docs: customer-claim arc — REPORT/CONTEXT, G9 supersede, tester-agreement claim step, day0 D.3/D.4 gate, drill F-4/F-5 RESOLVED

Claude-Session: https://claude.ai/code/session_01NptTCFtu7dz2Ru89qHRagN
This commit is contained in:
2026-07-12 18:56:46 +02:00
parent 9a14f04819
commit 8ded485a58
6 changed files with 64 additions and 67 deletions
+7 -3
View File
@@ -153,9 +153,13 @@ inspected, never piped straight into a shell).
1. Run pre-flight first: same command with `--preflight-only` — prints PASS/FAIL, writes no state.
Confirms 9.x, `:53` free, ACL storages exist, pool membership.
2. Run the install. Peti sees the host-mutation disclosure and types his hostname to acknowledge.
3. **Set the dashboard password (G9).** The customer dashboard is open until the operator sets the
password via the hub config; set it at onboarding, along with the geo-restriction. Until then the
dashboard is publicly reachable — do not consider onboarding complete without it.
3. **Claim the dashboard (customer-claim model, controller v0.122.0 + hub v0.50.0 — supersedes the
old operator-set G9).** The dashboard is NOT open before the customer claims it: an unclaimed box
serves only the claim page. On the box's first report the hub emails a one-time **claim code** to
Peti's registered address; he opens `felhom.sajatfelhom.hu`, enters the code, and sets his OWN
password. The operator never sets or sees it. If the code didn't arrive, the "Új kód kérése"
button (or the operator's "Kód újraküldése" on the hub customer page) emails a fresh one. Set the
geo-restriction at onboarding as before. Onboarding is complete once Peti has claimed + logged in.
4. **Re-point the `sajatfelhom.hu` Cloudflare tunnel** at the new guest.
5. **Verify local backups are green** on his box (§4 — the honesty gate). Confirm a backup completes
to `<PETI-BACKUP-STORAGE>` and a restore-test passes mount-parity.