Teardown verified on ep0, and the two periods I got wrong (R-600)
gates / gates (push) Successful in 25s

The customer delete cascade logged "full teardown" while the drill box's WireGuard
peer 10.77.0.5 was still configured on ep0. Checked THERE rather than inferred from
the hub, then watched until it went: gone about 6 minutes later. The mechanism is
asynchronous, not broken; the log line claims a completeness it does not yet have.

Both periods this session inferred from two log lines were wrong — the delete's
staleness window and wgsync's push interval. A period read off two log lines is not
a measurement, and both rows now carry what was actually observed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-20 19:48:20 +02:00
parent 75bc699f78
commit 732e9b9e0c
2 changed files with 11 additions and 5 deletions
@@ -96,10 +96,15 @@ here), the operator-tier event copies (Hungarian by design), the 18 counted form
- **Machine:** VM 9301 stopped and `qm destroy --purge`d; `/mnt/hdd_1/images/` holds only 9202's disk.
- **Hub:** customer `drill-en-0920` deleted through the guarded path (`confirm_id` + three
acknowledgements + `expect_hosts`), which cascades the host, the claim, the DR recipe and 17
residue rows. **The hub refused until the host went stale — 30 minutes after its last report
(R-599).**
- **ep0:** the WireGuard peer `10.77.0.5` the enrolment registered goes with the host delete, as on
2026-09-14.
residue rows. **The hub refused until the host went stale — 45 minutes after its last report
(`alerting.stale_threshold` in the deployed manifest, not the 30m literal in the checker's source;
R-599).**
- **ep0:** the WireGuard peer `10.77.0.5` the enrolment registered. **Checked on ep0 itself, not
inferred from the hub** — and it was still there 3 minutes after the cascade logged *full
teardown*. Watched until it went: **gone by 17:47:46Z**, about 6 minutes after the delete
(`wg show wg0 peers` 5 → 4). The mechanism works; the log line is premature about this layer.
Filed as **R-600**. The 2026-09-14 findings say the host delete removes it; measured, the host
delete removes the hub's RECORD and `wgsync` removes the peer on its next push.
**Untouched, and checked:** demo-hp guests **9201** and **9202** (running throughout, 24 containers
before and after), demo-felhom, DooPlex beyond the golden bake's own VM (reverted to `virgin`),