…`, the operator's address as its comment) beside
the box's own `root@demo-hp` RSA key. `~/.ssh/config` on DooPlex points `demo-hp` at it. The **G1
break-glass root password vaulted in the hub** (`host_recovery` row `demo-hp-bb76ea`, set at day-0,
2026-07-21 16:24 UTC) remains the way in when the key does not work.
Retrieval (operator-side, and **shred the copy** — that DB holds every host's secret):