hub v0.115.0: host_* mails skip the quiet hour (ruling 2, R-529); ruling 1 recorded (CC may sign agent_update until the first paying customer)
gates / gates (push) Successful in 23s

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 10:53:22 +02:00
parent 351296114c
commit 926723749d
6 changed files with 60 additions and 6 deletions
@@ -101,6 +101,18 @@ instructions.
just set sizing + a threshold policy**, addable later without a redesign (Phase 4 §8). Out of scope
now.
### 3.1 Where the keys live, and who may sign, TODAY [operator ruling 1, 2026-09-16]
The two-key model above is unchanged. What the ruling settles is custody and reach **for this phase
only**: both keys sit on DooPlex at `/mnt/5_hdd/felhom.eu/felhom-op-operational` and
`felhom-rec-recovery` (plus `felhom_op_ed25519`), **0600, owner `kisfenyo`** — they arrived 0664 on
2026-09-15 and were tightened the same day (R-533). **CC may sign `agent_update` ops with the
operational key until the first PAYING customer exists; testers do not count.** Every signature is
per box (the blob binds `host_id`), so one box moves at a time and a fenced box cannot be swept along.
Proven twice: `demo-hp-bb76ea` 2026-09-15, `demo-felhom-8363b5` 2026-09-16. **Revisit on the first
sale** — at that point the key belongs behind the operator (or a hardware key, §7), and a fleet
rollout step still has to be designed (R-530).
## 4. Rotation & compromise recovery
The agents pin the operator public keys. The danger: rotation must **not** flow as plain hub config,