release 2026-10-10: hub 0.145.0 deployed (security check PASS live), controller 0.305.0 delivered, kernel button offers -22; R-921/R-922 released; R-925 consequences; build skill: sync only the hub when other resources drift
gates / gates (push) Successful in 6m26s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-10 10:02:33 +02:00
parent b4083a06ed
commit a406efc7d5
9 changed files with 149 additions and 6 deletions
+57
View File
@@ -0,0 +1,57 @@
# REPORT — 2026-10-10: the waiting fixes released (a security hole closed), and the kernel approval rule
| Part | What | Result |
|---|---|---|
| A1 | Hub 0.145.0 (operator present) | Deployed 07:51Z, `Deployment/hub` only; `/healthz` 200, `/system` 200; **live check of the hole: PASS** |
| A2 | Controller 0.305.0; agent | Controller on demo-hp, demo-felhom, Tester 1 (floors 07:58:50Z, all three healthy by 07:59:08Z). Agent: no change since 0.154.0 — no release |
| A3 | MAIL-HOLD after the deploy | Marker absent, no banner, 0 MAIL-HOLD log lines |
| B | Kernel approval rule (`09` §3 decision 195) | Built, red-proved, deployed; the System page offers **7.0.14-22** — not clicked |
**Register: before 137 · after 137 · opened 0 · closed 0.** R-921 and R-922 marked released; R-925 got two measured
consequences.
## A1 — hub 0.145.0
- Contents: the SECURITY fix (`/preferences`, `/notify` refuse another household's key), R-922 (`email_cleared`),
MAIL-HOLD, two log lines without the address, the kernel rule. `go test ./...` rc 0; CI 1624 (code), 1625 (manifest).
- **Image push:** DooPlex's saved registry login is stale since the R-925 rotation (token endpoint 401 for it, 200 for
the current one) — the push used a one-off `DOCKER_CONFIG` login in the scratchpad, password file→stdin, shredded after.
- **Deploy:** the `felhom` app also showed 3 Secrets + `Deployment/umami` OutOfSync (R-925's de-gitting); a whole-app sync
would have pushed git's view over the rotated Secrets, so only `Deployment/hub` was synced. Pod image 0.145.0, log
`felhom-hub 0.145.0 starting`.
- **Live check (two channels):** Tester 1's key (read file→file from its controller.yaml, 64 chars, never printed):
own household, own settings → **200**; demo-felhom's household, demo-felhom's own settings → **403 „customer_id does
not match the key"**. Second channel: both households' stored rows hashed from a hub DB copy (with -wal/-shm) before
the deploy and after.
- **My mistake, corrected:** the control request stored Tester 1's event list as `["null"]` — my baseline script read
the stored JSON `null` as a list holding the word null. No real event was enabled by it. Restored with the same
own-household request carrying `enabled_events: null`; both rows then **equal the pre-deploy baseline** (hashes).
## A2 — controller 0.305.0
R-921 pre-check + R-922 `email_cleared`. CI 1627; image in the registry (anonymous 200). Floors 0.305.0 with MinAgent
0.131.0 for demo-hp, demo-felhom, tester-1; global floor and Tester 2 untouched. Read-back per box: sudo
`felhom-priv-apply controller-image 9201` → `WROTE … 0.305.0` → agent „new controller healthy" (host journal) and
`docker ps` 0.305.0 healthy (guest).
## B — the kernel rule
`KernelStatus` now offers the newest kernel in every ring-0 box's set of kernels booted healthily after a night stage;
per box and kernel only the newest ended step counts. 6 tests (`kernel_approval_test.go`); against the old function two
fail (today's case: „booted different kernels" where -22 was due; and the fell-back case). Behaviour change to note: a
box whose NEWEST step fell back on -23 no longer blocks the button — -22 (healthy earlier) is offered instead.
Live: the System page shows „Approve kernel set" (2 packages, first seen 07:52Z); the hub DB's candidate is
`proxmox-kernel-7.0` + `proxmox-kernel-7.0.14-22-pve-signed`. `11` §5.11 and `09` §3 updated; poster facts: no fact
changed (it says only „the operator approves on the System page").
## Instruction-file edit (rule 5)
`skills/felhom-build-deploy/SKILL.md`, hub step 4: added — read what is OutOfSync before syncing; if more than
`Deployment/hub`, sync only it (command given); a 401 push from DooPlex is the stale login (R-925). Why: both measured today.
## Not done
R-922 live (a real household clear) and R-921 live (a two-tier night) — not exercised today. No release of the agent.
## Decisions for the operator
1. **Refresh DooPlex's registry login** (`docker login gitea.dooplex.hu` with the new admin password, once, at your
keyboard; or a scoped push token). Pick: do it. **If you do nothing:** every build session must use a one-off login,
and a session that does not know this stops at the push.
2. **„Approve kernel set" for 7.0.14-22** — yours to click. Pick: click it (both demo boxes booted -22 healthily; ring 1
still takes it only by a signed job). **If you do nothing:** ring 1 gets no kernel; tonight demo-hp moves to -23, and
once it boots -23 healthily the button will offer -23 instead.
+15 -2
View File
@@ -2,8 +2,21 @@
**Ready for the first real tester (Tester-2): yes. Tester 2 (a laptop) is off; nothing was sent to it.**
**Updated 2026-10-09 (afternoon): hub 0.144.0; demo-hp, demo-felhom and Tester 1 run agent 0.154.0 and controller
0.304.0. The open-items list is at 138. Reports: `REPORT-break-the-circle-2026-10-09.md`, `REPORT-dooplex-survival-2026-10-09.md`, `REPORT-day4-2026-10-09.md`.**
**Updated 2026-10-10: hub 0.145.0; demo-hp, demo-felhom and Tester 1 run agent 0.154.0 and controller
0.305.0. The open-items list is at 137. Reports: `REPORT-release-2026-10-10.md`, `REPORT-break-the-circle-2026-10-09.md`, `REPORT-dooplex-survival-2026-10-09.md`, `REPORT-day4-2026-10-09.md`.**
## Saturday 2026-10-10: released — the security hole is closed, and the kernel button shows
- **Hub 0.145.0 is live** (you were present). One box's key could change another household's mail settings. Now it
cannot: checked live with Tester 1's key against demo-felhom — refused (403); the same key for its own household —
accepted. Nothing changed in either household.
- **Controller 0.305.0 runs on demo-hp, demo-felhom and Tester 1.** The agent did not change (still 0.154.0).
- **Also live:** a household's cleared mail address is deleted; a restored hub can start quiet; a backup no longer
stops the apps while the box's other backup is still running.
- **„Approve kernel set" shows now, for 7.0.14-22** (your new rule: the newest kernel every demo box started
healthily). Not clicked — that is yours.
- **Found on the way:** DooPlex's saved login for the image registry still has the old password (it changed
yesterday), so builds cannot push until it is refreshed. I used a one-off login and destroyed it.
## Evening (2026-10-09): the system poster is in the repository, and staying true is now a rule
@@ -0,0 +1,25 @@
== 2026-10-10T07:59:12Z read-back
--- demo-hp
agent: felhom-agent 0.154.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0 Up 11 seconds (healthy)
StartedAt=2026-10-10T07:59:02.745744507Z
2026-10-10T09:59:00+02:00 demo-hp sudo[894563]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/local/sbin/felhom-priv-apply controller-image 9201
2026-10-10T09:59:01+02:00 demo-hp felhom-priv-apply[894595]: felhom-priv-apply: WROTE controller-image 9201 gitea.dooplex.hu/admin/felhom-controller:0.305.0
2026-10-10T09:59:08+02:00 demo-hp felhom-agent[1262]: time=2026-10-10T09:59:08.372+02:00 level=INFO msg="controller-swap: new controller healthy" vmid=9201 target=gitea.dooplex.hu/admin/felhom-control
--- felhom-pve
agent: felhom-agent 0.154.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0 Up 14 seconds (healthy)
StartedAt=2026-10-10T07:58:58.628209837Z
2026-10-10T09:58:56+02:00 demo-felhom sudo[284694]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/local/sbin/felhom-priv-apply controller-image 9201
2026-10-10T09:58:57+02:00 demo-felhom felhom-priv-apply[284701]: felhom-priv-apply: WROTE controller-image 9201 gitea.dooplex.hu/admin/felhom-controller:0.305.0
2026-10-10T09:59:07+02:00 demo-felhom felhom-agent[1205]: time=2026-10-10T09:59:07.187+02:00 level=INFO msg="controller-swap: new controller healthy" vmid=9201 target=gitea.dooplex.hu/admin/felhom-con
--- root@192.168.0.154
agent: felhom-agent 0.154.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0
gitea.dooplex.hu/admin/felhom-controller:0.305.0 Up 13 seconds (healthy)
StartedAt=2026-10-10T07:59:02.717345534Z
2026-10-10T09:59:00+02:00 felhom sudo[418770]: felhom-agent : PWD=/ ; USER=root ; COMMAND=/usr/local/sbin/felhom-priv-apply controller-image 9201
2026-10-10T09:59:01+02:00 felhom felhom-priv-apply[418798]: felhom-priv-apply: WROTE controller-image 9201 gitea.dooplex.hu/admin/felhom-controller:0.305.0
2026-10-10T09:59:08+02:00 felhom felhom-agent[1161]: time=2026-10-10T09:59:08.339+02:00 level=INFO msg="controller-swap: new controller healthy" vmid=9201 target=gitea.dooplex.hu/admin/felhom-controll
@@ -0,0 +1,7 @@
== floors 2026-10-10T07:58:50Z: 0.305.0 with min_agent 0.131.0; global floor not touched; Tester 2 not touched
demo-hp: 303 Location: /customers/demo-hp?flash=floor_set
demo-felhom: 303 Location: /customers/demo-felhom?flash=floor_set
tester-1: 303 Location: /customers/tester-1?flash=floor_set
2026/10/10 09:58:50 [INFO] Customer demo-hp controller-version floor override set to "0.305.0" (declared MinAgent "0.131.0")
2026/10/10 09:58:50 [INFO] Customer demo-felhom controller-version floor override set to "0.305.0" (declared MinAgent "0.131.0")
2026/10/10 09:58:51 [INFO] Customer tester-1 controller-version floor override set to "0.305.0" (declared MinAgent "0.131.0")
@@ -0,0 +1,23 @@
## 2026-10-10T07:52:30Z after the deploy
GET /health: 302
GET /system: 200 26979 bytes; MAIL-HOLD banner on the page: False
MAIL-HOLD marker in /data: absent
hub log MAIL-HOLD lines since start: 0
GET /healthz: 200
## live check of the hole (each request sends that household's CURRENT settings unchanged; the key is never printed)
control (own household): POST /api/v1/preferences customer_id=tester-1 with Tester 1's key -> 200 {"status":"ok"}
TEST (another household): POST /api/v1/preferences customer_id=demo-felhom with Tester 1's key -> 403 Forbidden: customer_id does not match the key
RESULT: PASS — another household's settings refused, own accepted
## the stored rows after (hub DB copy with -wal/-shm, read-only, shredded) — compared with the baseline taken before the deploy
demo-felhom row present sha256: 5ef8fc1ff15b
tester-1 row present sha256: 38de0bad97e1
demo-felhom UNCHANGED
tester-1 CHANGED
hub log for the two requests:
2026/10/10 09:52:48 [INFO] Notification preferences updated for tester-1: address set=true, events=[null]
## 2026-10-10T07:53:23Z CORRECTION: the control request stored tester-1's events as ["null"] (the baseline script misread the stored JSON null as a list holding the word null; no real event became enabled). Restored with the same own-household request carrying enabled_events: null
restore POST (own household) -> 200
demo-felhom row present sha256: 5ef8fc1ff15b
tester-1 row present sha256: 5583ffee1d37
demo-felhom UNCHANGED vs the pre-deploy baseline
tester-1 UNCHANGED vs the pre-deploy baseline
@@ -0,0 +1,8 @@
2026-10-10T07:51:41Z
operation: Succeeded
Deployment/hub Synced deployment.apps/hub configured
Waiting for deployment "hub" rollout to finish: 0 of 1 updated replicas are available...
deployment "hub" successfully rolled out
hub-d9b69dc69-cthcb gitea.dooplex.hu/admin/felhom-hub:0.145.0 ready=true
2026/10/10 09:51:47 [INFO] felhom-hub 0.145.0 starting
2026/10/10 09:52:15 [INFO] Listening on :8080
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+6 -1
View File
@@ -161,7 +161,12 @@ is never placed on the system by an interactive install, so day-0 rides a `.deb`
# 1. commit+push code 2. build+push image (LOCAL)
cd $FELHOM_ROOT/build/felhom-hub && ./build.sh <VER> --push
# 3. bump manifests/hub.yaml image tag → <VER>, commit, push
# 4. hard-refresh + sync (argocd CLI is not logged in — drive the Application CR)
# 4. hard-refresh, then READ what is OutOfSync before syncing. If anything besides Deployment/hub is OutOfSync
# (since 2026-10-09: three Secrets de-gitted by R-925 + Deployment/umami), sync ONLY the hub — a whole-app sync
# pushes git's view over rotated live Secrets:
# sudo kubectl -n argocd patch application felhom --type merge -p '{"operation":{"initiatedBy":{"username":"cc"},"sync":{"revision":"<sha>","resources":[{"group":"apps","kind":"Deployment","name":"hub","namespace":"felhom-system"}]}}}'
# Image push 401 "unauthorized" from DooPlex = its saved Docker login predates the R-925 rotation (see R-925).
# (argocd CLI is not logged in — drive the Application CR)
sudo kubectl -n argocd annotate application felhom argocd.argoproj.io/refresh=hard --overwrite; sleep 8; sudo kubectl -n argocd get application felhom -o jsonpath='{.status.sync.status} {.status.sync.revision}{"\n"}'
sudo kubectl -n argocd patch application felhom --type merge -p '{"operation":{"initiatedBy":{"username":"cc"},"sync":{"syncStrategy":{"apply":{}}}}}'
# 5. verify: Synced/Healthy + rollout + image tag + startup log