R-274: the BYO disclosure names the golden it reuses; the local-golden check is pinned
The check itself shipped with R-297 (golden_local_matches_manifest: sha256 or controller version against the hub manifest; mismatch re-fetches, a named --golden is refused). This adds the disclosure line the row also asked for and tests that pin the check's place before the adopt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1881,6 +1881,9 @@ EOF
|
||||
else
|
||||
echo " guest: the provisioned Felhom LXC (vmid ${VMID}, capped ${CPU_CORES} cores / ${MEM_MIB} MiB) + its volumes"
|
||||
echo " + the golden vzdump imported onto storage '${ARCHIVE_STORAGE}'"
|
||||
# R-274: the disclosure names what the install REUSES, not only what it creates.
|
||||
echo " reuse: a golden already on '${ARCHIVE_STORAGE}' is used only if its sha256 or its controller version"
|
||||
echo " matches the hub's vouched golden; otherwise the vouched one is fetched (a --golden you name is refused)"
|
||||
fi
|
||||
echo " update: operator-signed self-update authority: ${RESOLVED_OP_ID:-NONE (self-update stays dormant)}"
|
||||
echo " NOT touched in byo mode: root@pam (no break-glass), host DNS (:53), OOB sshd."
|
||||
|
||||
Reference in New Issue
Block a user