hub v0.133.0 (R-859 test approvals end with the test; R-840 bundle on the System page, manifest, alarm); installer 1.31.0 (root files from the config bundle); bundle bootstrap script; golden 0.293.0 evidence; rulings 96–99; drill-r50 removed (evidence)
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -787,6 +787,28 @@ its length, and both fixes cost something the household would notice — operato
|
||||
controller templates and the golden on every box). Until the fix is released, the demo boxes' root-owned ring-0
|
||||
Docker mark is OFF (no unsigned step). *Operator ruling 2026-10-04 ~18:00.*
|
||||
|
||||
### 2026-10-04 (~18:49) — four operator rulings (recorded before the work; the R-840 / Tester 2 brief)
|
||||
|
||||
96. **R-840: build the route now, option A** (a signed `agent_config_update` op pinning the agent tag and the sha256 of
|
||||
a config bundle; the root side installs it after its own checks), and use it on Tester 2. Every later box needs it.
|
||||
**This replaces decision 82.** *Operator ruling 2026-10-04 ~18:49.*
|
||||
97. **Tester 2 may receive, in this session only:** the signed agent update to the vouched agent; the config bundle
|
||||
through the new route; the one-time `live-restore` reload through the wrapper (a reload, never a restart). Nothing
|
||||
else: no Docker engine step, no reboot, no crash test, no app change. *Operator ruling 2026-10-04 ~18:49.*
|
||||
**Added ~19:05, the operator's answer:** the first bundle cannot reach Tester 2 by the route (its root side predates
|
||||
the route — see `11` §5.4.2); the operator will try to reach Tester 2 through his own WireGuard tunnel and install the
|
||||
one bootstrap file by hand, with CC's written steps.
|
||||
98. **drill-r50 is removed from the hub. tester-1 stays** (CC's disposable test box, a VM on the HP box, down when not
|
||||
used). **Added ~19:05, the operator's answer:** the product delete may touch ep0 — it destroys drill-r50's PBS
|
||||
namespace and token there and removes its WireGuard peer. *Operator ruling 2026-10-04 ~18:49 / ~19:05.*
|
||||
99. **The operator's cause, with the reviewer's correction:** *"we didn't bake a new golden before he joined."* Partly:
|
||||
the golden carries `live-restore` and the Docker version; the crash guard and the operator-signers file come from the
|
||||
INSTALLER; the wrapper comes from the agent tag the installer pins. A newer golden alone would not have fixed it, and
|
||||
with perfect timing the next wrapper change would still leave Tester 2 behind — that is R-840. **CC's measurement
|
||||
(same evening) corrects the premise further:** Tester 2 was bound at 16:06 **UTC** (18:06 local), after installer
|
||||
1.30.0, agent 0.142.0 and the re-made golden; it lacks only agent 0.142.1's wrapper fix (R-858). *Operator ruling
|
||||
2026-10-04 ~18:49.*
|
||||
|
||||
### 2026-10-04 (evening) — decided by CC unattended — operator may reverse (System page / Docker / crash-restart brief)
|
||||
|
||||
90. **How does a box tell a crash boot from a clean one?** Options: (a) `pstore` — measured on demo-hp: `efi_pstore` is on,
|
||||
|
||||
@@ -0,0 +1,64 @@
|
||||
== demo-hp
|
||||
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-pbs-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
|
||||
DIFF /usr/local/sbin/felhom-os-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-crash-guard 755:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
|
||||
SAME /etc/felhom/crash-guard.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
|
||||
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
|
||||
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
|
||||
SAME /etc/systemd/system/felhom-sshd.service 644:root
|
||||
SAME /etc/felhom-oob.nft 644:root
|
||||
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
|
||||
SAME /etc/sudoers.d/felhom-op 440:root
|
||||
SAME /etc/sudoers.d/felhom-agent 440:root
|
||||
total 24
|
||||
drwxr-xr-x 2 root root 4096 Oct 4 16:08 .
|
||||
drwxr-xr-x 102 root root 4096 Oct 4 09:41 ..
|
||||
-rw-r--r-- 1 root root 0 Aug 21 18:01 .bootstrap-done
|
||||
-rw-r--r-- 1 root root 7 Aug 21 17:44 appliance-pairing-code
|
||||
-rw-r--r-- 1 root root 456 Oct 4 16:08 crash-guard.conf
|
||||
-rw-r--r-- 1 root root 131 Oct 4 16:08 operator-signers
|
||||
-rw-r--r-- 1 root root 61 Oct 4 18:34 os-trust.json
|
||||
felhom-agent 0.142.1
|
||||
== felhom-pve
|
||||
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-pbs-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
|
||||
DIFF /usr/local/sbin/felhom-os-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-crash-guard 755:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
|
||||
SAME /etc/felhom/crash-guard.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
|
||||
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
|
||||
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
|
||||
SAME /etc/systemd/system/felhom-sshd.service 644:root
|
||||
SAME /etc/felhom-oob.nft 644:root
|
||||
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
|
||||
SAME /etc/sudoers.d/felhom-op 440:root
|
||||
SAME /etc/sudoers.d/felhom-agent 440:root
|
||||
total 24
|
||||
drwxr-xr-x 2 root root 4096 Oct 4 16:12 .
|
||||
drwxr-xr-x 102 root root 4096 Oct 4 13:35 ..
|
||||
-rw-r--r-- 1 root root 0 Jul 18 18:32 .bootstrap-done
|
||||
-rw-r--r-- 1 root root 7 Jul 18 18:17 appliance-pairing-code
|
||||
-rw-r--r-- 1 root root 456 Oct 4 16:12 crash-guard.conf
|
||||
-rw-r--r-- 1 root root 131 Oct 4 16:12 operator-signers
|
||||
-rw-r--r-- 1 root root 65 Oct 4 18:34 os-trust.json
|
||||
felhom-agent 0.142.1
|
||||
@@ -0,0 +1,16 @@
|
||||
--- wrong sha (red):
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
STOP: the bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, not 0000000000000000000000000000000000000000000000000000000000000000 — nothing changed
|
||||
rc=1
|
||||
bdf60f5c79a84db7ebcfe1620fe832436caab831259308906eda08627aac7260 /usr/local/sbin/felhom-os-apply
|
||||
--- right sha:
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
|
||||
2/4 take felhom-os-apply out of the bundle and check it
|
||||
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
|
||||
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
|
||||
4/4 self-check
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba /usr/local/sbin/felhom-os-apply
|
||||
@@ -0,0 +1,9 @@
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
|
||||
2/4 take felhom-os-apply out of the bundle and check it
|
||||
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
|
||||
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
|
||||
4/4 self-check
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=10242c3b… durable_id=""
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=1e60311ec9cad857 op=agent_config_update key_id=felhom-op-1 nonce=10242c3bac90859807c1ab3dfd497a9a
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.002+02:00 level=ERROR msg="signedjobs: signed op execution FAILED (nonce spent — clearing)" job=1e60311ec9cad857 op=agent_config_update err="agent_config_update: the downloaded bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, the signed job pins 111111111111111111111111111111111111111111111
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=eb8a8219… durable_id=""
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=fa3df5a93740111e op=agent_config_update key_id=felhom-op-1 nonce=eb8a8219c7ab393e6702dc8a34cc578f
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.032+02:00 level=INFO msg="osupdate: config bundle downloaded; handing it to the root wrapper" op=agent_config_update agent_version=0.143.0 sha256=8d7273cf5313ef62 duration_ms=15
|
||||
Oct 04 20:04:35 demo-hp felhom-os-apply[496014]: os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0
|
||||
Oct 04 20:04:35 demo-hp felhom-os-apply[496158]: os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0"
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False"
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=WARN msg="osupdate: config bundle INSTALLED" op=agent_config_update agent_version=0.143.0 bundle="{\"agent_version\": \"0.143.0\", \"authority\": \"signed\", \"kept\": [\"/etc/felhom/crash-guard.conf\"], \"prev_dir\": \"/var/lib/felhom-os-apply/bundle-prev/20261004T180435Z-before-0.143.0\", \"same\": 21, \"self_
|
||||
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="osupdate: capability probe after the config bundle" ok=71 total=71 degraded=""
|
||||
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="signedjobs: signed op COMPLETED" job=fa3df5a93740111e op=agent_config_update
|
||||
|
||||
[exited with code 0]
|
||||
{
|
||||
"agent_version": "0.143.0",
|
||||
"authority": "signed",
|
||||
"bundle_sha256": "8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba",
|
||||
"files": {
|
||||
"/etc/felhom-oob.nft": "2c2b9cca89a439ac44efd353f4ea1936b3609ca43491b4c1853483e8321f238f",
|
||||
"/etc/felhom/crash-guard.conf": "9b9d305b421f81d223f2ccc4594e67d41618239779d983a2f72c191a8b3b65f7",
|
||||
"/etc/sudoers.d/felhom-agent": "02df92d751f1780aecbf600b2632b2366fcedeb3601852ebfa98c700e95f4dfc",
|
||||
-rw-r--r-- 1 root root 2754 Oct 4 20:04 /etc/felhom/config-bundle.json
|
||||
@@ -0,0 +1,8 @@
|
||||
RED no 7-day wait
|
||||
RED unknown counted as behind
|
||||
RED clock never clears
|
||||
GREEN! alarm without a vouched bundle
|
||||
RED cell never red
|
||||
RED exact lookup falls back to the first file
|
||||
unmutated: ok
|
||||
RED alarm without a vouched bundle (test strengthened: a box WITH a bundle, nothing vouched)
|
||||
@@ -0,0 +1,24 @@
|
||||
RED R17 trust-path check removed -> test_a_bundle_that_changes_a_signer_is_refused
|
||||
RED R16 table check removed -> test_a_path_outside_the_table_is_refused
|
||||
RED bundle sha check removed -> test_wrong_sha_is_refused
|
||||
RED per-file sha check removed -> test_content_not_matching_its_sha_is_refused
|
||||
RED version pin removed -> test_version_mismatch_is_refused
|
||||
RED visudo/sh/nft content check removed -> test_sudoers_failing_visudo_is_refused
|
||||
RED python compile check removed -> test_python_syntax_error_is_refused
|
||||
RED RuntimeDirectory guard removed -> test_unit_with_runtime_directory_is_refused
|
||||
RED agent-unit User= check removed -> test_agent_unit_not_as_the_agent_user_is_refused
|
||||
RED route-line pre-check removed -> test_sudoers_dropping_the_route_is_refused
|
||||
RED wrapper bundle-mode pre-check removed -> test_wrapper_without_bundle_mode_is_refused
|
||||
RED table re-ordering removed -> test_sudoers_is_written_after_every_wrapper
|
||||
RED self-check sudo -l removed -> test_route_missing_after_install_puts_everything_back
|
||||
RED undo removed -> test_route_missing_after_install_puts_everything_back
|
||||
RED crash-guard kernel.panic self-check removed -> test_crash_guard_disagreeing_with_kernel_panic_puts_everything_back
|
||||
RED nonce burn removed -> test_fresh_box_gets_every_file_and_a_record
|
||||
RED nonce burned before the sha check -> test_wrong_sha_is_refused
|
||||
RED pinned-key bootstrap removed (always the file) -> test_missing_signers_verifies_against_the_pinned_key_and_creates_it
|
||||
RED signers written even when present -> test_present_signers_are_never_touched
|
||||
RED SUDO_UID refusal removed -> test_installer_entry_is_refused_through_sudo
|
||||
RED if-absent policy ignored -> test_tuned_crash_guard_conf_is_kept
|
||||
RED oob policy ignored -> test_fresh_box_gets_every_file_and_a_record
|
||||
unmutated: OK
|
||||
ALL RED
|
||||
@@ -0,0 +1,7 @@
|
||||
RED approval never marked
|
||||
RED a cancelled release is still served
|
||||
RED cancels while the override is still on
|
||||
RED superseded ones cancelled too
|
||||
RED no backfill
|
||||
RED ring-1 boxes not bumped
|
||||
unmutated: ok
|
||||
@@ -0,0 +1,41 @@
|
||||
+ date -u +%FT%TZ
|
||||
2026-10-04T17:19:25Z
|
||||
+ docker ps -q --no-trunc
|
||||
+ sort
|
||||
+ wc -l
|
||||
6
|
||||
+ pidof dockerd
|
||||
+ echo dockerd_pid=225
|
||||
+ stat -c host_sock_inode=%i /var/run/docker.sock
|
||||
dockerd_pid=225
|
||||
host_sock_inode=144
|
||||
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
|
||||
felhom-controller sees: 144
|
||||
+ echo felhom-controller sees: 144
|
||||
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
|
||||
traefik sees: 144
|
||||
+ echo traefik sees: 144
|
||||
+ systemctl restart docker
|
||||
+ date -u +%FT%TZ
|
||||
2026-10-04T17:19:31Z
|
||||
+ sleep 5
|
||||
+ pidof dockerd
|
||||
dockerd_pid=66020
|
||||
+ echo dockerd_pid=66020
|
||||
+ stat -c host_sock_inode=%i /var/run/docker.sock
|
||||
host_sock_inode=144
|
||||
+ docker ps -q --no-trunc
|
||||
+ sort
|
||||
+ diff /tmp/ids.before /tmp/ids.after
|
||||
IDS-SAME
|
||||
+ echo IDS-SAME
|
||||
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
|
||||
felhom-controller sees: 144
|
||||
+ echo felhom-controller sees: 144
|
||||
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
|
||||
traefik sees: 144
|
||||
+ echo traefik sees: 144
|
||||
+ docker exec felhom-controller docker version --format {{.Server.Version}}
|
||||
+ tail -1
|
||||
controller->docker: 29.8.2
|
||||
+ echo controller->docker: 29.8.2
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
After=network-online.target nss-lookup.target docker.socket firewalld.service containerd.service time-set.target
|
||||
Wants=network-online.target containerd.service
|
||||
Requires=docker.socket
|
||||
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
|
||||
Restart=always
|
||||
# specify ListenStream=/var/run/docker.sock instead.
|
||||
ListenStream=/run/docker.sock
|
||||
SocketMode=0660
|
||||
== kill -9 dockerd
|
||||
2026-10-04T17:19:52Z
|
||||
dockerd_pid=66638
|
||||
host_sock_inode=144
|
||||
IDS-SAME
|
||||
controller->docker: 29.8.2
|
||||
== systemctl restart docker.socket
|
||||
2026-10-04T17:20:00Z
|
||||
active
|
||||
active
|
||||
dockerd_pid=67121
|
||||
host_sock_inode=7202
|
||||
IDS-SAME
|
||||
felhom-controller sees: 144
|
||||
traefik sees: 144
|
||||
controller->docker: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
@@ -0,0 +1,30 @@
|
||||
2026-10-04T17:22:27Z
|
||||
felhom-controller Up 2 hours (healthy)
|
||||
traefik Up 2 hours
|
||||
(took 32ms)
|
||||
2026/10/04 17:22:09 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 32ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
2026/10/04 17:22:09 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo starting (hddPath="/mnt/felhom-drives/scratch_hdd", hasCPUCollector=true)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readMemInfo: totalKB=30714356 availKB=25620992 → total=29994MB avail=25020MB used=4974MB (16.6%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/" bsize=4096 total=68.4GB used=5.6GB avail=59.2GB (8.3%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/mnt/felhom-drives/scratch_hdd" bsize=4096 total=937.8GB used=15.1GB avail=875.0GB (1.6%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readLoadAvg: raw="0.50 0.90 0.74 5/1182 23856" → 1m=0.50 5m=0.90 15m=0.74
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readThermalZones: /sys — found 1 zones
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readTemperature: found via hwmon at /sys — 52.9°C (hwmon1)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo done in 47ms — mem=4974MB/29994MB (16.6%), rootDisk=5.6GB/68.4GB (8.3%), load=0.50/0.90/0.74, temp=52.9°C (hwmon1), cpu=2.8%
|
||||
2026/10/04 17:22:19 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job ring-spill: execution starting
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job deadapp-check: execution starting
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job health-probes: execution starting
|
||||
2026/10/04 17:22:19 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: execution starting
|
||||
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
|
||||
2026/10/04 17:22:19 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
(took 24ms)
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 24ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
|
||||
|
||||
dashboard=302
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
1502 /usr/local/bin/felhom-controller
|
||||
2026-10-04T17:22:40Z
|
||||
17:22:45 running 2026-10-04T17:22:41.057453139Z restarts=1
|
||||
controller sees: 7202 host: 7202
|
||||
controller->docker: 29.8.2
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
traefik before: 144
|
||||
[90m2026-10-04T17:22:38Z[0m [31mERR[0m [1mProvider error, retrying in 8.088174175s[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
[90m2026-10-04T17:22:46Z[0m [31mERR[0m [1mFailed to retrieve information of the docker client and server host[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
[90m2026-10-04T17:22:46Z[0m [31mERR[0m [1mProvider error, retrying in 11.956516688s[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
traefik after: 7202
|
||||
@@ -0,0 +1,10 @@
|
||||
RED never-worked guard removed
|
||||
RED timeouts counted as refusals
|
||||
RED exit removed
|
||||
RED window ignored (exit at first refusal)
|
||||
RED a success does not reset
|
||||
RED CheckUsers acts while blind
|
||||
RED same-inode skip removed
|
||||
RED self not skipped
|
||||
RED ENOENT not a refusal
|
||||
unmutated: ok
|
||||
@@ -0,0 +1,41 @@
|
||||
T0 17:50:17 systemctl restart docker.socket
|
||||
host sock inode: 9108
|
||||
+10s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+16s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+21s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+26s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+31s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+36s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+41s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+47s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+52s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+57s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+62s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+67s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+73s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+78s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+83s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+88s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+94s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+99s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+104s controller->docker=29.8.2 traefik_inode=9108 host=9108
|
||||
HEALED
|
||||
== containers before/after (name id)
|
||||
== controller log
|
||||
2026/10/04 17:50:29 sockheal.go:118: [WARN] [sockheal] Docker refuses the socket (dial unix /var/run/docker.sock: connect: connection refused) — exiting after 1m0s of refusals so Docker restarts this controller on the current socket (R-860)
|
||||
2026/10/04 17:51:29 sockheal.go:123: [ERROR] [sockheal] Docker has refused the socket for 1m0s (dial unix /var/run/docker.sock: connect: connection refused) — the socket file was re-created and this container holds the old one; EXITING (code 75) so Docker's restart policy brings it back on the current socket (R-860)
|
||||
2026/10/04 17:52:00 sockheal.go:155: [WARN] [sockheal] traefik holds an old docker socket (inode 7202, current 9108) — restarting it (R-860)
|
||||
2026/10/04 17:52:01 sockheal.go:160: [INFO] [sockheal] traefik restarted onto the current docker socket
|
||||
controller restarts=1 started=2026-10-04T17:51:30.005016139Z
|
||||
@@ -0,0 +1,6 @@
|
||||
[golden] approved guest release: the template already runs every approved version
|
||||
[golden] first-night count vs the approved guest release: 0 (target 0)
|
||||
rc=0
|
||||
[golden] no approved guest release given ��� the template versions stay; first-night count vs an approved release: n/a
|
||||
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 1
|
||||
rc=0
|
||||
@@ -0,0 +1,39 @@
|
||||
Sun Oct 4 17:08:29 UTC 2026
|
||||
# GET /configs/drill-r50/delete (preview)
|
||||
{
|
||||
"claim_present": true,
|
||||
"cloudflare_manual": null,
|
||||
"customer_id": "drill-r50",
|
||||
"customer_name": "drill-r50",
|
||||
"dr_recipe_present": true,
|
||||
"has_config": true,
|
||||
"host_count": 1,
|
||||
"hosts": [
|
||||
{
|
||||
"host_id": "drill-r50-0a4f9a",
|
||||
"online": false,
|
||||
"status": "down"
|
||||
}
|
||||
],
|
||||
"offsite_enabled": false,
|
||||
"offsite_identifier": "",
|
||||
"offsite_type": "",
|
||||
"one_time_secret": false,
|
||||
"online_host_present": false,
|
||||
"pbs_tenancy_configured": true,
|
||||
"pending_journal": null,
|
||||
"residue": {
|
||||
"app_log_tails": 0,
|
||||
"app_telemetry": 185,
|
||||
"appliance_registrations": 1,
|
||||
"log_tail_requests": 0,
|
||||
"notification_prefs": 0,
|
||||
"reports": 185,
|
||||
"selfbind_tokens": 0
|
||||
},
|
||||
"residue_total": 371,
|
||||
"superseded_blobs": 0
|
||||
}
|
||||
# GET /hosts/drill-r50-0a4f9a/delete-impact
|
||||
{"deletable":true,"escrow_present":false,"guests":1,"log_bundles":0,"pbs_secret_present":false,"recovery_present":true,"reports":222,"status":"down","wg_peer_bound":true}
|
||||
# hub DB (read-only copy): wg peer 10.77.0.4 bound to drill-r50-0a4f9a; customer email empty (no mail can go out); dr_tier 0; host last report 2026-08-13 06:11:41Z, agent 0.129.0
|
||||
@@ -0,0 +1,5 @@
|
||||
HTTP/1.1 303 See Other
|
||||
Location: /configs?flash=deleted
|
||||
Date: Sun, 04 Oct 2026 17:08:35 GMT
|
||||
Content-Length: 0
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
2026/10/04 19:08:30 [INFO] customer DELETE cascade started for drill-r50 (journal #22, 1 host(s))
|
||||
2026/10/04 19:08:32 [INFO] delete drill-r50: host drill-r50-0a4f9a deleted (escrow DEMOTED to retained custody)
|
||||
2026/10/04 19:08:33 [INFO] tenantsync: deprovision ok for drill-r50 (ns=drill-r50, existed=false)
|
||||
2026/10/04 19:08:33 [INFO] reset drill-r50: PBS tenancy deprovisioned
|
||||
2026/10/04 19:08:33 [INFO] [claim] reset to unclaimed for drill-r50 (customer RESET) — next onboarding mints a fresh code
|
||||
2026/10/04 19:08:35 [INFO] delete drill-r50: residue purged (reports=185 app_telemetry=185 app_log_tails=0 log_tail_requests=0 notif_prefs=0 selfbind_tokens=0 appliance_registrations=1)
|
||||
2026/10/04 19:08:35 [INFO] customer DELETE cascade COMPLETE for drill-r50 (journal #22) — full teardown
|
||||
@@ -0,0 +1,6 @@
|
||||
Sun Oct 4 17:08:46 UTC 2026
|
||||
# /hosts after
|
||||
0
|
||||
# preview after
|
||||
404 page not found
|
||||
http=404
|
||||
@@ -0,0 +1,5 @@
|
||||
Sun Oct 4 18:15:55 UTC 2026
|
||||
anonymous GET https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.293.0/golden.tar.zst
|
||||
http=200 bytes=648135998
|
||||
sha256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
|
||||
expected=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
|
||||
@@ -0,0 +1,60 @@
|
||||
# Golden 0.293.0 — bake + publish, 2026-10-04
|
||||
|
||||
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM on DooPlex.
|
||||
Step 5 (vouching in the hub, the floor) was **not** done here — it is the main session's act.
|
||||
|
||||
| | Previous (`../golden-0.292.0-2026-10-04-rebake/`) | This bake |
|
||||
|---|---|---|
|
||||
| `build-golden.sh` | v3.1.0 | **v3.2.0** (agent `dc9164c`, sha256 `645b3b659cba…`; VM copy matched) |
|
||||
| Controller | `felhom-controller:0.292.0` | **`felhom-controller:0.293.0`** (MinAgent 0.131.0, unchanged) |
|
||||
| Docker engine | pinned, approved set | same pinned set: the operator-approved release `os-docker-20261004-142842` (stays in force) |
|
||||
| Guest packages | template | template — `GOLDEN_GUEST_PKGS` deliberately EMPTY (see below) |
|
||||
|
||||
**Why the guest list is empty.** The only guest release, `os-guest-20261004-123933`, was approved under a TEST wait;
|
||||
hub v0.133.0 (R-859) cancels it at start. No guest release is in force tonight, so the bake installs no guest fixes,
|
||||
and the box's first night installs whatever release is approved then. The bake reported **49 pending Debian upgrades**
|
||||
in the baked guest — what a future approval may bring, NOT what the first night installs (a ring-1 box installs only
|
||||
an approved release; with none in force, 0).
|
||||
|
||||
## Launch
|
||||
|
||||
- Drill VM reverted to `virgin`, cold-booted per §4.0; `pveversion` = `pve-manager/9.2.2`.
|
||||
- `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst` (the only `_amd64`
|
||||
debian-13 entry), downloaded, checksum verified.
|
||||
- `/root/bake-run.sh` in the VM reads the token from the file and exports `GOLDEN_DOCKER_PKGS` (the six approved
|
||||
versions) and `GOLDEN_GUEST_PKGS=""`; launched as transient unit `golden-bake`.
|
||||
- Token copied file → file (`scp`). `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F <token>` =
|
||||
**0** (control with the token appended = **1**).
|
||||
|
||||
## Pass markers (from `bake.log`)
|
||||
|
||||
```
|
||||
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie … docker-ce=5:29.8.2-1~debian.13~trixie …
|
||||
[golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a
|
||||
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49
|
||||
docker OK (overlay2; data-root /var/lib/docker)
|
||||
live-restore: on
|
||||
INFO: including mount point rootfs ('/') in backup
|
||||
INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||||
[golden] upload OK (HTTP 201)
|
||||
GOLDEN_VERSION=0.293.0
|
||||
GOLDEN_SHA256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
|
||||
```
|
||||
|
||||
No `excluding` and no `FATAL` in the log. Pre-delete before upload: HTTP 404 (a new version, nothing replaced).
|
||||
|
||||
## Round trip
|
||||
|
||||
Anonymous GET of `…/generic/felhom-golden/0.293.0/golden.tar.zst`: HTTP 200, **648135998 bytes**, sha256
|
||||
`e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7` = the printed sha (`02-round-trip.txt`).
|
||||
|
||||
## Secrets
|
||||
|
||||
Saved-log leak grep for the literal token: **0**; positive control (a throwaway copy with the token appended): **1**,
|
||||
copy shredded.
|
||||
|
||||
## Teardown
|
||||
|
||||
`pct destroy 9100 --purge`; `shred -u` of the token, the runner script and the log in the VM (log copied off first);
|
||||
`poweroff`; qemu gone (`ps -eo comm | grep -c qemu-system-x86` = 0); `qemu-img snapshot -a virgin`. Host: nothing
|
||||
provisioned. Hub: not touched.
|
||||
@@ -0,0 +1,342 @@
|
||||
[golden] build-golden.sh v3.2.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.293.0
|
||||
[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) …
|
||||
Logical volume "vm-9100-disk-0" created.
|
||||
Logical volume pve/vm-9100-disk-0 changed.
|
||||
Creating filesystem with 8388608 4k blocks and 2097152 inodes
|
||||
Filesystem UUID: 2ba3ff4c-bddd-47f5-b0dc-5f1949f4c908
|
||||
Superblock backups stored on blocks:
|
||||
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
|
||||
4096000, 7962624
|
||||
Logical volume "vm-9100-disk-1" created.
|
||||
Logical volume pve/vm-9100-disk-1 changed.
|
||||
Creating filesystem with 6291456 4k blocks and 1572864 inodes
|
||||
Filesystem UUID: 6565d64c-6e4b-45bc-b4ea-59f5bd2f7d91
|
||||
Superblock backups stored on blocks:
|
||||
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
|
||||
extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst'
|
||||
Total bytes read: 553512960 (528MiB, 148MiB/s)
|
||||
Detected container architecture: amd64
|
||||
Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ...
|
||||
done: SHA256:bGe7bRQch/Qk8hF5xTuvA4Mxm+o6J4x3G1W6uVOxLR0 root@felhom-golden
|
||||
Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ...
|
||||
done: SHA256:NCGNrT/PBO54a0wAfNAyyTzRoJbPfgrmNSmZDW+x2y0 root@felhom-golden
|
||||
Creating SSH host key 'ssh_host_rsa_key' - this may take some time ...
|
||||
done: SHA256:2yzTbaa+8zgXS4BGskQLtirKN/dy1YKmVddc2s7925o root@felhom-golden
|
||||
[golden] starting + installing Docker (official repo, trixie channel) …
|
||||
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
|
||||
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
|
||||
perl: warning: Setting locale failed.
|
||||
perl: warning: Please check that your locale settings:
|
||||
LANGUAGE = (unset),
|
||||
LC_ALL = (unset),
|
||||
LC_CTYPE = (unset),
|
||||
LC_NUMERIC = (unset),
|
||||
LC_COLLATE = (unset),
|
||||
LC_TIME = (unset),
|
||||
LC_MESSAGES = (unset),
|
||||
LC_MONETARY = (unset),
|
||||
LC_ADDRESS = (unset),
|
||||
LC_IDENTIFICATION = (unset),
|
||||
LC_MEASUREMENT = (unset),
|
||||
LC_PAPER = (unset),
|
||||
LC_TELEPHONE = (unset),
|
||||
LC_NAME = (unset),
|
||||
LANG = "en_US.UTF-8"
|
||||
are supported and installed on your system.
|
||||
perl: warning: Falling back to the standard locale ("C").
|
||||
locale: Cannot set LC_CTYPE to default locale: No such file or directory
|
||||
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
|
||||
locale: Cannot set LC_ALL to default locale: No such file or directory
|
||||
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
|
||||
perl: warning: Setting locale failed.
|
||||
perl: warning: Please check that your locale settings:
|
||||
LANGUAGE = (unset),
|
||||
LC_ALL = (unset),
|
||||
LC_CTYPE = (unset),
|
||||
LC_NUMERIC = (unset),
|
||||
LC_COLLATE = (unset),
|
||||
LC_TIME = (unset),
|
||||
LC_MESSAGES = (unset),
|
||||
LC_MONETARY = (unset),
|
||||
LC_ADDRESS = (unset),
|
||||
LC_IDENTIFICATION = (unset),
|
||||
LC_MEASUREMENT = (unset),
|
||||
LC_PAPER = (unset),
|
||||
LC_TELEPHONE = (unset),
|
||||
LC_NAME = (unset),
|
||||
LANG = "en_US.UTF-8"
|
||||
are supported and installed on your system.
|
||||
perl: warning: Falling back to the standard locale ("C").
|
||||
locale: Cannot set LC_CTYPE to default locale: No such file or directory
|
||||
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
|
||||
locale: Cannot set LC_ALL to default locale: No such file or directory
|
||||
installed: containerd.io 2.3.6-1~debian.13~trixie
|
||||
installed: docker-buildx-plugin 0.37.1-1~debian.13~trixie
|
||||
installed: docker-ce 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-ce-cli 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-ce-rootless-extras 5:29.8.2-1~debian.13~trixie
|
||||
installed: docker-compose-plugin 5.6.0-1~debian.13~trixie
|
||||
[golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a
|
||||
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49
|
||||
[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation …
|
||||
[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds …
|
||||
[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) …
|
||||
Unable to find image 'hello-world:latest' locally
|
||||
latest: Pulling from library/hello-world
|
||||
4f55086f7dd0: Pulling fs layer
|
||||
4f55086f7dd0: Verifying Checksum
|
||||
4f55086f7dd0: Download complete
|
||||
4f55086f7dd0: Pull complete
|
||||
Digest: sha256:5e23090353324d887c48ad5e5c56d294eab81588df9605b07d1afe895f9cc8f8
|
||||
Status: Downloaded newer image for hello-world:latest
|
||||
docker OK (overlay2; data-root /var/lib/docker)
|
||||
live-restore: on
|
||||
/var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4
|
||||
/mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4
|
||||
both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576
|
||||
[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.293.0 (no registry cred at deploy) …
|
||||
|
||||
WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'.
|
||||
Configure a credential helper to remove this warning. See
|
||||
https://docs.docker.com/go/credential-store/
|
||||
|
||||
0.293.0: Pulling from admin/felhom-controller
|
||||
774043ccc8cc: Pulling fs layer
|
||||
ab6b448d4be9: Pulling fs layer
|
||||
23a5bfa58353: Pulling fs layer
|
||||
862a57157567: Pulling fs layer
|
||||
c3ec21eb492c: Pulling fs layer
|
||||
fc53ea013f38: Pulling fs layer
|
||||
862a57157567: Waiting
|
||||
c3ec21eb492c: Waiting
|
||||
fc53ea013f38: Waiting
|
||||
774043ccc8cc: Verifying Checksum
|
||||
774043ccc8cc: Download complete
|
||||
23a5bfa58353: Verifying Checksum
|
||||
23a5bfa58353: Download complete
|
||||
862a57157567: Verifying Checksum
|
||||
862a57157567: Download complete
|
||||
c3ec21eb492c: Verifying Checksum
|
||||
c3ec21eb492c: Download complete
|
||||
fc53ea013f38: Verifying Checksum
|
||||
fc53ea013f38: Download complete
|
||||
ab6b448d4be9: Verifying Checksum
|
||||
ab6b448d4be9: Download complete
|
||||
774043ccc8cc: Pull complete
|
||||
ab6b448d4be9: Pull complete
|
||||
23a5bfa58353: Pull complete
|
||||
862a57157567: Pull complete
|
||||
c3ec21eb492c: Pull complete
|
||||
fc53ea013f38: Pull complete
|
||||
Digest: sha256:b1407516c4c4f9d8dcd35ea8ab56d177139e8858d37ab1b3a4e6be84ec9be3ae
|
||||
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.293.0
|
||||
gitea.dooplex.hu/admin/felhom-controller:0.293.0
|
||||
[golden] asking the controller which infra images it manages …
|
||||
[golden] baking infra images (4): traefik:v3.7.13 cloudflare/cloudflared:2026.9.3 gtstef/filebrowser:1.5.6-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 …
|
||||
v3.7.13: Pulling from library/traefik
|
||||
e2de96513ba9: Pulling fs layer
|
||||
b686a4f73445: Pulling fs layer
|
||||
78cb21c375ca: Pulling fs layer
|
||||
acb2f33459b1: Pulling fs layer
|
||||
acb2f33459b1: Waiting
|
||||
e2de96513ba9: Verifying Checksum
|
||||
e2de96513ba9: Download complete
|
||||
b686a4f73445: Verifying Checksum
|
||||
b686a4f73445: Download complete
|
||||
e2de96513ba9: Pull complete
|
||||
acb2f33459b1: Verifying Checksum
|
||||
acb2f33459b1: Download complete
|
||||
78cb21c375ca: Verifying Checksum
|
||||
78cb21c375ca: Download complete
|
||||
b686a4f73445: Pull complete
|
||||
78cb21c375ca: Pull complete
|
||||
acb2f33459b1: Pull complete
|
||||
Digest: sha256:24841fe2de7304c149343d877d2923b4c8800a38ba015dea9174c23b20e344a0
|
||||
Status: Downloaded newer image for traefik:v3.7.13
|
||||
docker.io/library/traefik:v3.7.13
|
||||
2026.9.3: Pulling from cloudflare/cloudflared
|
||||
2cc7ee286bf3: Pulling fs layer
|
||||
c172f21841df: Pulling fs layer
|
||||
218cf840d0d9: Pulling fs layer
|
||||
f6069939f718: Pulling fs layer
|
||||
d6b1b89eccac: Pulling fs layer
|
||||
2780920e5dbf: Pulling fs layer
|
||||
7c12895b777b: Pulling fs layer
|
||||
3214acf345c0: Pulling fs layer
|
||||
52630fc75a18: Pulling fs layer
|
||||
dd64bf2dd177: Pulling fs layer
|
||||
b839dfae01f6: Pulling fs layer
|
||||
ebddc55facdc: Pulling fs layer
|
||||
c4bc6f35ff5e: Pulling fs layer
|
||||
b96fe2995f90: Pulling fs layer
|
||||
58c0c263dc73: Pulling fs layer
|
||||
bd8962e29291: Pulling fs layer
|
||||
cac2ae0193cb: Pulling fs layer
|
||||
f0383d5ebc47: Pulling fs layer
|
||||
f6069939f718: Waiting
|
||||
d6b1b89eccac: Waiting
|
||||
2780920e5dbf: Waiting
|
||||
7c12895b777b: Waiting
|
||||
3214acf345c0: Waiting
|
||||
52630fc75a18: Waiting
|
||||
dd64bf2dd177: Waiting
|
||||
b839dfae01f6: Waiting
|
||||
ebddc55facdc: Waiting
|
||||
c4bc6f35ff5e: Waiting
|
||||
b96fe2995f90: Waiting
|
||||
58c0c263dc73: Waiting
|
||||
bd8962e29291: Waiting
|
||||
cac2ae0193cb: Waiting
|
||||
f0383d5ebc47: Waiting
|
||||
c172f21841df: Verifying Checksum
|
||||
c172f21841df: Download complete
|
||||
2cc7ee286bf3: Download complete
|
||||
f6069939f718: Verifying Checksum
|
||||
f6069939f718: Download complete
|
||||
d6b1b89eccac: Verifying Checksum
|
||||
d6b1b89eccac: Download complete
|
||||
2cc7ee286bf3: Pull complete
|
||||
2780920e5dbf: Verifying Checksum
|
||||
2780920e5dbf: Download complete
|
||||
c172f21841df: Pull complete
|
||||
218cf840d0d9: Verifying Checksum
|
||||
218cf840d0d9: Download complete
|
||||
218cf840d0d9: Pull complete
|
||||
7c12895b777b: Download complete
|
||||
52630fc75a18: Verifying Checksum
|
||||
52630fc75a18: Download complete
|
||||
3214acf345c0: Verifying Checksum
|
||||
3214acf345c0: Download complete
|
||||
dd64bf2dd177: Verifying Checksum
|
||||
dd64bf2dd177: Download complete
|
||||
b839dfae01f6: Verifying Checksum
|
||||
b839dfae01f6: Download complete
|
||||
ebddc55facdc: Verifying Checksum
|
||||
ebddc55facdc: Download complete
|
||||
c4bc6f35ff5e: Verifying Checksum
|
||||
c4bc6f35ff5e: Download complete
|
||||
b96fe2995f90: Verifying Checksum
|
||||
b96fe2995f90: Download complete
|
||||
58c0c263dc73: Verifying Checksum
|
||||
58c0c263dc73: Download complete
|
||||
f6069939f718: Pull complete
|
||||
d6b1b89eccac: Pull complete
|
||||
cac2ae0193cb: Verifying Checksum
|
||||
cac2ae0193cb: Download complete
|
||||
f0383d5ebc47: Verifying Checksum
|
||||
f0383d5ebc47: Download complete
|
||||
2780920e5dbf: Pull complete
|
||||
7c12895b777b: Pull complete
|
||||
bd8962e29291: Verifying Checksum
|
||||
bd8962e29291: Download complete
|
||||
3214acf345c0: Pull complete
|
||||
52630fc75a18: Pull complete
|
||||
dd64bf2dd177: Pull complete
|
||||
b839dfae01f6: Pull complete
|
||||
ebddc55facdc: Pull complete
|
||||
c4bc6f35ff5e: Pull complete
|
||||
b96fe2995f90: Pull complete
|
||||
58c0c263dc73: Pull complete
|
||||
bd8962e29291: Pull complete
|
||||
cac2ae0193cb: Pull complete
|
||||
f0383d5ebc47: Pull complete
|
||||
Digest: sha256:072c067d25ccbe61d46e18f0d0723255f2bb5304f7317caa95b27031520ff92c
|
||||
Status: Downloaded newer image for cloudflare/cloudflared:2026.9.3
|
||||
docker.io/cloudflare/cloudflared:2026.9.3
|
||||
1.5.6-stable: Pulling from gtstef/filebrowser
|
||||
55afa1ecc21d: Pulling fs layer
|
||||
8ed8f35f8d4f: Pulling fs layer
|
||||
989b226a579c: Pulling fs layer
|
||||
660aeead31d5: Pulling fs layer
|
||||
4f4fb700ef54: Pulling fs layer
|
||||
adce24567e4c: Pulling fs layer
|
||||
f17ea56b313b: Pulling fs layer
|
||||
6b6f3b3efe88: Pulling fs layer
|
||||
4ed1ca4f3fce: Pulling fs layer
|
||||
e6fc9c6a5757: Pulling fs layer
|
||||
d47782d1182a: Pulling fs layer
|
||||
6b6f3b3efe88: Waiting
|
||||
4ed1ca4f3fce: Waiting
|
||||
e6fc9c6a5757: Waiting
|
||||
d47782d1182a: Waiting
|
||||
4f4fb700ef54: Waiting
|
||||
adce24567e4c: Waiting
|
||||
f17ea56b313b: Waiting
|
||||
660aeead31d5: Waiting
|
||||
55afa1ecc21d: Verifying Checksum
|
||||
55afa1ecc21d: Download complete
|
||||
8ed8f35f8d4f: Verifying Checksum
|
||||
8ed8f35f8d4f: Download complete
|
||||
55afa1ecc21d: Pull complete
|
||||
989b226a579c: Verifying Checksum
|
||||
989b226a579c: Download complete
|
||||
4f4fb700ef54: Verifying Checksum
|
||||
4f4fb700ef54: Download complete
|
||||
660aeead31d5: Verifying Checksum
|
||||
660aeead31d5: Download complete
|
||||
6b6f3b3efe88: Verifying Checksum
|
||||
6b6f3b3efe88: Download complete
|
||||
adce24567e4c: Verifying Checksum
|
||||
adce24567e4c: Download complete
|
||||
f17ea56b313b: Verifying Checksum
|
||||
f17ea56b313b: Download complete
|
||||
4ed1ca4f3fce: Verifying Checksum
|
||||
4ed1ca4f3fce: Download complete
|
||||
d47782d1182a: Verifying Checksum
|
||||
d47782d1182a: Download complete
|
||||
e6fc9c6a5757: Verifying Checksum
|
||||
e6fc9c6a5757: Download complete
|
||||
8ed8f35f8d4f: Pull complete
|
||||
989b226a579c: Pull complete
|
||||
660aeead31d5: Pull complete
|
||||
4f4fb700ef54: Pull complete
|
||||
adce24567e4c: Pull complete
|
||||
f17ea56b313b: Pull complete
|
||||
6b6f3b3efe88: Pull complete
|
||||
4ed1ca4f3fce: Pull complete
|
||||
e6fc9c6a5757: Pull complete
|
||||
d47782d1182a: Pull complete
|
||||
Digest: sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8
|
||||
Status: Downloaded newer image for gtstef/filebrowser:1.5.6-stable
|
||||
docker.io/gtstef/filebrowser:1.5.6-stable
|
||||
1.1.0: Pulling from admin/felhom-samba
|
||||
897d797d2723: Pulling fs layer
|
||||
3051591aa250: Pulling fs layer
|
||||
ce57a3f93416: Pulling fs layer
|
||||
fb94eeec2fe1: Pulling fs layer
|
||||
fb94eeec2fe1: Waiting
|
||||
ce57a3f93416: Verifying Checksum
|
||||
ce57a3f93416: Download complete
|
||||
fb94eeec2fe1: Verifying Checksum
|
||||
fb94eeec2fe1: Download complete
|
||||
897d797d2723: Verifying Checksum
|
||||
897d797d2723: Download complete
|
||||
3051591aa250: Verifying Checksum
|
||||
3051591aa250: Download complete
|
||||
897d797d2723: Pull complete
|
||||
3051591aa250: Pull complete
|
||||
ce57a3f93416: Pull complete
|
||||
fb94eeec2fe1: Pull complete
|
||||
Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10
|
||||
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0
|
||||
gitea.dooplex.hu/admin/felhom-samba:1.1.0
|
||||
[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'.
|
||||
[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'.
|
||||
[golden] baking the first-boot SSH host-key regeneration unit (F3) …
|
||||
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'.
|
||||
[golden] identity-clean + minimize …
|
||||
[golden] stop + archive …
|
||||
INFO: including mount point rootfs ('/') in backup
|
||||
INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||||
INFO: archive file size: 618MB
|
||||
INFO: Finished Backup of VM 9100 (00:00:29)
|
||||
[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_10_04-20_14_33.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive)
|
||||
[golden] publishing golden (648135998 bytes, sha256 e7966872abeb38db…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.293.0/golden.tar.zst
|
||||
[golden] pre-delete existing: HTTP 404 (404/204 expected)
|
||||
[golden] upload OK (HTTP 201)
|
||||
GOLDEN_VERSION=0.293.0
|
||||
GOLDEN_SHA256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
|
||||
[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.293.0 / e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
|
||||
[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge)
|
||||
Reference in New Issue
Block a user