OS updates guest fast lane: records — 11 §8.1 BUILT, 03 cloudflared corrected, 07 §6.1 OS leg, 00 PARTIAL, monthly runbook infra pins, golden 0.291.0 record + vouch, register 331 -> 333 (R-837/838/726/843 closed; R-840/841/842/844/845 opened), STATUS, report
gates / gates (push) Successful in 31s
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -2,8 +2,40 @@
|
||||
|
||||
**Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).**
|
||||
|
||||
**Updated 2026-10-04 (day): the off-site topic is closed; the OS-update test is done. Both demo boxes run controller
|
||||
0.290.0 and host agent 0.139.0. Hub 0.129.0. New installs get golden 0.290.0; every box's floor is 0.290.0.**
|
||||
**Updated 2026-10-04 (afternoon): guest system updates are automatic on the demo boxes. Both demo boxes run
|
||||
controller 0.291.0 and host agent 0.140.0. Hub 0.130.0. New installs get golden 0.291.0.**
|
||||
|
||||
## Today (2026-10-04, afternoon): the guest's security fixes install themselves
|
||||
|
||||
**One decision for you (a safe default if you say nothing):**
|
||||
|
||||
1. **Undo for a guest update that goes wrong.** I tested it first, as you asked: Proxmox cannot take a snapshot of a
|
||||
customer box at all (the box is linked to the household's drives, and Proxmox refuses). So there is no automatic undo.
|
||||
Today a failed check stops, mails you, and last night's whole-box backup (minutes old) is the undo, by hand.
|
||||
- **A (my pick):** keep it so. Nothing new to build. A restore takes about 1–3 minutes plus losing what apps wrote
|
||||
since the backup.
|
||||
- **B:** build our own disk snapshot under Proxmox. Automatic, but a new mechanism nobody has tested, with a risk to
|
||||
the disk pool.
|
||||
- **If you say nothing:** A stays.
|
||||
|
||||
**What I did:**
|
||||
- **Your two choices are built.** A returning household's new box sets the old off-site copy aside on night one and
|
||||
starts a new one (nothing deleted). An approved version that Debian already replaced comes from Debian's dated archive.
|
||||
- **Guest security fixes now install themselves.** Each night, after the whole-box backup, the demo boxes install
|
||||
Debian's fixes. When both demo boxes run the same versions healthy for 24 hours and one night, the hub approves that
|
||||
set; every other box then installs exactly those versions. Docker, the host and the kernel are not touched.
|
||||
- Proven live: each demo box installed 53 fixes and stayed healthy. With a 2-minute test wait the hub approved the
|
||||
set; then I put back 24 hours. demo-felhom, made "ring 1" for the test, installed exactly the 3 approved versions it
|
||||
lacked and nothing newer. A run where I stopped an app failed its check and mailed you (you got that mail).
|
||||
- You can switch OS updates off per box in the hub. They are ON by default. The household sees one line in its
|
||||
timeline: "System security fixes installed".
|
||||
- **The tunnel and two other built-in programs are current** (cloudflared was 4 months old). A new monthly check
|
||||
catches them falling behind. The tunnel came back by itself on both demo boxes within 20 seconds.
|
||||
- **Three bugs found and fixed during the live test**, before release.
|
||||
- **Two gaps found, now rows:** existing boxes cannot receive the new update tool through the product (only new
|
||||
installs, or by hand — the demo boxes got it by hand); and the hub's "tunnel status" for every box always reads
|
||||
"inactive" because it checks the wrong place.
|
||||
- **Rows:** 4 closed (one opened and closed the same day), 5 opened. The list went from 331 to 333.
|
||||
|
||||
## Today (2026-10-04, day): off-site closed, operating-system updates measured
|
||||
|
||||
@@ -148,8 +180,8 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne
|
||||
|
||||
## What needs you
|
||||
|
||||
0. **The two decisions at the top of today's section** (a returning household's first night; approved OS updates
|
||||
when Debian has moved on). Each has a safe default if you say nothing. The Hetzner key change stays your call (3 steps, in the list).
|
||||
0. **The undo choice at the top of today's section** (A: keep the backup as the undo; B: build our own snapshot).
|
||||
If you say nothing, A stays. Earlier today's two decisions are built. The Hetzner key change stays your call.
|
||||
1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say
|
||||
nothing:** it stays hidden; nothing runs it.
|
||||
2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list).
|
||||
|
||||
Reference in New Issue
Block a user