ISO 1.28.0 source: the console stops showing the pairing code once bound (R-535)
gates / gates (push) Successful in 20s
gates / gates (push) Successful in 20s
Measured 2026-09-16: 25 minutes after a successful bind AND claim the console still showed the pairing code under a line promising the screen refreshes itself. print_bound_banner is printed the moment the bind delivery lands. It does NOT name the dashboard URL: the one-shot delivery carries the customer id, passphrase and mode, not the domain, so naming an address would mean inventing one. The residue — the console still does not reflect the later CLAIM, because this unit has exited by then — is recorded in the changelog rather than implied away. Not published: the built image needs the release gate and the operator's yes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
<stdin>:30: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
|
||||
## 2026-09-16T15:03:54Z Part B live — enabling the off-site tier for tester-1 through the hub page
|
||||
fields re-sent (values not printed): _csrf, cf_api_token, cf_tunnel_token, customer_id, customer_name, domain, dr_tier, email, git_token, git_username, offsite_box_type, offsite_enabled, offsite_quota_gb, offsite_type, pbsdr_storage_id
|
||||
preserved-not-blanked: cf_api_token, cf_tunnel_token
|
||||
Traceback (most recent call last):
|
||||
File "<stdin>", line 36, in <module>
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 189, in urlopen
|
||||
return opener.open(url, data, timeout)
|
||||
~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 489, in open
|
||||
response = self._open(req, data)
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 506, in _open
|
||||
result = self._call_chain(self.handle_open, protocol, protocol +
|
||||
'_open', req)
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 466, in _call_chain
|
||||
result = func(*args)
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 1348, in http_open
|
||||
return self.do_open(http.client.HTTPConnection, req)
|
||||
~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
||||
File "/usr/lib/python3.13/urllib/request.py", line 1323, in do_open
|
||||
r = h.getresponse()
|
||||
File "/usr/lib/python3.13/http/client.py", line 1459, in getresponse
|
||||
response.begin()
|
||||
~~~~~~~~~~~~~~^^
|
||||
File "/usr/lib/python3.13/http/client.py", line 336, in begin
|
||||
version, status, reason = self._read_status()
|
||||
~~~~~~~~~~~~~~~~~^^
|
||||
File "/usr/lib/python3.13/http/client.py", line 305, in _read_status
|
||||
raise RemoteDisconnected("Remote end closed connection without"
|
||||
" response")
|
||||
http.client.RemoteDisconnected: Remote end closed connection without response
|
||||
@@ -0,0 +1,26 @@
|
||||
## 2026-09-16T14:57:56Z ep0 ACL BEFORE (read-only) — scope: the hub's tenantsync auth-id only
|
||||
--- all ACL entries:
|
||||
+========================+=======================================+===========+=================+
|
||||
| ugid | path | propagate | roleid |
|
||||
+========================+=======================================+===========+=================+
|
||||
| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||
+========================+=======================================+===========+=================+
|
||||
--- users/tokens:
|
||||
+============+========+========+===========+==========+=======+===============================================+
|
||||
| userid | enable | expire | firstname | lastname | email | comment |
|
||||
+============+========+========+===========+==========+=======+===============================================+
|
||||
| felhom@pbs | 1 | never | | | | offsite tenancy (per-customer privsep tokens) |
|
||||
+------------+--------+--------+-----------+----------+-------+-----------------------------------------------+
|
||||
| root@pam | 1 | never | | | | Superuser |
|
||||
+============+========+========+===========+==========+=======+===============================================+
|
||||
--- roles that carry Datastore.Modify:
|
||||
@@ -0,0 +1,42 @@
|
||||
## 2026-09-16T15:03:10Z Part C.1 — the grant, narrowest role FIRST, measured at every step
|
||||
--- BEFORE: effective permissions of felhom@pbs at the datastore ROOT (where R-534 failed):
|
||||
Privileges with (*) have the propagate flag set
|
||||
|
||||
--- try the NARROWER role first: DatastorePowerUser
|
||||
Privileges with (*) have the propagate flag set
|
||||
|
||||
Path: /datastore/felhom-offsite
|
||||
- Datastore.Backup (*)
|
||||
- Datastore.Prune (*)
|
||||
## 2026-09-16T15:03:42Z DatastorePowerUser does NOT carry Datastore.Modify (measured above: Backup + Prune only).
|
||||
## PBS has no role-create command and no custom roles, so the next role up is the narrowest that works.
|
||||
--- apply DatastoreAdmin at the datastore ROOT for the hub user only:
|
||||
--- remove the DatastorePowerUser line so exactly one entry remains:
|
||||
--- AFTER: effective permissions at the datastore root:
|
||||
Privileges with (*) have the propagate flag set
|
||||
|
||||
Path: /datastore/felhom-offsite
|
||||
- Datastore.Audit (*)
|
||||
- Datastore.Backup (*)
|
||||
- Datastore.Modify (*)
|
||||
- Datastore.Prune (*)
|
||||
- Datastore.Read (*)
|
||||
- Datastore.Verify (*)
|
||||
--- AFTER: the full ACL table (nothing else changed):
|
||||
+========================+=======================================+===========+=================+
|
||||
| ugid | path | propagate | roleid |
|
||||
+========================+=======================================+===========+=================+
|
||||
| felhom@pbs | /datastore/felhom-offsite | 1 | DatastoreAdmin |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||
+------------------------+---------------------------------------+-----------+-----------------+
|
||||
| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||
+========================+=======================================+===========+=================+
|
||||
@@ -0,0 +1,5 @@
|
||||
## 2026-09-16T15:00:36Z releases
|
||||
controller 0.244.0 image: pushed (registry tags now 0.241.0 0.242.0 0.243.0 0.244.0)
|
||||
hub 0.116.0 image: pushed; manifest bumped; ArgoCD sync=Synced health=Healthy;
|
||||
rollout complete; live image gitea.dooplex.hu/admin/felhom-hub:0.116.0
|
||||
commits: felhom-controller 2f8ff24, felhom.eu 3738dfc (+ the manifest bump)
|
||||
Reference in New Issue
Block a user