ten answers: golden 0.300.0 baked (pinned), delivery evidence; R-645 R-856 R-747 R-774 R-734 R-624 R-502 R-99 closed; R-890/R-891 filed; 03 gains FELHOM_FSTRIM and GET /host/crash-guard (149 -> 143)
gates / gates (push) Successful in 2m47s
gates / gates (push) Successful in 2m47s
CI 1423 (929e59e8) was red on golden-currency: it read controller v0.300.0 before this commit recorded its golden.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -118,6 +118,7 @@ fixed file, delivered by the signed config bundle):
|
||||
| `FELHOM_OOB` | the OOB firewall sets | `add element` takes exactly `{ <ip>[/n] }` or `{ <port> }` — no chained command | — |
|
||||
| `FELHOM_PBSDR` / `FELHOM_BACKUPTARGET` | PBS DR entry; whole-system backup target | unchanged: the arguments stay coarse, and the root wrappers (`felhom-pbs-apply`, `felhom-backup-target-apply`) are the gate (fixed verbs, own validation) | coarse argv into a checking wrapper |
|
||||
| `FELHOM_ESCROW` | the recovery-code ceremony (runs the agent binary as root) | the binary is only ever an operator-signed one (`FELHOM_SELFUPDATE`); as root it pins the PVE secret dir and the WG state dir, refuses a storage id that is a path, and reads its two staged files by walking the path with `openat(O_NOFOLLOW)` (no symlink anywhere) | **by design the agent relays R**, so a compromised agent can still learn this box's PBS key through the ceremony — not root, but the backup key |
|
||||
| `FELHOM_FSTRIM` | the weekly disk trim of each customer guest (R-444, `09` §3 decision 139; agent v0.149.0) | ONE regex-anchored rule `/usr/sbin/pct ^fstrim [0-9]+$` — no option, no second vmid, no chained command (pinned by `TestSudoersFstrimRuleIsExact`; read live on demo-hp and demo-felhom 2026-10-06: `pct fstrim 9201` allowed, `--ignore-mountpoints`, `;x`, `9201 9202`, `pct destroy` refused) | — |
|
||||
| `FELHOM_SELFHEAL` / `FELHOM_GUESTNET` / `FELHOM_OSAPPLY` | networking restart; guest DHCP watchdog; OS updates | exact; `felhom-os-apply --plan …` stays the glob line on purpose — the bundle's own self-check reads that exact text, and the wrapper refuses any other plan path (R1) | — |
|
||||
|
||||
**What this does not change.** The operator key (`/etc/felhom/operator-signers`, root-owned, never a bundle path) stays
|
||||
@@ -229,6 +230,10 @@ The controller (in its LXC) reaches the agent (on the host) over the local bridg
|
||||
- `POST /backup` — request a backup-now of *this* guest (enqueued; non-destructive).
|
||||
- `GET /backup/due` — whether a policy-scheduled backup is due for *this* guest, so the controller can quiesce then call `POST /backup` (the app-consistent path, §8).
|
||||
- `GET /backup/status`, `GET /restore-test/status` — read-only status for the controller's UI.
|
||||
- **Crash-boot fact (R-856, agent v0.149.0):** `GET /host/crash-guard` — the host crash guard's last-boot record
|
||||
(`present`, `last_boot_at`, `last_boot_unclean`, `tripped`) read from `/var/lib/felhom-crash-guard/state.json`; a missing
|
||||
or garbled file answers 200 `present:false`, an older agent 404 — both read as a normal boot. The controller waits
|
||||
~15 min with app mails after a crash boot (`09` §3 decision 143).
|
||||
- **Host metrics (slice 9):** `GET /host/metrics` — **host-wide** health for the customer's
|
||||
monitoring view: cpu%/mem/load/uptime, **CPU/chassis temperature** (`cpu_temp_c`, nullable —
|
||||
"n/a" when the hardware exposes no sensor), and per-storage capacity (total/used/fraction,
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
== controller delivery 2026-10-06T10:23:27Z
|
||||
demo-hp + demo-felhom felhom-controller:0.300.0 (healthy) 10:22:07Z; tester-1 hub page 'Controller elindult (0.300.0)'
|
||||
R-856 live read (both NORMAL branches, through the real agent route):
|
||||
demo-hp: [deadapp] boot grace 1m30s: the host's last unclean boot (2026-10-05T07:56:41Z) is not the one this start followed (R-856)
|
||||
demo-felhom: [deadapp] boot grace 1m30s: the host's last boot was clean (R-856)
|
||||
bundle e182c82d on demo-hp (BUNDLE DONE 12:06:31 local, capability probe 68/68) and demo-felhom (config-bundle.json); sudo -l on demo-felhom: fstrim allowed, destroy refused
|
||||
@@ -0,0 +1,9 @@
|
||||
== 2026-10-06T09:55:58Z
|
||||
healthz 200
|
||||
system 200
|
||||
image=gitea.dooplex.hu/admin/felhom-hub:0.139.0
|
||||
sync=Synced health=Healthy rev=929e59e8f4fdf1163313729113ba29f145854597
|
||||
2026/10/06 11:55:10 [INFO] felhom-hub 0.139.0 starting
|
||||
2026/10/06 11:55:10 [INFO] off-site secrets sealed at rest (0 legacy plaintext row(s) sealed now)
|
||||
2026/10/06 11:55:10 [INFO] console passwords sealed at rest (0 legacy plaintext row(s) sealed now)
|
||||
2026/10/06 11:55:10 [INFO] box secrets sealed at rest (0 legacy plaintext value(s) sealed now)
|
||||
@@ -0,0 +1,5 @@
|
||||
pct fstrim 9201: ALLOWED
|
||||
pct fstrim 9201 --ignore-mountpoints: refused
|
||||
pct fstrim 9201;x: refused
|
||||
pct fstrim 9201 9202: refused
|
||||
pct destroy 9201: refused
|
||||
@@ -0,0 +1,14 @@
|
||||
== System/hosts 2026-10-06T09:56:47Z: demo-hp, demo-felhom, tester-1 agent 0.149.0; Tester-2 0.142.0 (nothing sent)
|
||||
== agent_config_update 0.149.0 (bundle e182c82d…), 2026-10-06T09:56:47Z
|
||||
-- demo-hp-bb76ea
|
||||
signed: op=agent_config_update host=demo-hp-bb76ea guest="" key_id=felhom-op-1 nonce=58ab3d41a9318bfac142372f6362c2c0 expires=2026-10-06T10:41:47Z
|
||||
wrote envelope to <scratch>/env-demo-hp-bb76ea-acu.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
-- demo-felhom-8363b5
|
||||
signed: op=agent_config_update host=demo-felhom-8363b5 guest="" key_id=felhom-op-1 nonce=0fb920820f8499349e7f098f3008295f expires=2026-10-06T10:41:47Z
|
||||
wrote envelope to <scratch>/env-demo-felhom-8363b5-acu.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
-- tester-1-d70be4
|
||||
signed: op=agent_config_update host=tester-1-d70be4 guest="" key_id=felhom-op-1 nonce=8033f0f0d70cf5a5f7b3eb74aa0efc01 expires=2026-10-06T10:41:47Z
|
||||
wrote envelope to <scratch>/env-tester-1-d70be4-acu.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
@@ -0,0 +1,17 @@
|
||||
== vouch 2026-10-06T09:50:38Z: agent 0.149.0, golden 0.299.0, min_agent 0.131.0
|
||||
HTTP/1.1 303 See Other
|
||||
Location: /configuration?flash=artifacts_set
|
||||
2026/10/06 11:51:08 [INFO] Artifact manifest set: agent=0.149.0 golden=0.299.0 min_agent="0.131.0" wrapper_sha=false bundle_sha="e182c82dcf4a67faa3bcb74dbe4ffa7b06e0b27dc8451cb7574d6339ce91ad66"
|
||||
== agent_update 0.149.0 (sha 6bcae9c2…) signed with felhom-op-1, ttl 45m, 2026-10-06T09:51:11Z
|
||||
-- demo-hp-bb76ea
|
||||
signed: op=agent_update host=demo-hp-bb76ea guest="" key_id=felhom-op-1 nonce=07c59d5479139b7bc3807b977eb37729 expires=2026-10-06T10:36:11Z
|
||||
wrote envelope to <scratch>/env-demo-hp-bb76ea-au.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
-- demo-felhom-8363b5
|
||||
signed: op=agent_update host=demo-felhom-8363b5 guest="" key_id=felhom-op-1 nonce=9ba373bce19019bc3a76ecb3b429c666 expires=2026-10-06T10:36:11Z
|
||||
wrote envelope to <scratch>/env-demo-felhom-8363b5-au.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
-- tester-1-d70be4
|
||||
signed: op=agent_update host=tester-1-d70be4 guest="" key_id=felhom-op-1 nonce=7ca22f2ed83309082d779840275822da expires=2026-10-06T10:36:11Z
|
||||
wrote envelope to <scratch>/env-tester-1-d70be4-au.json
|
||||
uploaded signed op to the hub jobs queue
|
||||
@@ -0,0 +1,11 @@
|
||||
== vouch 2026-10-06T10:21:01Z: agent 0.149.0, golden 0.300.0, min_agent 0.131.0
|
||||
HTTP/1.1 303 See Other
|
||||
Location: /configuration?flash=artifacts_set
|
||||
== floors 2026-10-06T10:21:30Z: 0.300.0 / min_agent 0.131.0
|
||||
demo-hp: Location: /customers/demo-hp?flash=floor_set
|
||||
demo-felhom: Location: /customers/demo-felhom?flash=floor_set
|
||||
tester-1: Location: /customers/tester-1?flash=floor_set
|
||||
2026/10/06 12:21:30 [INFO] Artifact manifest set: agent=0.149.0 golden=0.300.0 min_agent="0.131.0" wrapper_sha=false bundle_sha="e182c82dcf4a67faa3bcb74dbe4ffa7b06e0b27dc8451cb7574d6339ce91ad66"
|
||||
2026/10/06 12:21:31 [INFO] Customer demo-hp controller-version floor override set to "0.300.0" (declared MinAgent "0.131.0")
|
||||
2026/10/06 12:21:31 [INFO] Customer demo-felhom controller-version floor override set to "0.300.0" (declared MinAgent "0.131.0")
|
||||
2026/10/06 12:21:31 [INFO] Customer tester-1 controller-version floor override set to "0.300.0" (declared MinAgent "0.131.0")
|
||||
@@ -26,6 +26,21 @@
|
||||
|
||||
---
|
||||
|
||||
## 2026-10-06 (midday) — the operator's ten answers built
|
||||
|
||||
The full text of every row below: `git show 929e59e8:documentation/backlog/OPEN-ITEMS.md`.
|
||||
|
||||
| Row | What | Closed | Evidence |
|
||||
|---|---|---|---|
|
||||
| **R-774** | **[P3-LOW] Two things the new apps' pages do not show yet: Karakeep's mail-ON path is unproven, and its official phone app reports crashes to its makers.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 148): Karakeep's page says its phone app sends crash reports | catalog `ec72c9d` (live `1938921`): hu + en. The row's other half — one password-reset mail from Karakeep on a hub-enabled box — is NOT covered by this ruling; it is not built. |
|
||||
| **R-734** | **[P3-LOW] The harness marks immich `files_may_change` because immich rewrites six 13-byte `.immich` folder markers at every start.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 145): the update test ignores listed marker files, each with a reason | catalog `b0939cf`: `scripts/upgrade-test.py` per-app list, immich's six `.immich` markers first; a listed file is ignored only when changed/added and ≤ 64 bytes; verdict records `files_ignored`; harness v5. `MarkerIgnore` tests on the measured immich lists; red-proof: an ignore-all mutant fails two tests. |
|
||||
| **R-645** | **[P3-LOW] Lifting an update hold by the operator CLI lets the recovery unit be re-captured with the FAILED new definition within seconds — the copy the hold sentence names is overwritten.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 142): the night backup skips an app that runs another version than it saved | controller `2d63714` (v0.300.0): every night leg (DB dump, volume dump, unit capture, Tier 2) skips an app whose pin is not what it runs; one amber line on the backups page (`backup.status.version_skip`, hu + en); unknown never skips. `TestR645_HandLiftedHoldKeepsTheGoodUnit` runs the night + Tier 2 on the hand-lift shape (unit checksum unchanged); red-proof: without the skip the unit was rewritten with `docmost:0.96.0`. Delivered 10:22Z to the three boxes. **Residual, stated:** after the lift the boot reconciler may START the app on the new version, and then pin = running — the ruling's predicate protects the window between the lift and that start (the measured overwrite came 3 s after the restart); covering the started-new-version case is a design question, not built. |
|
||||
| **R-99** | Server-side prune **never removes** a phantom snapshot. Confirmed it does NOT count them toward `keep-last` (dry-run kept 2 real + the phantom) so there is **no retention/data-loss bug** — but one acc (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 140): phantom leftovers are deleted by a runbook — none exist today | `runbooks/pbs-phantom-cleanup.md` + `pbs-phantom-list.py`; read-only listing of ep0 2026-10-06: 9 snapshots in 5 namespaces, all ≥ 369,808,250 B, all verification `ok`, every directory has its manifest — **no phantom, nothing deleted**, real counts unchanged (`audits/ten-answers-2026-10-06/r99-ep0-listing.txt`). The agent's WARN for a phantom now names the runbook (agent `be398f9`, v0.149.0, `TestRejectedArchiveWarnNamesTheCleanupRunbook`). |
|
||||
| **R-747** | **[P3-LOW] A stranger can lock the household out of mealie with five wrong logins.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 144): mealie's page says five wrong logins lock the account for 1–2 hours | catalog `ec72c9d` (live `1938921`): a new last first step, hu + en, informal. The 1–2 h is true where mealie runs with the one-hour lock setting; an already-installed mealie gets it when its compose is rendered again (still unmeasured, as the row said). |
|
||||
| **R-856** | **A crash restart reaches the household twice: the hub's "restarted after an unexpected stop" line AND the controller's app mails.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 143): app mails wait ~15 minutes after a crash boot | controller `c393d85` (v0.300.0, `internal/crashboot`) + agent `f277e61` route `GET /host/crash-guard` (v0.149.0). Tests + red-proofs both halves (crash boot holds the mails at +3m30s; a normal boot keeps 90 s; an agent 404 = normal). **Live, through the real route (`audits/ten-answers-2026-10-06/delivery/controller-and-bundle.txt`):** demo-hp logged „boot grace 1m30s: the host's last unclean boot (2026-10-05T07:56:41Z) is not the one this start followed", demo-felhom „… the host's last boot was clean". The crash branch itself was not shown live (no crash allowed by the brief). |
|
||||
| **R-502** | **[P3-LOW] The bootstrap regression harness is run by NO gate and NO CI — and it had never exercised the pairing banner.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 147): the ISO first-boot test is a gate, full runs only | felhom.eu `9d39faab`: `scripts/iso_bootstrap_gate.py`, fast=False (CI and the pre-push hook call --fast, so never), NOT CHECKED (exit 2) without docker or the image; a built-in decoy every full run; 9 docker-free decoy tests. **First real full run on DooPlex 2026-10-06** (after building `felhom-iso-assistant:trixie`): 73 harness checks green, the built-in decoy convicted (`audits/ten-answers-2026-10-06/r502-first-full-run.txt`). |
|
||||
| **R-624** | **[P3-LOW] Three of the catalog's apps cannot be seeded by ANY headless route, and for two of them that is a deliberate security decision — so the upgrade harness has a permanent ceiling nobody has written down.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 146): the bench may seed vaultwarden through its admin route, bench only | catalog `aed80ee`. **Proven on the recreated bench 9401 (2026-10-06):** admin sign-in 200, invite 200, invited registration 200, seed read back before AND after the move; `.env` shredded, 64-hex grep 0 (control 1), `VW_ADMIN=` 0; WITHOUT the run flag the admin route is not tried and the verdict is `inconclusive` (`audits/ten-answers-2026-10-06/r624-bench/`). The move used (1.36.0-alpine → 1.36.0) failed on health — the non-alpine image fails the alpine health check; that is the test target, not the seed. Zipline needs no held secret (its `/api/setup`); its redaction is covered by `SecretHygiene`. **New question filed as R-890:** the ladder writer needs both venues, so a vaultwarden step still cannot be written. |
|
||||
|
||||
## 2026-10-06 (midday) — the ten answers
|
||||
|
||||
The full text of every row below: `git show 8c65ff0c:documentation/backlog/OPEN-ITEMS.md`.
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,3 @@
|
||||
== round trip 2026-10-06T10:20:16Z: downloaded golden.tar.zst 0.300.0 from the registry
|
||||
sha256 fb2e9d427917f0ba14dc646c7575789577b7826dc9469587cfcf066a623f1b93
|
||||
bake fb2e9d427917f0ba14dc646c7575789577b7826dc9469587cfcf066a623f1b93
|
||||
@@ -0,0 +1,29 @@
|
||||
# Golden 0.300.0 — bake + publish, 2026-10-06 (midday; R-645 + R-856 release)
|
||||
|
||||
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM on DooPlex.
|
||||
|
||||
| | Previous (`../golden-0.299.0-2026-10-06/`) | This bake |
|
||||
|---|---|---|
|
||||
| `build-golden.sh` | v3.2.0 | same file, unchanged |
|
||||
| Controller | `felhom-controller:0.299.0` | **`felhom-controller:0.300.0`** (MinAgent 0.131.0, unchanged) |
|
||||
| Docker engine | approved set `os-docker-20261004-142842` | same — `GOLDEN_DOCKER_PKGS` set in the runner from the start (the hub's System page still names `os-docker-20261004-142842`, read 2026-10-06 12:07) |
|
||||
|
||||
## Pass markers (from `bake.log`, this folder)
|
||||
|
||||
```
|
||||
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie … docker-ce=5:29.8.2-1~debian.13~trixie …
|
||||
docker OK (overlay2; data-root /var/lib/docker)
|
||||
INFO: including mount point rootfs ('/') in backup
|
||||
INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||||
[golden] upload OK (HTTP 201)
|
||||
GOLDEN_VERSION=0.300.0
|
||||
GOLDEN_SHA256=fb2e9d427917f0ba14dc646c7575789577b7826dc9469587cfcf066a623f1b93
|
||||
```
|
||||
|
||||
No `excluding`, no `FATAL`, no `GOLDEN_DOCKER_PKGS not set` (a grep for `not set` hits only the six `locale: Cannot set LC_…`
|
||||
noise lines, as in the 0.298.0 log). Round trip: the registry's file hashed = the bake's sha (`02-round-trip.txt`).
|
||||
Token: unit properties grep = 0; saved log grep = 0, with a working control (= 1 on a copy with the token appended).
|
||||
|
||||
## Teardown
|
||||
|
||||
Build guest 9100 destroyed (`pct list` empty); token, runner and log shredded in the VM; VM off (no qemu process); disk on `virgin`.
|
||||
@@ -0,0 +1,337 @@
|
||||
[golden] build-golden.sh v3.2.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.300.0
|
||||
[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) …
|
||||
Logical volume "vm-9100-disk-0" created.
|
||||
Logical volume pve/vm-9100-disk-0 changed.
|
||||
Creating filesystem with 8388608 4k blocks and 2097152 inodes
|
||||
Filesystem UUID: 9393c493-7544-4a1a-8b51-e7a6aa2d8db4
|
||||
Superblock backups stored on blocks:
|
||||
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
|
||||
4096000, 7962624
|
||||
Logical volume "vm-9100-disk-1" created.
|
||||
Logical volume pve/vm-9100-disk-1 changed.
|
||||
Creating filesystem with 6291456 4k blocks and 1572864 inodes
|
||||
Filesystem UUID: 2ae2821b-d92b-4beb-9b79-d39d031fe729
|
||||
Superblock backups stored on blocks:
|
||||
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
|
||||
extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst'
|
||||
Total bytes read: 553512960 (528MiB, 77MiB/s)
|
||||
Detected container architecture: amd64
|
||||
Creating SSH host key 'ssh_host_rsa_key' - this may take some time ...
|
||||
done: SHA256:q8xt00nBoIyZObiCoA5mkwkoTgxuaB/eXDt9GIKrA5M root@felhom-golden
|
||||
Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ...
|
||||
done: SHA256:w42bqsQvBtaxdH/xQtInvn6DLeGbjctlH07y8vWy3U8 root@felhom-golden
|
||||
Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ...
|
||||
done: SHA256:GQcwkCddr94rk8H8yer9bKsDzPog2WswWMc2e9gSVAg root@felhom-golden
|
||||
[golden] starting + installing Docker (official repo, trixie channel) …
|
||||
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
|
||||
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
|
||||
perl: warning: Setting locale failed.
|
||||
perl: warning: Please check that your locale settings:
|
||||
LANGUAGE = (unset),
|
||||
LC_ALL = (unset),
|
||||
LC_CTYPE = (unset),
|
||||
LC_NUMERIC = (unset),
|
||||
LC_COLLATE = (unset),
|
||||
LC_TIME = (unset),
|
||||
LC_MESSAGES = (unset),
|
||||
LC_MONETARY = (unset),
|
||||
LC_ADDRESS = (unset),
|
||||
LC_IDENTIFICATION = (unset),
|
||||
LC_MEASUREMENT = (unset),
|
||||
LC_PAPER = (unset),
|
||||
LC_TELEPHONE = (unset),
|
||||
LC_NAME = (unset),
|
||||
LANG = "en_US.UTF-8"
|
||||
are supported and installed on your system.
|
||||
perl: warning: Falling back to the standard locale ("C").
|
||||
locale: Cannot set LC_CTYPE to default locale: No such file or directory
|
||||
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
|
||||
locale: Cannot set LC_ALL to default locale: No such file or directory
|
||||
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
|
||||
perl: warning: Setting locale failed.
|
||||
perl: warning: Please check that your locale settings:
|
||||
LANGUAGE = (unset),
|
||||
LC_ALL = (unset),
|
||||
LC_CTYPE = (unset),
|
||||
LC_NUMERIC = (unset),
|
||||
LC_COLLATE = (unset),
|
||||
LC_TIME = (unset),
|
||||
LC_MESSAGES = (unset),
|
||||
LC_MONETARY = (unset),
|
||||
LC_ADDRESS = (unset),
|
||||
LC_IDENTIFICATION = (unset),
|
||||
LC_MEASUREMENT = (unset),
|
||||
LC_PAPER = (unset),
|
||||
LC_TELEPHONE = (unset),
|
||||
LC_NAME = (unset),
|
||||
LANG = "en_US.UTF-8"
|
||||
are supported and installed on your system.
|
||||
perl: warning: Falling back to the standard locale ("C").
|
||||
locale: Cannot set LC_CTYPE to default locale: No such file or directory
|
||||
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
|
||||
locale: Cannot set LC_ALL to default locale: No such file or directory
|
||||
installed: containerd.io 2.3.6-1~debian.13~trixie
|
||||
installed: docker-buildx-plugin 0.37.1-1~debian.13~trixie
|
||||
installed: docker-ce 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-ce-cli 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-ce-rootless-extras 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-compose-plugin 5.6.0-1~debian.13~trixie
|
||||
[golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a
|
||||
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49
|
||||
[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation …
|
||||
[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds …
|
||||
[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) …
|
||||
Unable to find image 'hello-world:latest' locally
|
||||
latest: Pulling from library/hello-world
|
||||
4f55086f7dd0: Pulling fs layer
|
||||
4f55086f7dd0: Verifying Checksum
|
||||
4f55086f7dd0: Download complete
|
||||
4f55086f7dd0: Pull complete
|
||||
Digest: sha256:5e23090353324d887c48ad5e5c56d294eab81588df9605b07d1afe895f9cc8f8
|
||||
Status: Downloaded newer image for hello-world:latest
|
||||
docker OK (overlay2; data-root /var/lib/docker)
|
||||
live-restore: on
|
||||
/var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4
|
||||
/mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4
|
||||
both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576
|
||||
[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.300.0 (no registry cred at deploy) …
|
||||
|
||||
WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'.
|
||||
Configure a credential helper to remove this warning. See
|
||||
https://docs.docker.com/go/credential-store/
|
||||
|
||||
0.300.0: Pulling from admin/felhom-controller
|
||||
774043ccc8cc: Pulling fs layer
|
||||
ab6b448d4be9: Pulling fs layer
|
||||
23a5bfa58353: Pulling fs layer
|
||||
862a57157567: Pulling fs layer
|
||||
009e99acf0ec: Pulling fs layer
|
||||
3b6997c6d048: Pulling fs layer
|
||||
862a57157567: Waiting
|
||||
009e99acf0ec: Waiting
|
||||
3b6997c6d048: Waiting
|
||||
774043ccc8cc: Verifying Checksum
|
||||
774043ccc8cc: Download complete
|
||||
862a57157567: Verifying Checksum
|
||||
862a57157567: Download complete
|
||||
23a5bfa58353: Verifying Checksum
|
||||
23a5bfa58353: Download complete
|
||||
009e99acf0ec: Verifying Checksum
|
||||
009e99acf0ec: Download complete
|
||||
3b6997c6d048: Verifying Checksum
|
||||
3b6997c6d048: Download complete
|
||||
ab6b448d4be9: Verifying Checksum
|
||||
ab6b448d4be9: Download complete
|
||||
774043ccc8cc: Pull complete
|
||||
ab6b448d4be9: Pull complete
|
||||
23a5bfa58353: Pull complete
|
||||
862a57157567: Pull complete
|
||||
009e99acf0ec: Pull complete
|
||||
3b6997c6d048: Pull complete
|
||||
Digest: sha256:4f0ff7a5bad6a6e3ee59ba81d9596892db6acc5e5834760d842bd94744c5f232
|
||||
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.300.0
|
||||
gitea.dooplex.hu/admin/felhom-controller:0.300.0
|
||||
[golden] asking the controller which infra images it manages …
|
||||
[golden] baking infra images (4): traefik:v3.7.13 cloudflare/cloudflared:2026.9.3 gtstef/filebrowser:1.5.6-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 …
|
||||
v3.7.13: Pulling from library/traefik
|
||||
e2de96513ba9: Pulling fs layer
|
||||
b686a4f73445: Pulling fs layer
|
||||
78cb21c375ca: Pulling fs layer
|
||||
acb2f33459b1: Pulling fs layer
|
||||
acb2f33459b1: Waiting
|
||||
b686a4f73445: Verifying Checksum
|
||||
b686a4f73445: Download complete
|
||||
e2de96513ba9: Verifying Checksum
|
||||
e2de96513ba9: Download complete
|
||||
acb2f33459b1: Verifying Checksum
|
||||
acb2f33459b1: Download complete
|
||||
e2de96513ba9: Pull complete
|
||||
78cb21c375ca: Verifying Checksum
|
||||
b686a4f73445: Pull complete
|
||||
78cb21c375ca: Pull complete
|
||||
acb2f33459b1: Pull complete
|
||||
Digest: sha256:24841fe2de7304c149343d877d2923b4c8800a38ba015dea9174c23b20e344a0
|
||||
Status: Downloaded newer image for traefik:v3.7.13
|
||||
docker.io/library/traefik:v3.7.13
|
||||
2026.9.3: Pulling from cloudflare/cloudflared
|
||||
2cc7ee286bf3: Pulling fs layer
|
||||
c172f21841df: Pulling fs layer
|
||||
218cf840d0d9: Pulling fs layer
|
||||
f6069939f718: Pulling fs layer
|
||||
d6b1b89eccac: Pulling fs layer
|
||||
2780920e5dbf: Pulling fs layer
|
||||
7c12895b777b: Pulling fs layer
|
||||
3214acf345c0: Pulling fs layer
|
||||
52630fc75a18: Pulling fs layer
|
||||
dd64bf2dd177: Pulling fs layer
|
||||
b839dfae01f6: Pulling fs layer
|
||||
ebddc55facdc: Pulling fs layer
|
||||
c4bc6f35ff5e: Pulling fs layer
|
||||
b96fe2995f90: Pulling fs layer
|
||||
58c0c263dc73: Pulling fs layer
|
||||
bd8962e29291: Pulling fs layer
|
||||
cac2ae0193cb: Pulling fs layer
|
||||
f0383d5ebc47: Pulling fs layer
|
||||
dd64bf2dd177: Waiting
|
||||
b839dfae01f6: Waiting
|
||||
ebddc55facdc: Waiting
|
||||
c4bc6f35ff5e: Waiting
|
||||
b96fe2995f90: Waiting
|
||||
58c0c263dc73: Waiting
|
||||
f6069939f718: Waiting
|
||||
d6b1b89eccac: Waiting
|
||||
2780920e5dbf: Waiting
|
||||
bd8962e29291: Waiting
|
||||
cac2ae0193cb: Waiting
|
||||
f0383d5ebc47: Waiting
|
||||
7c12895b777b: Waiting
|
||||
3214acf345c0: Waiting
|
||||
52630fc75a18: Waiting
|
||||
2cc7ee286bf3: Download complete
|
||||
c172f21841df: Verifying Checksum
|
||||
c172f21841df: Download complete
|
||||
2cc7ee286bf3: Pull complete
|
||||
218cf840d0d9: Download complete
|
||||
f6069939f718: Download complete
|
||||
d6b1b89eccac: Verifying Checksum
|
||||
d6b1b89eccac: Download complete
|
||||
2780920e5dbf: Download complete
|
||||
7c12895b777b: Verifying Checksum
|
||||
7c12895b777b: Download complete
|
||||
3214acf345c0: Verifying Checksum
|
||||
3214acf345c0: Download complete
|
||||
52630fc75a18: Verifying Checksum
|
||||
52630fc75a18: Download complete
|
||||
c172f21841df: Pull complete
|
||||
dd64bf2dd177: Verifying Checksum
|
||||
dd64bf2dd177: Download complete
|
||||
b839dfae01f6: Verifying Checksum
|
||||
b839dfae01f6: Download complete
|
||||
ebddc55facdc: Verifying Checksum
|
||||
ebddc55facdc: Download complete
|
||||
c4bc6f35ff5e: Download complete
|
||||
b96fe2995f90: Verifying Checksum
|
||||
b96fe2995f90: Download complete
|
||||
bd8962e29291: Verifying Checksum
|
||||
bd8962e29291: Download complete
|
||||
58c0c263dc73: Verifying Checksum
|
||||
58c0c263dc73: Download complete
|
||||
cac2ae0193cb: Verifying Checksum
|
||||
cac2ae0193cb: Download complete
|
||||
218cf840d0d9: Pull complete
|
||||
f0383d5ebc47: Verifying Checksum
|
||||
f0383d5ebc47: Download complete
|
||||
f6069939f718: Pull complete
|
||||
d6b1b89eccac: Pull complete
|
||||
2780920e5dbf: Pull complete
|
||||
7c12895b777b: Pull complete
|
||||
3214acf345c0: Pull complete
|
||||
52630fc75a18: Pull complete
|
||||
dd64bf2dd177: Pull complete
|
||||
b839dfae01f6: Pull complete
|
||||
ebddc55facdc: Pull complete
|
||||
c4bc6f35ff5e: Pull complete
|
||||
b96fe2995f90: Pull complete
|
||||
58c0c263dc73: Pull complete
|
||||
bd8962e29291: Pull complete
|
||||
cac2ae0193cb: Pull complete
|
||||
f0383d5ebc47: Pull complete
|
||||
Digest: sha256:072c067d25ccbe61d46e18f0d0723255f2bb5304f7317caa95b27031520ff92c
|
||||
Status: Downloaded newer image for cloudflare/cloudflared:2026.9.3
|
||||
docker.io/cloudflare/cloudflared:2026.9.3
|
||||
1.5.6-stable: Pulling from gtstef/filebrowser
|
||||
55afa1ecc21d: Pulling fs layer
|
||||
8ed8f35f8d4f: Pulling fs layer
|
||||
989b226a579c: Pulling fs layer
|
||||
660aeead31d5: Pulling fs layer
|
||||
4f4fb700ef54: Pulling fs layer
|
||||
adce24567e4c: Pulling fs layer
|
||||
f17ea56b313b: Pulling fs layer
|
||||
6b6f3b3efe88: Pulling fs layer
|
||||
4ed1ca4f3fce: Pulling fs layer
|
||||
e6fc9c6a5757: Pulling fs layer
|
||||
d47782d1182a: Pulling fs layer
|
||||
660aeead31d5: Waiting
|
||||
4f4fb700ef54: Waiting
|
||||
adce24567e4c: Waiting
|
||||
f17ea56b313b: Waiting
|
||||
6b6f3b3efe88: Waiting
|
||||
4ed1ca4f3fce: Waiting
|
||||
e6fc9c6a5757: Waiting
|
||||
d47782d1182a: Waiting
|
||||
55afa1ecc21d: Verifying Checksum
|
||||
55afa1ecc21d: Download complete
|
||||
660aeead31d5: Verifying Checksum
|
||||
660aeead31d5: Download complete
|
||||
4f4fb700ef54: Verifying Checksum
|
||||
4f4fb700ef54: Download complete
|
||||
8ed8f35f8d4f: Verifying Checksum
|
||||
8ed8f35f8d4f: Download complete
|
||||
989b226a579c: Verifying Checksum
|
||||
989b226a579c: Download complete
|
||||
f17ea56b313b: Verifying Checksum
|
||||
f17ea56b313b: Download complete
|
||||
6b6f3b3efe88: Verifying Checksum
|
||||
6b6f3b3efe88: Download complete
|
||||
adce24567e4c: Verifying Checksum
|
||||
adce24567e4c: Download complete
|
||||
e6fc9c6a5757: Verifying Checksum
|
||||
e6fc9c6a5757: Download complete
|
||||
4ed1ca4f3fce: Verifying Checksum
|
||||
4ed1ca4f3fce: Download complete
|
||||
d47782d1182a: Verifying Checksum
|
||||
d47782d1182a: Download complete
|
||||
55afa1ecc21d: Pull complete
|
||||
8ed8f35f8d4f: Pull complete
|
||||
989b226a579c: Pull complete
|
||||
660aeead31d5: Pull complete
|
||||
4f4fb700ef54: Pull complete
|
||||
adce24567e4c: Pull complete
|
||||
f17ea56b313b: Pull complete
|
||||
6b6f3b3efe88: Pull complete
|
||||
4ed1ca4f3fce: Pull complete
|
||||
e6fc9c6a5757: Pull complete
|
||||
d47782d1182a: Pull complete
|
||||
Digest: sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8
|
||||
Status: Downloaded newer image for gtstef/filebrowser:1.5.6-stable
|
||||
docker.io/gtstef/filebrowser:1.5.6-stable
|
||||
1.1.0: Pulling from admin/felhom-samba
|
||||
897d797d2723: Pulling fs layer
|
||||
3051591aa250: Pulling fs layer
|
||||
ce57a3f93416: Pulling fs layer
|
||||
fb94eeec2fe1: Pulling fs layer
|
||||
fb94eeec2fe1: Waiting
|
||||
ce57a3f93416: Verifying Checksum
|
||||
ce57a3f93416: Download complete
|
||||
897d797d2723: Verifying Checksum
|
||||
897d797d2723: Download complete
|
||||
fb94eeec2fe1: Verifying Checksum
|
||||
fb94eeec2fe1: Download complete
|
||||
897d797d2723: Pull complete
|
||||
3051591aa250: Download complete
|
||||
3051591aa250: Pull complete
|
||||
ce57a3f93416: Pull complete
|
||||
fb94eeec2fe1: Pull complete
|
||||
Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10
|
||||
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0
|
||||
gitea.dooplex.hu/admin/felhom-samba:1.1.0
|
||||
[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'.
|
||||
[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'.
|
||||
[golden] baking the first-boot SSH host-key regeneration unit (F3) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'.
|
||||
[golden] identity-clean + minimize …
|
||||
[golden] stop + archive …
|
||||
INFO: including mount point rootfs ('/') in backup
|
||||
INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||||
INFO: archive file size: 618MB
|
||||
INFO: Finished Backup of VM 9100 (00:00:28)
|
||||
[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_10_06-12_03_30.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive)
|
||||
[golden] publishing golden (648833571 bytes, sha256 fb2e9d427917f0ba…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.300.0/golden.tar.zst
|
||||
[golden] pre-delete existing: HTTP 404 (404/204 expected)
|
||||
[golden] upload OK (HTTP 201)
|
||||
GOLDEN_VERSION=0.300.0
|
||||
GOLDEN_SHA256=fb2e9d427917f0ba14dc646c7575789577b7826dc9469587cfcf066a623f1b93
|
||||
[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.300.0 / fb2e9d427917f0ba14dc646c7575789577b7826dc9469587cfcf066a623f1b93
|
||||
[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge)
|
||||
Reference in New Issue
Block a user