docs(G1): REPORT + scripts CHANGELOG for break-glass (hub v0.34.1 live-validated)
Auto-heal drill (agent stopped) healed /run/sshd in 30.0s; mgmt_plane_healed warning fired end-to-end; break-glass vault→retrieve→PVE-ticket proven. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
@@ -1,5 +1,17 @@
|
||||
# Felhom scripts — Changelog
|
||||
|
||||
## felhom-host-install — break-glass credential + management-plane watchdog install (TASK G1) (2026-07-05)
|
||||
|
||||
- `step_break_glass` (new step 4b): generates a strong root@pam console password (`openssl rand`,
|
||||
NEVER logged/filed — stdin→chpasswd + stdin→curl), sets it, and vaults it to the hub over the
|
||||
enroll-authenticated host-key channel (`PUT /hosts/{id}/recovery-credential`). Idempotent (state
|
||||
marker) unless `--rotate-recovery`. The human break-glass path for the PVE web console.
|
||||
- `install_mgmt_watchdog` (in step 5): installs the G1 host artifacts from the agent repo configs —
|
||||
`felhom-privsep.tmpfiles` (boot-persistent `/run/sshd`), `felhom-mgmt-watchdog.{sh,service,timer}`
|
||||
(agent-independent ~60s privsep-dir auto-heal). **HARD GUARD:** refuses any fetched unit declaring
|
||||
`RuntimeDirectory=` (the SPIKE-felhom-sshd §8 incident cause). Non-fatal on a repo that predates the
|
||||
artifacts. Uninstall (step 4b2) stops+disables the timer and removes all four artifacts + the marker.
|
||||
|
||||
## docs — 06-doc S3 row SHIPPED + agent-side revocation semantics (2026-07-04)
|
||||
|
||||
Docs-only companion to **felhom-agent v0.64.0** (the S3 slice — keygen, registration,
|
||||
|
||||
Reference in New Issue
Block a user