diff --git a/CONTEXT.md b/CONTEXT.md index f4b3583..c3041f8 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -3,6 +3,14 @@ > Created with the REUSE.md rollout (2026-07-03). Authoritative history: `hub/CHANGELOG.md` (hub), > `website/CHANGELOG.md`, `scripts/CHANGELOG.md`; end-of-task detail in `REPORT.md`. +- **2026-07-05 — TASK G1 SHIPPED: management-plane break-glass (hub v0.34.1 + installer; agent + v0.71.0)** — prereq for felhom-sshd (H1). Hub: `store.host_recovery` vault (per-host root@pam + console password; `PUT /hosts/{id}/recovery-credential` self-scoped + `GET /admin/hosts/{id}/ + recovery-credential` global-only, secret never logged) + `host_mgmtplane` monitor raising + `mgmt_plane_healed`. Installer: `step_break_glass` (generate+set+vault root@pam, `--rotate-recovery`) + + `install_mgmt_watchdog` (the 3 host artifacts, RuntimeDirectory-guarded). Live-validated: + agent-independent `/run/sshd` auto-heal in 30.0s; warning fired end-to-end; break-glass + vault→retrieve→PVE-ticket(200). felhom-pve root@pam is now the vaulted value. - **2026-07-04 — S3 SHIPPED: agent WG tunnel (felhom-agent v0.64.0; docs-only here)** — the doc-06 §3.3 handshake is now END-TO-END LIVE on demo: agent keygen → `POST /hosts/{id}/wg` → desired-state `wireguard` block → agent-managed `wg-quick@wg-felhom` → PBS page over