REPORT + Day-0 doc: BUNDLE slice (hub v0.16.0 artifact manifest + host-install v1.1.0 self-install)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,15 @@
|
||||
# SPIKE — Day-0 first-boot trust handshake (operator-deploy)
|
||||
|
||||
> **Update 2026-06-28 (BUNDLE slice):** Day-0 now **self-installs the agent** + fetches the golden from
|
||||
> Gitea. The host-bootstrap script (`scripts/felhom-host-install.sh` v1.1.0) fetches the agent binary +
|
||||
> golden from Gitea generic packages and **verifies each sha256 against a hub-vouched artifact manifest**
|
||||
> (`GET /api/v1/artifacts/{id}`, hub v0.16.0) before installing/using them — the fetch credential is the
|
||||
> existing config-retrieve git token (no new credential); the checksum trust root is the **hub**, not
|
||||
> Gitea. The "works on a box that isn't felhom-pve" gap is closed: prerequisites are now just **install
|
||||
> PVE + create the customer in the hub**. The agent runs **non-root** (`felhom-agent` + sudoers).
|
||||
> Remaining follow-ups: per-customer artifact pinning, a `make golden` that resolves-latest, non-root
|
||||
> PBS-key access, the DR mode, and the local-DNS slice.
|
||||
|
||||
**Date:** 2026-06-26
|
||||
**Class:** Spike (empirical validation; no production code shipped). Output is this doc only.
|
||||
**Question:** Does the composed first-boot chain — customer-in-hub → host mint → agent host-auth →
|
||||
|
||||
Reference in New Issue
Block a user