drill 0242: teardown complete in three layers; R-501 filed
gates / gates (push) Successful in 19s

Machine: VM 330 destroyed with its disks. Host: ISO and scratch removed,
~8.5 GiB returned on nvme-scratch. Hub: customer drill0242 DELETED via the
cascade (journal #17), pages 404; its ep0 WireGuard peer dropped at the next
full-list push. Evidence pulled before the destroy. R-501: the documented
CI-check recipe reads only the last jobs page, which is not in id order.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-14 16:40:59 +02:00
parent 38848ffbeb
commit 8c7f882d1c
5 changed files with 73 additions and 4 deletions
@@ -480,3 +480,17 @@ the lock is honest about its length and lifts on time. Two properties recorded,
household out for 15 minutes, by design against guessing; and the lockout e-mail went to the
**operator only** (`Operator email sent for drill0242/claim_lockout`), while the screen tells the
customer.
## Teardown — three layers (`teardown-before.txt`, `teardown-layer1.txt`, `teardown-layer2.txt`, `teardown-layer3-hub.txt`)
Evidence was copied off the box **before** the destroy (`box-logs-final/`, 14:16, secret sweep 0).
| layer | UTC | result |
|---|---|---|
| **1. machine** | 14:16:23 | `qm destroy 330 --purge` → `qm list` empty; `/mnt/hdd_1/images/330` gone; `images/9202` untouched |
| **2. host** | 14:16:27 | ISO removed (0 left); `/root/drill0242` shredded, removed; `nvme-scratch` used **19 059 372 → 10 130 532 KiB**; `local` **24 768 200 → 23 013 832 KiB**; `local-lvm` 44.17 % before and after; 9201 and 9202 running; `vmbr9` pre-existed |
| **3. hub** | 14:35:15 | host stale at 14:34:45 (true `host_stale` operator mail); **customer DELETE cascade COMPLETE** (journal #17); customer and host pages 404; lists 0 (control 1) |
| 3b. ep0 peer | 14:40:00 | `10.77.0.5/32` removed at the 14:39:30 periodic push (5 → 4 peers); 4 m 14 s after the delete; control peer present |
**Disposition of `drill0242`: DELETED.** The hub's event stream and the three operator mails
(`claim_lockout`, `host_stale`, and the bind/enrol log lines) are append-only and stay, by design.
@@ -0,0 +1,29 @@
=== LAYER 3 — the hub 2026-09-14T14:35:15Z
ep0 WG peer for 10.77.0.5 BEFORE: 1
delete POST: HTTP/1.1 303 See Other Location: /configs?flash=deleted
customer page: 404
host page: 404
configs list mentions drill0242: 0 (control, a live customer 'enkisfelhom': 1)
hosts list mentions drill0242: 0
ep0 WG peer for 10.77.0.5 AFTER: 1 (control, demo-hp 10.77.0.3: 1)
--- hub log
2026/09/14 16:34:45 [INFO] Host staleness: drill0242-3f4b42 ok → stale (host_stale)
2026/09/14 16:34:46 [INFO] Operator email sent for drill0242/host_stale
2026/09/14 16:35:16 [INFO] customer DELETE cascade started for drill0242 (journal #17, 1 host(s))
2026/09/14 16:35:16 [INFO] delete drill0242: host drill0242-3f4b42 deleted (escrow DEMOTED to retained custody)
2026/09/14 16:35:17 [INFO] tenantsync: deprovision ok for drill0242 (ns=drill0242, existed=false)
2026/09/14 16:35:17 [INFO] reset drill0242: PBS tenancy deprovisioned
2026/09/14 16:35:17 [INFO] [claim] reset to unclaimed for drill0242 (customer RESET) — next onboarding mints a fresh code
2026/09/14 16:35:17 [INFO] delete drill0242: residue purged (reports=9 app_telemetry=16 app_log_tails=0 log_tail_requests=0 notif_prefs=1 selfbind_tokens=1 appliance_registrations=1)
2026/09/14 16:35:17 [INFO] customer DELETE cascade COMPLETE for drill0242 (journal #17) — full teardown
=== ep0 re-check 14:37:21
peer 10.77.0.5: 1 control 10.77.0.3: 1
peer config files naming 10.77.0.5: 1
--- hub log wg lines
2026/09/14 16:29:30 [INFO] wgsync: pushed 5 peers to 167.233.158.164:22
2026/09/14 16:34:30 [INFO] wgsync: pushed 5 peers to 167.233.158.164:22
=== ep0 re-check after the next wgsync push 14:40:00
peer 10.77.0.5: 0 control 10.77.0.3: 1
config files naming 10.77.0.5: 0
2026/09/14 16:39:30 [INFO] wgsync: pushed 4 peers to 167.233.158.164:22