Golden 0.227.1 baked, vouched, floor raised — and the floor delivered the new job by itself
gates / gates (push) Successful in 16s

Second full delivery of the day. golden_currency_gate.py went red -> green on
the same command, so the --no-verify bypass declared on the previous push is now
historical rather than standing.

  GOLDEN_VERSION  0.227.1
  GOLDEN_SHA256   66754491dc9bd0130ef8ded9562f63c53a5ffdcfd91baa551141e55fa083ea32
  size            657 403 203 B
  baked           gitea.dooplex.hu/admin/felhom-controller:0.227.1
  MinAgent        0.129.0  (read from the controller CHANGELOG header, not assumed)

THE EVIDENCE IS THE ROUND TRIP. The published bytes were downloaded back -- size
and sha256 identical to what the bake reported -- and ./etc/felhom-controller-
image was read OUT of the downloaded archive: felhom-controller:0.227.1. That is
the delivered artifact naming the controller it will start, from the bytes a
customer's box would actually fetch.

Markers counted: docker OK (overlay2 = 1, mount point rootfs = 1, mp0 = 1,
upload OK (HTTP 201) = 1; excluding = 0, FATAL = 0, mp1 = 0. 404 pre-gate passed
before the run and the script's own pre-delete agreed, so nothing was
overwritten.

Three-field vouch, all three checked: agent_version 0.130.0 >= min_agent 0.129.0
(NOT the R-216 shape), wrapper_sha256 carried through explicitly because the
handler clears it when omitted. Verified by RE-READING the manifest rather than
trusting the flash. The R-120 gate on that POST passed on its own terms rather
than being worked around.

AND THE LINE WORTH KEEPING. demo-felhom self-updated 0.226.1 -> 0.227.1 in under
30 seconds and then logged:

  [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-08-31 06:00 CEST

A box nobody deployed to now runs today's off-site integrity check on its own
schedule. That is a floor DELIVERING rather than merely recording, observed
instead of assumed -- and it is the strongest evidence R-242 has carried.

Token hygiene: file->file, read inside the VM by a runner script, never on a
command line (systemctl show ... grep -c -F token = 0). The leak grep on the
committed log was PROVEN TO WORK before its 0 was believed.

Teardown: guest 9100 destroyed --purge, secrets shredded AFTER the log was
copied out, VM powered off, disk reverted to virgin.

R-242 now records the cadence as MEASURED: five convictions and two full bakes
in one day. Every bypass declared, every debt paid -- and the pattern the row
exists to name is exactly that a release and its delivery are separate acts. Its
other half stays open: nothing gates the VOUCH itself.
This commit is contained in:
2026-08-30 21:48:15 +02:00
parent 99af997ab9
commit db0812b6f2
4 changed files with 439 additions and 14 deletions
+8 -13
View File
@@ -12,13 +12,7 @@ hub deployed itself; nothing is waiting on you except the floor from the last re
*This section is allowed to be longer than one screen, and each item says what happens if you do
nothing.*
1. **Nothing — the golden train is current again.** Golden **0.226.1** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.226.1 on 2026-08-30. Both demo
machines run 0.226.1; `demo-felhom` reached it by self-update, not by hand. A machine installed
today receives 0.226.1 and every fix from the four releases of 2026-08-30.
Evidence: `documentation/tests/golden-0.226.1-2026-08-30/`.
2. **How deep should the off-site check go?** (R-399). The box now checks its off-site store weekly.
1. **How deep should the off-site check go?** (R-399). The box now checks its off-site store weekly.
The check it runs today reads the catalogue — it catches a missing or unreadable backup, and it does
**not** re-read the stored bytes, so it cannot see a file that has quietly rotted.
**What it costs to go deeper, measured on your own machine today, not guessed:**
@@ -28,15 +22,16 @@ nothing.*
**If you do nothing:** the catalogue is checked weekly and the stored bytes are never re-read.
I can turn it on with one setting whenever you say.
3. **Bake and vouch a golden carrying 0.227.1, then raise the floor** — the usual last step. `demo-hp`
runs 0.227.1; the fleet floor is 0.226.1 and the golden carries 0.226.1.
**If you do nothing:** a machine installed today gets 0.226.1 and none of today's off-site checking,
and `demo-felhom` stays where it is. Tracked on R-242.
2. **Nothing about delivery — the golden train is current.** Golden **0.227.1** was baked, published,
round-trip verified, vouched, and the fleet floor raised to 0.227.1 on 2026-08-30. Both demo
machines run it; **`demo-felhom` got there by itself** and started the new off-site check on its own
schedule without anyone touching it. A machine installed today receives 0.227.1 and everything
shipped today. Evidence: `documentation/tests/golden-0.227.1-2026-08-30/`.
4. **Nothing else.** Everything in the releases of 2026-08-30 is a fix to code that ships in the
3. **Nothing else.** Everything in the releases of 2026-08-30 is a fix to code that ships in the
controller image; no customer action, no data migration, no credential change.
5. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
4. **Whether to change the hub password** (R-350). I printed it into my own session log on 20 August.
Not in git, not in any saved file — in the log on this machine. **If you do nothing:** it stays as
it is, at the risk you accept by leaving it. I can change it without ever showing you the new one.
4. **`demo-hp`'s network setup does not match our own notes** (R-338) — the machine works, the page is
File diff suppressed because one or more lines are too long
@@ -0,0 +1,105 @@
# Golden bake 0.227.1 — 2026-08-30
Baked, published, round-trip verified, **vouched**, and the fleet floor raised — the second full
delivery of the day, and the first one where a box picked up the new controller **and its new job**
entirely by itself.
## What was produced
| | |
|---|---|
| `GOLDEN_VERSION` | **0.227.1** |
| `GOLDEN_SHA256` | `66754491dc9bd0130ef8ded9562f63c53a5ffdcfd91baa551141e55fa083ea32` |
| size | **657 403 203 B** |
| package URL | `…/api/packages/admin/generic/felhom-golden/0.227.1/golden.tar.zst` |
| baked controller | `gitea.dooplex.hu/admin/felhom-controller:0.227.1` |
| `MinAgent` | **0.129.0** — read from the controller `CHANGELOG.md` header, not assumed |
| script | `build-golden.sh v3.0.0` |
| venue | the drill VM on DooPlex, reverted to `virgin` and **cold-booted** first |
| template | `debian-13-standard_13.6-1_amd64.tar.zst`, after `pveam update` (the virgin snapshot's INDEX is stale too, and the failure reads as a bogus `400 no such template`) |
## Acceptance markers — counted, not eyeballed
```
docker OK (overlay2 : 1 ← " docker OK (overlay2; data-root /var/lib/docker)"
including mount point rootfs : 1
including mount point mp0 : 1
upload OK (HTTP 201) : 1
--- must be ZERO ---
excluding : 0
FATAL : 0
mount point mp1 : 0 ← mp1 stopped existing in build-golden.sh v3.0.0 (R-165)
```
`felhom-controller:0.227.1` appears **4** times in the bake log. **404 pre-gate before the run**, and
the script's own pre-delete reported `HTTP 404 (404/204 expected)` — nothing was overwritten.
## The evidence is the ROUND TRIP, not the build log
```
downloaded size : 657403203 bake reported : 657403203
downloaded sha : 66754491…083ea32 bake reported : 66754491…083ea32
```
**And the delivered artifact was asked what it will start** — `./etc/felhom-controller-image` read
*out of the downloaded archive*:
```
gitea.dooplex.hu/admin/felhom-controller:0.227.1
```
That is the golden naming the controller it will run, read from the bytes a customer's box would
actually fetch — not from the build host, and not from the local file.
## The vouch — three fields, all checked
| field | value | why it is right |
|---|---|---|
| `golden_version` | 0.227.1 | baked and round-trip verified above |
| `agent_version` | 0.130.0 | published, and **≥ `min_agent`** |
| `min_agent` | 0.129.0 | read from the golden's controller CHANGELOG header |
`agent_version (0.130.0) ≥ min_agent (0.129.0)` — **not the R-216 shape**, where a floor points above
the agent it is served with. `wrapper_sha256` was carried through explicitly, because the handler
clears it when omitted. **Verified by RE-READING the manifest, not by trusting the flash**: golden
option `0.227.1 SELECTED`, all four shas matching.
The **R-120 gate** on this POST refuses a golden below the newest controller the fleet reports; fleet
newest was 0.227.1 and the golden is 0.227.1, so it passed rather than being bypassed.
## The floor is ACTING, not merely set
Impact preview before the change: `{"below":3,"valid":true,"version":"0.227.1"}`.
**`demo-felhom` self-updated in under 30 seconds and registered the new job by itself:**
```
[INFO] [selfupdate] Post-update startup: update successful (0.226.1 → 0.227.1)
[INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-08-31 06:00 CEST
```
**That second line is the one worth keeping.** A box nobody deployed to now runs the off-site
integrity check on its own schedule — which is the whole point of a floor, observed rather than
assumed. Both demo machines are on 0.227.1; only `demo-hp` was ever touched by hand.
`golden_currency_gate.py` went **red → green** on the same command.
## Token hygiene
Copied **file → file** (`scp`), never crossing a shell on either side; the bake ran through a runner
script inside the VM that reads the token itself, so it never reached a command line or a transient
unit's properties:
```
systemctl show golden-bake -p Environment -p ExecStart | grep -c -F "$(cat /root/.gitea-token)" → 0
```
**The leak grep on the committed log was PROVEN TO WORK before its `0` was believed** — a throwaway
copy with the token appended grepped **1**, was `shred -u`'d, and only then was the real log's **0**
taken as evidence. A `0` from an untested grep is not a measurement.
## Teardown
Build guest `9100` destroyed `--purge`; token, runner, script and log `shred -u`'d **after** the log
was copied out (standing rule 5); VM powered off; disk reverted to `virgin`. Nothing else provisioned:
no hub record, no host record, no storage entry.
@@ -0,0 +1,325 @@
[golden] build-golden.sh v3.0.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.227.1
[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) …
Logical volume "vm-9100-disk-0" created.
Logical volume pve/vm-9100-disk-0 changed.
Creating filesystem with 8388608 4k blocks and 2097152 inodes
Filesystem UUID: 1565e732-a5c8-4c15-927e-009b273ef7cf
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
4096000, 7962624
Logical volume "vm-9100-disk-1" created.
Logical volume pve/vm-9100-disk-1 changed.
Creating filesystem with 6291456 4k blocks and 1572864 inodes
Filesystem UUID: 10025428-20f8-4510-8a7a-a55d36f183a8
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst'
Total bytes read: 553512960 (528MiB, 105MiB/s)
Detected container architecture: amd64
Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ...
done: SHA256:F8NLGmSziP94eziIeIrrhf12i077Embm8kQ1i0UTD9g root@felhom-golden
Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ...
done: SHA256:h6hkCDYJIgCAMS4ZDhPDOWaM3B4Wl6YFoqZT/eil4Y4 root@felhom-golden
Creating SSH host key 'ssh_host_rsa_key' - this may take some time ...
done: SHA256:kp7H4PpXREn6ICTYpQ37zlSG8tARCk8H6UFA7DUadho root@felhom-golden
[golden] starting + installing Docker (official repo, trixie channel) …
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation …
[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds …
[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) …
Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
4f55086f7dd0: Pulling fs layer
4f55086f7dd0: Download complete
4f55086f7dd0: Pull complete
Digest: sha256:5dd0d3e6e255913fc30f90b9f2b1d359cc2cbdb48090cc4b65f1676e203243cc
Status: Downloaded newer image for hello-world:latest
docker OK (overlay2; data-root /var/lib/docker)
/var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4
/mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4
both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576
[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.227.1 (no registry cred at deploy) …
WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'.
Configure a credential helper to remove this warning. See
https://docs.docker.com/go/credential-store/
0.227.1: Pulling from admin/felhom-controller
a8ac7f6c67ab: Pulling fs layer
bf30769d36e7: Pulling fs layer
044b66fbe46c: Pulling fs layer
b5c41a28e83f: Pulling fs layer
83b5c7d2c53b: Pulling fs layer
a2531a34ad7a: Pulling fs layer
b5c41a28e83f: Waiting
83b5c7d2c53b: Waiting
a2531a34ad7a: Waiting
a8ac7f6c67ab: Verifying Checksum
a8ac7f6c67ab: Download complete
b5c41a28e83f: Verifying Checksum
b5c41a28e83f: Download complete
83b5c7d2c53b: Verifying Checksum
83b5c7d2c53b: Download complete
a2531a34ad7a: Verifying Checksum
a2531a34ad7a: Download complete
044b66fbe46c: Verifying Checksum
044b66fbe46c: Download complete
bf30769d36e7: Verifying Checksum
bf30769d36e7: Download complete
a8ac7f6c67ab: Pull complete
bf30769d36e7: Pull complete
044b66fbe46c: Pull complete
b5c41a28e83f: Pull complete
83b5c7d2c53b: Pull complete
a2531a34ad7a: Pull complete
Digest: sha256:ff9fc151eab7ee3f02a16d171092a2eadb6ac2019b1f64e52cdbb06101137c70
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.227.1
gitea.dooplex.hu/admin/felhom-controller:0.227.1
[golden] asking the controller which infra images it manages …
[golden] baking infra images (4): traefik:v3.6.7 cloudflare/cloudflared:2026.6.0 gtstef/filebrowser:1.3.3-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 …
v3.6.7: Pulling from library/traefik
589002ba0eae: Pulling fs layer
ef63511ea6cc: Pulling fs layer
0738e5cb835e: Pulling fs layer
3e6813f70c64: Pulling fs layer
3e6813f70c64: Waiting
589002ba0eae: Verifying Checksum
589002ba0eae: Download complete
3e6813f70c64: Verifying Checksum
3e6813f70c64: Download complete
ef63511ea6cc: Verifying Checksum
ef63511ea6cc: Download complete
0738e5cb835e: Verifying Checksum
0738e5cb835e: Download complete
589002ba0eae: Pull complete
ef63511ea6cc: Pull complete
0738e5cb835e: Pull complete
3e6813f70c64: Pull complete
Digest: sha256:a9890c898f379c1905ee5b28342f6b408dc863f08db2dab20e46c267d1ff463a
Status: Downloaded newer image for traefik:v3.6.7
docker.io/library/traefik:v3.6.7
2026.6.0: Pulling from cloudflare/cloudflared
47de5dd0b812: Pulling fs layer
c172f21841df: Pulling fs layer
99515e7b4d35: Pulling fs layer
99ba982a9142: Pulling fs layer
d6b1b89eccac: Pulling fs layer
2780920e5dbf: Pulling fs layer
7c12895b777b: Pulling fs layer
3214acf345c0: Pulling fs layer
52630fc75a18: Pulling fs layer
dd64bf2dd177: Pulling fs layer
b839dfae01f6: Pulling fs layer
ebddc55facdc: Pulling fs layer
bdfd7f7e5bf6: Pulling fs layer
2d4d7adf6272: Pulling fs layer
40008157d8d2: Pulling fs layer
bd8962e29291: Pulling fs layer
cac2ae0193cb: Pulling fs layer
74d1dac84ecc: Pulling fs layer
99ba982a9142: Waiting
d6b1b89eccac: Waiting
2780920e5dbf: Waiting
7c12895b777b: Waiting
3214acf345c0: Waiting
52630fc75a18: Waiting
dd64bf2dd177: Waiting
b839dfae01f6: Waiting
ebddc55facdc: Waiting
bdfd7f7e5bf6: Waiting
2d4d7adf6272: Waiting
40008157d8d2: Waiting
bd8962e29291: Waiting
cac2ae0193cb: Waiting
74d1dac84ecc: Waiting
47de5dd0b812: Verifying Checksum
99515e7b4d35: Verifying Checksum
99515e7b4d35: Download complete
47de5dd0b812: Pull complete
c172f21841df: Verifying Checksum
c172f21841df: Download complete
99ba982a9142: Verifying Checksum
d6b1b89eccac: Verifying Checksum
d6b1b89eccac: Download complete
2780920e5dbf: Verifying Checksum
2780920e5dbf: Download complete
3214acf345c0: Verifying Checksum
3214acf345c0: Download complete
7c12895b777b: Verifying Checksum
7c12895b777b: Download complete
52630fc75a18: Download complete
c172f21841df: Pull complete
b839dfae01f6: Verifying Checksum
b839dfae01f6: Download complete
dd64bf2dd177: Verifying Checksum
dd64bf2dd177: Download complete
ebddc55facdc: Verifying Checksum
ebddc55facdc: Download complete
bdfd7f7e5bf6: Verifying Checksum
bdfd7f7e5bf6: Download complete
40008157d8d2: Verifying Checksum
40008157d8d2: Download complete
bd8962e29291: Verifying Checksum
bd8962e29291: Download complete
2d4d7adf6272: Verifying Checksum
2d4d7adf6272: Download complete
cac2ae0193cb: Verifying Checksum
cac2ae0193cb: Download complete
99515e7b4d35: Pull complete
74d1dac84ecc: Verifying Checksum
74d1dac84ecc: Download complete
99ba982a9142: Pull complete
d6b1b89eccac: Pull complete
2780920e5dbf: Pull complete
7c12895b777b: Pull complete
3214acf345c0: Pull complete
52630fc75a18: Pull complete
dd64bf2dd177: Pull complete
b839dfae01f6: Pull complete
ebddc55facdc: Pull complete
bdfd7f7e5bf6: Pull complete
2d4d7adf6272: Pull complete
40008157d8d2: Pull complete
bd8962e29291: Pull complete
cac2ae0193cb: Pull complete
74d1dac84ecc: Pull complete
Digest: sha256:ba461b8aa9c042156dbd39c38657fe7431bafa063220eab8d5330a523863da9f
Status: Downloaded newer image for cloudflare/cloudflared:2026.6.0
docker.io/cloudflare/cloudflared:2026.6.0
1.3.3-stable: Pulling from gtstef/filebrowser
6a0ac1617861: Pulling fs layer
ef8806083e82: Pulling fs layer
b74107c861c7: Pulling fs layer
adc935def003: Pulling fs layer
4f4fb700ef54: Pulling fs layer
18695ccc900a: Pulling fs layer
45d119d5c397: Pulling fs layer
dac52db4fc51: Pulling fs layer
6d598f86b2f2: Pulling fs layer
8aa349c8396c: Pulling fs layer
18695ccc900a: Waiting
45d119d5c397: Waiting
dac52db4fc51: Waiting
6d598f86b2f2: Waiting
8aa349c8396c: Waiting
adc935def003: Waiting
4f4fb700ef54: Waiting
b74107c861c7: Verifying Checksum
b74107c861c7: Download complete
6a0ac1617861: Verifying Checksum
6a0ac1617861: Download complete
adc935def003: Verifying Checksum
adc935def003: Download complete
4f4fb700ef54: Verifying Checksum
4f4fb700ef54: Download complete
45d119d5c397: Verifying Checksum
45d119d5c397: Download complete
dac52db4fc51: Verifying Checksum
dac52db4fc51: Download complete
ef8806083e82: Verifying Checksum
ef8806083e82: Download complete
18695ccc900a: Verifying Checksum
18695ccc900a: Download complete
6a0ac1617861: Pull complete
6d598f86b2f2: Verifying Checksum
6d598f86b2f2: Download complete
8aa349c8396c: Verifying Checksum
8aa349c8396c: Download complete
ef8806083e82: Pull complete
b74107c861c7: Pull complete
adc935def003: Pull complete
4f4fb700ef54: Pull complete
18695ccc900a: Pull complete
45d119d5c397: Pull complete
dac52db4fc51: Pull complete
6d598f86b2f2: Pull complete
8aa349c8396c: Pull complete
Digest: sha256:eb3733681db8757412632c61a99ad656f0d94ed6781bb2ea114b4d70babab78c
Status: Downloaded newer image for gtstef/filebrowser:1.3.3-stable
docker.io/gtstef/filebrowser:1.3.3-stable
1.1.0: Pulling from admin/felhom-samba
897d797d2723: Pulling fs layer
3051591aa250: Pulling fs layer
ce57a3f93416: Pulling fs layer
fb94eeec2fe1: Pulling fs layer
fb94eeec2fe1: Waiting
ce57a3f93416: Verifying Checksum
ce57a3f93416: Download complete
fb94eeec2fe1: Verifying Checksum
fb94eeec2fe1: Download complete
897d797d2723: Verifying Checksum
897d797d2723: Download complete
897d797d2723: Pull complete
3051591aa250: Verifying Checksum
3051591aa250: Download complete
3051591aa250: Pull complete
ce57a3f93416: Pull complete
fb94eeec2fe1: Pull complete
Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0
gitea.dooplex.hu/admin/felhom-samba:1.1.0
[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'.
[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'.
[golden] baking the first-boot SSH host-key regeneration unit (F3) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'.
[golden] identity-clean + minimize …
[golden] stop + archive …
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
INFO: archive file size: 626MB
INFO: Finished Backup of VM 9100 (00:00:41)
[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_08_30-21_42_45.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive)
[golden] publishing golden (657403203 bytes, sha256 66754491dc9bd013…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.227.1/golden.tar.zst
[golden] pre-delete existing: HTTP 404 (404/204 expected)
[golden] upload OK (HTTP 201)
GOLDEN_VERSION=0.227.1
GOLDEN_SHA256=66754491dc9bd0130ef8ded9562f63c53a5ffdcfd91baa551141e55fa083ea32
[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.227.1 / 66754491dc9bd0130ef8ded9562f63c53a5ffdcfd91baa551141e55fa083ea32
[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge)