hub v0.133.0 (R-859 test approvals end with the test; R-840 bundle on the System page, manifest, alarm); installer 1.31.0 (root files from the config bundle); bundle bootstrap script; golden 0.293.0 evidence; rulings 96–99; drill-r50 removed (evidence)
gates / gates (push) Successful in 29s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 20:18:37 +02:00
parent 6b820143f8
commit ff1db11db4
45 changed files with 1707 additions and 42 deletions
@@ -787,6 +787,28 @@ its length, and both fixes cost something the household would notice — operato
controller templates and the golden on every box). Until the fix is released, the demo boxes' root-owned ring-0
Docker mark is OFF (no unsigned step). *Operator ruling 2026-10-04 ~18:00.*
### 2026-10-04 (~18:49) — four operator rulings (recorded before the work; the R-840 / Tester 2 brief)
96. **R-840: build the route now, option A** (a signed `agent_config_update` op pinning the agent tag and the sha256 of
a config bundle; the root side installs it after its own checks), and use it on Tester 2. Every later box needs it.
**This replaces decision 82.** *Operator ruling 2026-10-04 ~18:49.*
97. **Tester 2 may receive, in this session only:** the signed agent update to the vouched agent; the config bundle
through the new route; the one-time `live-restore` reload through the wrapper (a reload, never a restart). Nothing
else: no Docker engine step, no reboot, no crash test, no app change. *Operator ruling 2026-10-04 ~18:49.*
**Added ~19:05, the operator's answer:** the first bundle cannot reach Tester 2 by the route (its root side predates
the route — see `11` §5.4.2); the operator will try to reach Tester 2 through his own WireGuard tunnel and install the
one bootstrap file by hand, with CC's written steps.
98. **drill-r50 is removed from the hub. tester-1 stays** (CC's disposable test box, a VM on the HP box, down when not
used). **Added ~19:05, the operator's answer:** the product delete may touch ep0 — it destroys drill-r50's PBS
namespace and token there and removes its WireGuard peer. *Operator ruling 2026-10-04 ~18:49 / ~19:05.*
99. **The operator's cause, with the reviewer's correction:** *"we didn't bake a new golden before he joined."* Partly:
the golden carries `live-restore` and the Docker version; the crash guard and the operator-signers file come from the
INSTALLER; the wrapper comes from the agent tag the installer pins. A newer golden alone would not have fixed it, and
with perfect timing the next wrapper change would still leave Tester 2 behind — that is R-840. **CC's measurement
(same evening) corrects the premise further:** Tester 2 was bound at 16:06 **UTC** (18:06 local), after installer
1.30.0, agent 0.142.0 and the re-made golden; it lacks only agent 0.142.1's wrapper fix (R-858). *Operator ruling
2026-10-04 ~18:49.*
### 2026-10-04 (evening) — decided by CC unattended — operator may reverse (System page / Docker / crash-restart brief)
90. **How does a box tell a crash boot from a clean one?** Options: (a) `pstore` — measured on demo-hp: `efi_pstore` is on,
@@ -0,0 +1,64 @@
== demo-hp
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
SAME /usr/local/sbin/felhom-pbs-apply 755:root
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
DIFF /usr/local/sbin/felhom-os-apply 755:root
SAME /usr/local/sbin/felhom-crash-guard 755:root
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
SAME /etc/felhom/crash-guard.conf 644:root
SAME /etc/systemd/system/felhom-agent.service 644:root
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
SAME /etc/systemd/system/felhom-sshd.service 644:root
SAME /etc/felhom-oob.nft 644:root
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
SAME /etc/sudoers.d/felhom-op 440:root
SAME /etc/sudoers.d/felhom-agent 440:root
total 24
drwxr-xr-x 2 root root 4096 Oct 4 16:08 .
drwxr-xr-x 102 root root 4096 Oct 4 09:41 ..
-rw-r--r-- 1 root root 0 Aug 21 18:01 .bootstrap-done
-rw-r--r-- 1 root root 7 Aug 21 17:44 appliance-pairing-code
-rw-r--r-- 1 root root 456 Oct 4 16:08 crash-guard.conf
-rw-r--r-- 1 root root 131 Oct 4 16:08 operator-signers
-rw-r--r-- 1 root root 61 Oct 4 18:34 os-trust.json
felhom-agent 0.142.1
== felhom-pve
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
SAME /usr/local/sbin/felhom-pbs-apply 755:root
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
DIFF /usr/local/sbin/felhom-os-apply 755:root
SAME /usr/local/sbin/felhom-crash-guard 755:root
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
SAME /etc/felhom/crash-guard.conf 644:root
SAME /etc/systemd/system/felhom-agent.service 644:root
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
SAME /etc/systemd/system/felhom-sshd.service 644:root
SAME /etc/felhom-oob.nft 644:root
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
SAME /etc/sudoers.d/felhom-op 440:root
SAME /etc/sudoers.d/felhom-agent 440:root
total 24
drwxr-xr-x 2 root root 4096 Oct 4 16:12 .
drwxr-xr-x 102 root root 4096 Oct 4 13:35 ..
-rw-r--r-- 1 root root 0 Jul 18 18:32 .bootstrap-done
-rw-r--r-- 1 root root 7 Jul 18 18:17 appliance-pairing-code
-rw-r--r-- 1 root root 456 Oct 4 16:12 crash-guard.conf
-rw-r--r-- 1 root root 131 Oct 4 16:12 operator-signers
-rw-r--r-- 1 root root 65 Oct 4 18:34 os-trust.json
felhom-agent 0.142.1
@@ -0,0 +1,16 @@
--- wrong sha (red):
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
STOP: the bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, not 0000000000000000000000000000000000000000000000000000000000000000 — nothing changed
rc=1
bdf60f5c79a84db7ebcfe1620fe832436caab831259308906eda08627aac7260 /usr/local/sbin/felhom-os-apply
--- right sha:
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
2/4 take felhom-os-apply out of the bundle and check it
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
4/4 self-check
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba /usr/local/sbin/felhom-os-apply
@@ -0,0 +1,9 @@
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
2/4 take felhom-os-apply out of the bundle and check it
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
4/4 self-check
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
@@ -0,0 +1,29 @@
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=10242c3b… durable_id=""
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=1e60311ec9cad857 op=agent_config_update key_id=felhom-op-1 nonce=10242c3bac90859807c1ab3dfd497a9a
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.002+02:00 level=ERROR msg="signedjobs: signed op execution FAILED (nonce spent — clearing)" job=1e60311ec9cad857 op=agent_config_update err="agent_config_update: the downloaded bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, the signed job pins 111111111111111111111111111111111111111111111
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=eb8a8219… durable_id=""
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=fa3df5a93740111e op=agent_config_update key_id=felhom-op-1 nonce=eb8a8219c7ab393e6702dc8a34cc578f
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.032+02:00 level=INFO msg="osupdate: config bundle downloaded; handing it to the root wrapper" op=agent_config_update agent_version=0.143.0 sha256=8d7273cf5313ef62 duration_ms=15
Oct 04 20:04:35 demo-hp felhom-os-apply[496014]: os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0
Oct 04 20:04:35 demo-hp felhom-os-apply[496158]: os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0"
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False"
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=WARN msg="osupdate: config bundle INSTALLED" op=agent_config_update agent_version=0.143.0 bundle="{\"agent_version\": \"0.143.0\", \"authority\": \"signed\", \"kept\": [\"/etc/felhom/crash-guard.conf\"], \"prev_dir\": \"/var/lib/felhom-os-apply/bundle-prev/20261004T180435Z-before-0.143.0\", \"same\": 21, \"self_
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="osupdate: capability probe after the config bundle" ok=71 total=71 degraded=""
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="signedjobs: signed op COMPLETED" job=fa3df5a93740111e op=agent_config_update
[exited with code 0]
{
"agent_version": "0.143.0",
"authority": "signed",
"bundle_sha256": "8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba",
"files": {
"/etc/felhom-oob.nft": "2c2b9cca89a439ac44efd353f4ea1936b3609ca43491b4c1853483e8321f238f",
"/etc/felhom/crash-guard.conf": "9b9d305b421f81d223f2ccc4594e67d41618239779d983a2f72c191a8b3b65f7",
"/etc/sudoers.d/felhom-agent": "02df92d751f1780aecbf600b2632b2366fcedeb3601852ebfa98c700e95f4dfc",
-rw-r--r-- 1 root root 2754 Oct 4 20:04 /etc/felhom/config-bundle.json
@@ -0,0 +1,8 @@
RED no 7-day wait
RED unknown counted as behind
RED clock never clears
GREEN! alarm without a vouched bundle
RED cell never red
RED exact lookup falls back to the first file
unmutated: ok
RED alarm without a vouched bundle (test strengthened: a box WITH a bundle, nothing vouched)
@@ -0,0 +1,24 @@
RED R17 trust-path check removed -> test_a_bundle_that_changes_a_signer_is_refused
RED R16 table check removed -> test_a_path_outside_the_table_is_refused
RED bundle sha check removed -> test_wrong_sha_is_refused
RED per-file sha check removed -> test_content_not_matching_its_sha_is_refused
RED version pin removed -> test_version_mismatch_is_refused
RED visudo/sh/nft content check removed -> test_sudoers_failing_visudo_is_refused
RED python compile check removed -> test_python_syntax_error_is_refused
RED RuntimeDirectory guard removed -> test_unit_with_runtime_directory_is_refused
RED agent-unit User= check removed -> test_agent_unit_not_as_the_agent_user_is_refused
RED route-line pre-check removed -> test_sudoers_dropping_the_route_is_refused
RED wrapper bundle-mode pre-check removed -> test_wrapper_without_bundle_mode_is_refused
RED table re-ordering removed -> test_sudoers_is_written_after_every_wrapper
RED self-check sudo -l removed -> test_route_missing_after_install_puts_everything_back
RED undo removed -> test_route_missing_after_install_puts_everything_back
RED crash-guard kernel.panic self-check removed -> test_crash_guard_disagreeing_with_kernel_panic_puts_everything_back
RED nonce burn removed -> test_fresh_box_gets_every_file_and_a_record
RED nonce burned before the sha check -> test_wrong_sha_is_refused
RED pinned-key bootstrap removed (always the file) -> test_missing_signers_verifies_against_the_pinned_key_and_creates_it
RED signers written even when present -> test_present_signers_are_never_touched
RED SUDO_UID refusal removed -> test_installer_entry_is_refused_through_sudo
RED if-absent policy ignored -> test_tuned_crash_guard_conf_is_kept
RED oob policy ignored -> test_fresh_box_gets_every_file_and_a_record
unmutated: OK
ALL RED
@@ -0,0 +1,7 @@
RED approval never marked
RED a cancelled release is still served
RED cancels while the override is still on
RED superseded ones cancelled too
RED no backfill
RED ring-1 boxes not bumped
unmutated: ok
@@ -0,0 +1,41 @@
+ date -u +%FT%TZ
2026-10-04T17:19:25Z
+ docker ps -q --no-trunc
+ sort
+ wc -l
6
+ pidof dockerd
+ echo dockerd_pid=225
+ stat -c host_sock_inode=%i /var/run/docker.sock
dockerd_pid=225
host_sock_inode=144
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
felhom-controller sees: 144
+ echo felhom-controller sees: 144
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
traefik sees: 144
+ echo traefik sees: 144
+ systemctl restart docker
+ date -u +%FT%TZ
2026-10-04T17:19:31Z
+ sleep 5
+ pidof dockerd
dockerd_pid=66020
+ echo dockerd_pid=66020
+ stat -c host_sock_inode=%i /var/run/docker.sock
host_sock_inode=144
+ docker ps -q --no-trunc
+ sort
+ diff /tmp/ids.before /tmp/ids.after
IDS-SAME
+ echo IDS-SAME
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
felhom-controller sees: 144
+ echo felhom-controller sees: 144
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
traefik sees: 144
+ echo traefik sees: 144
+ docker exec felhom-controller docker version --format {{.Server.Version}}
+ tail -1
controller->docker: 29.8.2
+ echo controller->docker: 29.8.2
@@ -0,0 +1,24 @@
After=network-online.target nss-lookup.target docker.socket firewalld.service containerd.service time-set.target
Wants=network-online.target containerd.service
Requires=docker.socket
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
Restart=always
# specify ListenStream=/var/run/docker.sock instead.
ListenStream=/run/docker.sock
SocketMode=0660
== kill -9 dockerd
2026-10-04T17:19:52Z
dockerd_pid=66638
host_sock_inode=144
IDS-SAME
controller->docker: 29.8.2
== systemctl restart docker.socket
2026-10-04T17:20:00Z
active
active
dockerd_pid=67121
host_sock_inode=7202
IDS-SAME
felhom-controller sees: 144
traefik sees: 144
controller->docker: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
@@ -0,0 +1,30 @@
2026-10-04T17:22:27Z
felhom-controller Up 2 hours (healthy)
traefik Up 2 hours
(took 32ms)
2026/10/04 17:22:09 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 32ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
2026/10/04 17:22:09 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo starting (hddPath="/mnt/felhom-drives/scratch_hdd", hasCPUCollector=true)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readMemInfo: totalKB=30714356 availKB=25620992 → total=29994MB avail=25020MB used=4974MB (16.6%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/" bsize=4096 total=68.4GB used=5.6GB avail=59.2GB (8.3%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/mnt/felhom-drives/scratch_hdd" bsize=4096 total=937.8GB used=15.1GB avail=875.0GB (1.6%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readLoadAvg: raw="0.50 0.90 0.74 5/1182 23856" → 1m=0.50 5m=0.90 15m=0.74
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readThermalZones: /sys — found 1 zones
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readTemperature: found via hwmon at /sys — 52.9°C (hwmon1)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo done in 47ms — mem=4974MB/29994MB (16.6%), rootDisk=5.6GB/68.4GB (8.3%), load=0.50/0.90/0.74, temp=52.9°C (hwmon1), cpu=2.8%
2026/10/04 17:22:19 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job ring-spill: execution starting
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job deadapp-check: execution starting
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job health-probes: execution starting
2026/10/04 17:22:19 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: execution starting
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
2026/10/04 17:22:19 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
(took 24ms)
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 24ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
dashboard=302
@@ -0,0 +1,5 @@
1502 /usr/local/bin/felhom-controller
2026-10-04T17:22:40Z
17:22:45 running 2026-10-04T17:22:41.057453139Z restarts=1
controller sees: 7202 host: 7202
controller->docker: 29.8.2
@@ -0,0 +1,5 @@
traefik before: 144
2026-10-04T17:22:38Z ERR Provider error, retrying in 8.088174175s error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
2026-10-04T17:22:46Z ERR Failed to retrieve information of the docker client and server host error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
2026-10-04T17:22:46Z ERR Provider error, retrying in 11.956516688s error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
traefik after: 7202
@@ -0,0 +1,10 @@
RED never-worked guard removed
RED timeouts counted as refusals
RED exit removed
RED window ignored (exit at first refusal)
RED a success does not reset
RED CheckUsers acts while blind
RED same-inode skip removed
RED self not skipped
RED ENOENT not a refusal
unmutated: ok
@@ -0,0 +1,41 @@
T0 17:50:17 systemctl restart docker.socket
host sock inode: 9108
+10s controller->docker=
BLIND traefik_inode=7202 host=9108
+16s controller->docker=
BLIND traefik_inode=7202 host=9108
+21s controller->docker=
BLIND traefik_inode=7202 host=9108
+26s controller->docker=
BLIND traefik_inode=7202 host=9108
+31s controller->docker=
BLIND traefik_inode=7202 host=9108
+36s controller->docker=
BLIND traefik_inode=7202 host=9108
+41s controller->docker=
BLIND traefik_inode=7202 host=9108
+47s controller->docker=
BLIND traefik_inode=7202 host=9108
+52s controller->docker=
BLIND traefik_inode=7202 host=9108
+57s controller->docker=
BLIND traefik_inode=7202 host=9108
+62s controller->docker=
BLIND traefik_inode=7202 host=9108
+67s controller->docker=
BLIND traefik_inode=7202 host=9108
+73s controller->docker=29.8.2 traefik_inode=7202 host=9108
+78s controller->docker=29.8.2 traefik_inode=7202 host=9108
+83s controller->docker=29.8.2 traefik_inode=7202 host=9108
+88s controller->docker=29.8.2 traefik_inode=7202 host=9108
+94s controller->docker=29.8.2 traefik_inode=7202 host=9108
+99s controller->docker=29.8.2 traefik_inode=7202 host=9108
+104s controller->docker=29.8.2 traefik_inode=9108 host=9108
HEALED
== containers before/after (name id)
== controller log
2026/10/04 17:50:29 sockheal.go:118: [WARN] [sockheal] Docker refuses the socket (dial unix /var/run/docker.sock: connect: connection refused) — exiting after 1m0s of refusals so Docker restarts this controller on the current socket (R-860)
2026/10/04 17:51:29 sockheal.go:123: [ERROR] [sockheal] Docker has refused the socket for 1m0s (dial unix /var/run/docker.sock: connect: connection refused) — the socket file was re-created and this container holds the old one; EXITING (code 75) so Docker's restart policy brings it back on the current socket (R-860)
2026/10/04 17:52:00 sockheal.go:155: [WARN] [sockheal] traefik holds an old docker socket (inode 7202, current 9108) — restarting it (R-860)
2026/10/04 17:52:01 sockheal.go:160: [INFO] [sockheal] traefik restarted onto the current docker socket
controller restarts=1 started=2026-10-04T17:51:30.005016139Z
@@ -0,0 +1,6 @@
[golden] approved guest release: the template already runs every approved version
[golden] first-night count vs the approved guest release: 0 (target 0)
rc=0
[golden] no approved guest release given ��� the template versions stay; first-night count vs an approved release: n/a
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 1
rc=0
@@ -0,0 +1,39 @@
Sun Oct 4 17:08:29 UTC 2026
# GET /configs/drill-r50/delete (preview)
{
"claim_present": true,
"cloudflare_manual": null,
"customer_id": "drill-r50",
"customer_name": "drill-r50",
"dr_recipe_present": true,
"has_config": true,
"host_count": 1,
"hosts": [
{
"host_id": "drill-r50-0a4f9a",
"online": false,
"status": "down"
}
],
"offsite_enabled": false,
"offsite_identifier": "",
"offsite_type": "",
"one_time_secret": false,
"online_host_present": false,
"pbs_tenancy_configured": true,
"pending_journal": null,
"residue": {
"app_log_tails": 0,
"app_telemetry": 185,
"appliance_registrations": 1,
"log_tail_requests": 0,
"notification_prefs": 0,
"reports": 185,
"selfbind_tokens": 0
},
"residue_total": 371,
"superseded_blobs": 0
}
# GET /hosts/drill-r50-0a4f9a/delete-impact
{"deletable":true,"escrow_present":false,"guests":1,"log_bundles":0,"pbs_secret_present":false,"recovery_present":true,"reports":222,"status":"down","wg_peer_bound":true}
# hub DB (read-only copy): wg peer 10.77.0.4 bound to drill-r50-0a4f9a; customer email empty (no mail can go out); dr_tier 0; host last report 2026-08-13 06:11:41Z, agent 0.129.0
@@ -0,0 +1,5 @@
HTTP/1.1 303 See Other
Location: /configs?flash=deleted
Date: Sun, 04 Oct 2026 17:08:35 GMT
Content-Length: 0
@@ -0,0 +1,7 @@
2026/10/04 19:08:30 [INFO] customer DELETE cascade started for drill-r50 (journal #22, 1 host(s))
2026/10/04 19:08:32 [INFO] delete drill-r50: host drill-r50-0a4f9a deleted (escrow DEMOTED to retained custody)
2026/10/04 19:08:33 [INFO] tenantsync: deprovision ok for drill-r50 (ns=drill-r50, existed=false)
2026/10/04 19:08:33 [INFO] reset drill-r50: PBS tenancy deprovisioned
2026/10/04 19:08:33 [INFO] [claim] reset to unclaimed for drill-r50 (customer RESET) — next onboarding mints a fresh code
2026/10/04 19:08:35 [INFO] delete drill-r50: residue purged (reports=185 app_telemetry=185 app_log_tails=0 log_tail_requests=0 notif_prefs=0 selfbind_tokens=0 appliance_registrations=1)
2026/10/04 19:08:35 [INFO] customer DELETE cascade COMPLETE for drill-r50 (journal #22) — full teardown
@@ -0,0 +1,6 @@
Sun Oct 4 17:08:46 UTC 2026
# /hosts after
0
# preview after
404 page not found
http=404
@@ -0,0 +1,5 @@
Sun Oct 4 18:15:55 UTC 2026
anonymous GET https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.293.0/golden.tar.zst
http=200 bytes=648135998
sha256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
expected=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
@@ -0,0 +1,60 @@
# Golden 0.293.0 — bake + publish, 2026-10-04
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM on DooPlex.
Step 5 (vouching in the hub, the floor) was **not** done here — it is the main session's act.
| | Previous (`../golden-0.292.0-2026-10-04-rebake/`) | This bake |
|---|---|---|
| `build-golden.sh` | v3.1.0 | **v3.2.0** (agent `dc9164c`, sha256 `645b3b659cba…`; VM copy matched) |
| Controller | `felhom-controller:0.292.0` | **`felhom-controller:0.293.0`** (MinAgent 0.131.0, unchanged) |
| Docker engine | pinned, approved set | same pinned set: the operator-approved release `os-docker-20261004-142842` (stays in force) |
| Guest packages | template | template — `GOLDEN_GUEST_PKGS` deliberately EMPTY (see below) |
**Why the guest list is empty.** The only guest release, `os-guest-20261004-123933`, was approved under a TEST wait;
hub v0.133.0 (R-859) cancels it at start. No guest release is in force tonight, so the bake installs no guest fixes,
and the box's first night installs whatever release is approved then. The bake reported **49 pending Debian upgrades**
in the baked guest — what a future approval may bring, NOT what the first night installs (a ring-1 box installs only
an approved release; with none in force, 0).
## Launch
- Drill VM reverted to `virgin`, cold-booted per §4.0; `pveversion` = `pve-manager/9.2.2`.
- `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst` (the only `_amd64`
debian-13 entry), downloaded, checksum verified.
- `/root/bake-run.sh` in the VM reads the token from the file and exports `GOLDEN_DOCKER_PKGS` (the six approved
versions) and `GOLDEN_GUEST_PKGS=""`; launched as transient unit `golden-bake`.
- Token copied file → file (`scp`). `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F <token>` =
**0** (control with the token appended = **1**).
## Pass markers (from `bake.log`)
```
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie … docker-ce=5:29.8.2-1~debian.13~trixie …
[golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49
docker OK (overlay2; data-root /var/lib/docker)
live-restore: on
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
[golden] upload OK (HTTP 201)
GOLDEN_VERSION=0.293.0
GOLDEN_SHA256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
```
No `excluding` and no `FATAL` in the log. Pre-delete before upload: HTTP 404 (a new version, nothing replaced).
## Round trip
Anonymous GET of `…/generic/felhom-golden/0.293.0/golden.tar.zst`: HTTP 200, **648135998 bytes**, sha256
`e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7` = the printed sha (`02-round-trip.txt`).
## Secrets
Saved-log leak grep for the literal token: **0**; positive control (a throwaway copy with the token appended): **1**,
copy shredded.
## Teardown
`pct destroy 9100 --purge`; `shred -u` of the token, the runner script and the log in the VM (log copied off first);
`poweroff`; qemu gone (`ps -eo comm | grep -c qemu-system-x86` = 0); `qemu-img snapshot -a virgin`. Host: nothing
provisioned. Hub: not touched.
@@ -0,0 +1,342 @@
[golden] build-golden.sh v3.2.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.293.0
[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) …
Logical volume "vm-9100-disk-0" created.
Logical volume pve/vm-9100-disk-0 changed.
Creating filesystem with 8388608 4k blocks and 2097152 inodes
Filesystem UUID: 2ba3ff4c-bddd-47f5-b0dc-5f1949f4c908
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
4096000, 7962624
Logical volume "vm-9100-disk-1" created.
Logical volume pve/vm-9100-disk-1 changed.
Creating filesystem with 6291456 4k blocks and 1572864 inodes
Filesystem UUID: 6565d64c-6e4b-45bc-b4ea-59f5bd2f7d91
Superblock backups stored on blocks:
32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst'
Total bytes read: 553512960 (528MiB, 148MiB/s)
Detected container architecture: amd64
Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ...
done: SHA256:bGe7bRQch/Qk8hF5xTuvA4Mxm+o6J4x3G1W6uVOxLR0 root@felhom-golden
Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ...
done: SHA256:NCGNrT/PBO54a0wAfNAyyTzRoJbPfgrmNSmZDW+x2y0 root@felhom-golden
Creating SSH host key 'ssh_host_rsa_key' - this may take some time ...
done: SHA256:2yzTbaa+8zgXS4BGskQLtirKN/dy1YKmVddc2s7925o root@felhom-golden
[golden] starting + installing Docker (official repo, trixie channel) …
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct!
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = (unset),
LC_COLLATE = (unset),
LC_TIME = (unset),
LC_MESSAGES = (unset),
LC_MONETARY = (unset),
LC_ADDRESS = (unset),
LC_IDENTIFICATION = (unset),
LC_MEASUREMENT = (unset),
LC_PAPER = (unset),
LC_TELEPHONE = (unset),
LC_NAME = (unset),
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
locale: Cannot set LC_CTYPE to default locale: No such file or directory
locale: Cannot set LC_MESSAGES to default locale: No such file or directory
locale: Cannot set LC_ALL to default locale: No such file or directory
installed: containerd.io 2.3.6-1~debian.13~trixie
installed: docker-buildx-plugin 0.37.1-1~debian.13~trixie
installed: docker-ce 5:29.8.2-1~debian.13~trixie
installed: docker-ce-cli 5:29.8.2-1~debian.13~trixie
installed: docker-ce-rootless-extras 5:29.8.2-1~debian.13~trixie
installed: docker-compose-plugin 5.6.0-1~debian.13~trixie
[golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49
[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation …
[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds …
[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) …
Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
4f55086f7dd0: Pulling fs layer
4f55086f7dd0: Verifying Checksum
4f55086f7dd0: Download complete
4f55086f7dd0: Pull complete
Digest: sha256:5e23090353324d887c48ad5e5c56d294eab81588df9605b07d1afe895f9cc8f8
Status: Downloaded newer image for hello-world:latest
docker OK (overlay2; data-root /var/lib/docker)
live-restore: on
/var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4
/mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4
both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576
[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.293.0 (no registry cred at deploy) …
WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'.
Configure a credential helper to remove this warning. See
https://docs.docker.com/go/credential-store/
0.293.0: Pulling from admin/felhom-controller
774043ccc8cc: Pulling fs layer
ab6b448d4be9: Pulling fs layer
23a5bfa58353: Pulling fs layer
862a57157567: Pulling fs layer
c3ec21eb492c: Pulling fs layer
fc53ea013f38: Pulling fs layer
862a57157567: Waiting
c3ec21eb492c: Waiting
fc53ea013f38: Waiting
774043ccc8cc: Verifying Checksum
774043ccc8cc: Download complete
23a5bfa58353: Verifying Checksum
23a5bfa58353: Download complete
862a57157567: Verifying Checksum
862a57157567: Download complete
c3ec21eb492c: Verifying Checksum
c3ec21eb492c: Download complete
fc53ea013f38: Verifying Checksum
fc53ea013f38: Download complete
ab6b448d4be9: Verifying Checksum
ab6b448d4be9: Download complete
774043ccc8cc: Pull complete
ab6b448d4be9: Pull complete
23a5bfa58353: Pull complete
862a57157567: Pull complete
c3ec21eb492c: Pull complete
fc53ea013f38: Pull complete
Digest: sha256:b1407516c4c4f9d8dcd35ea8ab56d177139e8858d37ab1b3a4e6be84ec9be3ae
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.293.0
gitea.dooplex.hu/admin/felhom-controller:0.293.0
[golden] asking the controller which infra images it manages …
[golden] baking infra images (4): traefik:v3.7.13 cloudflare/cloudflared:2026.9.3 gtstef/filebrowser:1.5.6-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 …
v3.7.13: Pulling from library/traefik
e2de96513ba9: Pulling fs layer
b686a4f73445: Pulling fs layer
78cb21c375ca: Pulling fs layer
acb2f33459b1: Pulling fs layer
acb2f33459b1: Waiting
e2de96513ba9: Verifying Checksum
e2de96513ba9: Download complete
b686a4f73445: Verifying Checksum
b686a4f73445: Download complete
e2de96513ba9: Pull complete
acb2f33459b1: Verifying Checksum
acb2f33459b1: Download complete
78cb21c375ca: Verifying Checksum
78cb21c375ca: Download complete
b686a4f73445: Pull complete
78cb21c375ca: Pull complete
acb2f33459b1: Pull complete
Digest: sha256:24841fe2de7304c149343d877d2923b4c8800a38ba015dea9174c23b20e344a0
Status: Downloaded newer image for traefik:v3.7.13
docker.io/library/traefik:v3.7.13
2026.9.3: Pulling from cloudflare/cloudflared
2cc7ee286bf3: Pulling fs layer
c172f21841df: Pulling fs layer
218cf840d0d9: Pulling fs layer
f6069939f718: Pulling fs layer
d6b1b89eccac: Pulling fs layer
2780920e5dbf: Pulling fs layer
7c12895b777b: Pulling fs layer
3214acf345c0: Pulling fs layer
52630fc75a18: Pulling fs layer
dd64bf2dd177: Pulling fs layer
b839dfae01f6: Pulling fs layer
ebddc55facdc: Pulling fs layer
c4bc6f35ff5e: Pulling fs layer
b96fe2995f90: Pulling fs layer
58c0c263dc73: Pulling fs layer
bd8962e29291: Pulling fs layer
cac2ae0193cb: Pulling fs layer
f0383d5ebc47: Pulling fs layer
f6069939f718: Waiting
d6b1b89eccac: Waiting
2780920e5dbf: Waiting
7c12895b777b: Waiting
3214acf345c0: Waiting
52630fc75a18: Waiting
dd64bf2dd177: Waiting
b839dfae01f6: Waiting
ebddc55facdc: Waiting
c4bc6f35ff5e: Waiting
b96fe2995f90: Waiting
58c0c263dc73: Waiting
bd8962e29291: Waiting
cac2ae0193cb: Waiting
f0383d5ebc47: Waiting
c172f21841df: Verifying Checksum
c172f21841df: Download complete
2cc7ee286bf3: Download complete
f6069939f718: Verifying Checksum
f6069939f718: Download complete
d6b1b89eccac: Verifying Checksum
d6b1b89eccac: Download complete
2cc7ee286bf3: Pull complete
2780920e5dbf: Verifying Checksum
2780920e5dbf: Download complete
c172f21841df: Pull complete
218cf840d0d9: Verifying Checksum
218cf840d0d9: Download complete
218cf840d0d9: Pull complete
7c12895b777b: Download complete
52630fc75a18: Verifying Checksum
52630fc75a18: Download complete
3214acf345c0: Verifying Checksum
3214acf345c0: Download complete
dd64bf2dd177: Verifying Checksum
dd64bf2dd177: Download complete
b839dfae01f6: Verifying Checksum
b839dfae01f6: Download complete
ebddc55facdc: Verifying Checksum
ebddc55facdc: Download complete
c4bc6f35ff5e: Verifying Checksum
c4bc6f35ff5e: Download complete
b96fe2995f90: Verifying Checksum
b96fe2995f90: Download complete
58c0c263dc73: Verifying Checksum
58c0c263dc73: Download complete
f6069939f718: Pull complete
d6b1b89eccac: Pull complete
cac2ae0193cb: Verifying Checksum
cac2ae0193cb: Download complete
f0383d5ebc47: Verifying Checksum
f0383d5ebc47: Download complete
2780920e5dbf: Pull complete
7c12895b777b: Pull complete
bd8962e29291: Verifying Checksum
bd8962e29291: Download complete
3214acf345c0: Pull complete
52630fc75a18: Pull complete
dd64bf2dd177: Pull complete
b839dfae01f6: Pull complete
ebddc55facdc: Pull complete
c4bc6f35ff5e: Pull complete
b96fe2995f90: Pull complete
58c0c263dc73: Pull complete
bd8962e29291: Pull complete
cac2ae0193cb: Pull complete
f0383d5ebc47: Pull complete
Digest: sha256:072c067d25ccbe61d46e18f0d0723255f2bb5304f7317caa95b27031520ff92c
Status: Downloaded newer image for cloudflare/cloudflared:2026.9.3
docker.io/cloudflare/cloudflared:2026.9.3
1.5.6-stable: Pulling from gtstef/filebrowser
55afa1ecc21d: Pulling fs layer
8ed8f35f8d4f: Pulling fs layer
989b226a579c: Pulling fs layer
660aeead31d5: Pulling fs layer
4f4fb700ef54: Pulling fs layer
adce24567e4c: Pulling fs layer
f17ea56b313b: Pulling fs layer
6b6f3b3efe88: Pulling fs layer
4ed1ca4f3fce: Pulling fs layer
e6fc9c6a5757: Pulling fs layer
d47782d1182a: Pulling fs layer
6b6f3b3efe88: Waiting
4ed1ca4f3fce: Waiting
e6fc9c6a5757: Waiting
d47782d1182a: Waiting
4f4fb700ef54: Waiting
adce24567e4c: Waiting
f17ea56b313b: Waiting
660aeead31d5: Waiting
55afa1ecc21d: Verifying Checksum
55afa1ecc21d: Download complete
8ed8f35f8d4f: Verifying Checksum
8ed8f35f8d4f: Download complete
55afa1ecc21d: Pull complete
989b226a579c: Verifying Checksum
989b226a579c: Download complete
4f4fb700ef54: Verifying Checksum
4f4fb700ef54: Download complete
660aeead31d5: Verifying Checksum
660aeead31d5: Download complete
6b6f3b3efe88: Verifying Checksum
6b6f3b3efe88: Download complete
adce24567e4c: Verifying Checksum
adce24567e4c: Download complete
f17ea56b313b: Verifying Checksum
f17ea56b313b: Download complete
4ed1ca4f3fce: Verifying Checksum
4ed1ca4f3fce: Download complete
d47782d1182a: Verifying Checksum
d47782d1182a: Download complete
e6fc9c6a5757: Verifying Checksum
e6fc9c6a5757: Download complete
8ed8f35f8d4f: Pull complete
989b226a579c: Pull complete
660aeead31d5: Pull complete
4f4fb700ef54: Pull complete
adce24567e4c: Pull complete
f17ea56b313b: Pull complete
6b6f3b3efe88: Pull complete
4ed1ca4f3fce: Pull complete
e6fc9c6a5757: Pull complete
d47782d1182a: Pull complete
Digest: sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8
Status: Downloaded newer image for gtstef/filebrowser:1.5.6-stable
docker.io/gtstef/filebrowser:1.5.6-stable
1.1.0: Pulling from admin/felhom-samba
897d797d2723: Pulling fs layer
3051591aa250: Pulling fs layer
ce57a3f93416: Pulling fs layer
fb94eeec2fe1: Pulling fs layer
fb94eeec2fe1: Waiting
ce57a3f93416: Verifying Checksum
ce57a3f93416: Download complete
fb94eeec2fe1: Verifying Checksum
fb94eeec2fe1: Download complete
897d797d2723: Verifying Checksum
897d797d2723: Download complete
3051591aa250: Verifying Checksum
3051591aa250: Download complete
897d797d2723: Pull complete
3051591aa250: Pull complete
ce57a3f93416: Pull complete
fb94eeec2fe1: Pull complete
Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10
Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0
gitea.dooplex.hu/admin/felhom-samba:1.1.0
[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'.
[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'.
[golden] baking the first-boot SSH host-key regeneration unit (F3) …
Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'.
[golden] identity-clean + minimize …
[golden] stop + archive …
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
INFO: archive file size: 618MB
INFO: Finished Backup of VM 9100 (00:00:29)
[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_10_04-20_14_33.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive)
[golden] publishing golden (648135998 bytes, sha256 e7966872abeb38db…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.293.0/golden.tar.zst
[golden] pre-delete existing: HTTP 404 (404/204 expected)
[golden] upload OK (HTTP 201)
GOLDEN_VERSION=0.293.0
GOLDEN_SHA256=e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.293.0 / e7966872abeb38db320e7b26bd9baf6527e87270ed2faf3f0e53763bfc4764b7
[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge)