hub v0.133.0 (R-859 test approvals end with the test; R-840 bundle on the System page, manifest, alarm); installer 1.31.0 (root files from the config bundle); bundle bootstrap script; golden 0.293.0 evidence; rulings 96–99; drill-r50 removed (evidence)
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
== demo-hp
|
||||
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-pbs-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
|
||||
DIFF /usr/local/sbin/felhom-os-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-crash-guard 755:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
|
||||
SAME /etc/felhom/crash-guard.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
|
||||
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
|
||||
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
|
||||
SAME /etc/systemd/system/felhom-sshd.service 644:root
|
||||
SAME /etc/felhom-oob.nft 644:root
|
||||
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
|
||||
SAME /etc/sudoers.d/felhom-op 440:root
|
||||
SAME /etc/sudoers.d/felhom-agent 440:root
|
||||
total 24
|
||||
drwxr-xr-x 2 root root 4096 Oct 4 16:08 .
|
||||
drwxr-xr-x 102 root root 4096 Oct 4 09:41 ..
|
||||
-rw-r--r-- 1 root root 0 Aug 21 18:01 .bootstrap-done
|
||||
-rw-r--r-- 1 root root 7 Aug 21 17:44 appliance-pairing-code
|
||||
-rw-r--r-- 1 root root 456 Oct 4 16:08 crash-guard.conf
|
||||
-rw-r--r-- 1 root root 131 Oct 4 16:08 operator-signers
|
||||
-rw-r--r-- 1 root root 61 Oct 4 18:34 os-trust.json
|
||||
felhom-agent 0.142.1
|
||||
== felhom-pve
|
||||
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
|
||||
SAME /usr/local/sbin/felhom-pbs-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
|
||||
DIFF /usr/local/sbin/felhom-os-apply 755:root
|
||||
SAME /usr/local/sbin/felhom-crash-guard 755:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
|
||||
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
|
||||
SAME /etc/felhom/crash-guard.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
|
||||
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
|
||||
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
|
||||
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
|
||||
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
|
||||
SAME /etc/systemd/system/felhom-sshd.service 644:root
|
||||
SAME /etc/felhom-oob.nft 644:root
|
||||
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
|
||||
SAME /etc/sudoers.d/felhom-op 440:root
|
||||
SAME /etc/sudoers.d/felhom-agent 440:root
|
||||
total 24
|
||||
drwxr-xr-x 2 root root 4096 Oct 4 16:12 .
|
||||
drwxr-xr-x 102 root root 4096 Oct 4 13:35 ..
|
||||
-rw-r--r-- 1 root root 0 Jul 18 18:32 .bootstrap-done
|
||||
-rw-r--r-- 1 root root 7 Jul 18 18:17 appliance-pairing-code
|
||||
-rw-r--r-- 1 root root 456 Oct 4 16:12 crash-guard.conf
|
||||
-rw-r--r-- 1 root root 131 Oct 4 16:12 operator-signers
|
||||
-rw-r--r-- 1 root root 65 Oct 4 18:34 os-trust.json
|
||||
felhom-agent 0.142.1
|
||||
@@ -0,0 +1,16 @@
|
||||
--- wrong sha (red):
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
STOP: the bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, not 0000000000000000000000000000000000000000000000000000000000000000 — nothing changed
|
||||
rc=1
|
||||
bdf60f5c79a84db7ebcfe1620fe832436caab831259308906eda08627aac7260 /usr/local/sbin/felhom-os-apply
|
||||
--- right sha:
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
|
||||
2/4 take felhom-os-apply out of the bundle and check it
|
||||
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
|
||||
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
|
||||
4/4 self-check
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba /usr/local/sbin/felhom-os-apply
|
||||
@@ -0,0 +1,9 @@
|
||||
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
|
||||
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
|
||||
2/4 take felhom-os-apply out of the bundle and check it
|
||||
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
|
||||
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
|
||||
4/4 self-check
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
felhom-os-apply ok bundle-format=1 files=22
|
||||
DONE. This box can now take signed config bundles. Nothing else was changed.
|
||||
rc=0
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=10242c3b… durable_id=""
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
|
||||
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=1e60311ec9cad857 op=agent_config_update key_id=felhom-op-1 nonce=10242c3bac90859807c1ab3dfd497a9a
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.002+02:00 level=ERROR msg="signedjobs: signed op execution FAILED (nonce spent — clearing)" job=1e60311ec9cad857 op=agent_config_update err="agent_config_update: the downloaded bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, the signed job pins 111111111111111111111111111111111111111111111
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=eb8a8219… durable_id=""
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=fa3df5a93740111e op=agent_config_update key_id=felhom-op-1 nonce=eb8a8219c7ab393e6702dc8a34cc578f
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.032+02:00 level=INFO msg="osupdate: config bundle downloaded; handing it to the root wrapper" op=agent_config_update agent_version=0.143.0 sha256=8d7273cf5313ef62 duration_ms=15
|
||||
Oct 04 20:04:35 demo-hp felhom-os-apply[496014]: os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0
|
||||
Oct 04 20:04:35 demo-hp felhom-os-apply[496158]: os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0"
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False"
|
||||
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=WARN msg="osupdate: config bundle INSTALLED" op=agent_config_update agent_version=0.143.0 bundle="{\"agent_version\": \"0.143.0\", \"authority\": \"signed\", \"kept\": [\"/etc/felhom/crash-guard.conf\"], \"prev_dir\": \"/var/lib/felhom-os-apply/bundle-prev/20261004T180435Z-before-0.143.0\", \"same\": 21, \"self_
|
||||
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="osupdate: capability probe after the config bundle" ok=71 total=71 degraded=""
|
||||
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="signedjobs: signed op COMPLETED" job=fa3df5a93740111e op=agent_config_update
|
||||
|
||||
[exited with code 0]
|
||||
{
|
||||
"agent_version": "0.143.0",
|
||||
"authority": "signed",
|
||||
"bundle_sha256": "8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba",
|
||||
"files": {
|
||||
"/etc/felhom-oob.nft": "2c2b9cca89a439ac44efd353f4ea1936b3609ca43491b4c1853483e8321f238f",
|
||||
"/etc/felhom/crash-guard.conf": "9b9d305b421f81d223f2ccc4594e67d41618239779d983a2f72c191a8b3b65f7",
|
||||
"/etc/sudoers.d/felhom-agent": "02df92d751f1780aecbf600b2632b2366fcedeb3601852ebfa98c700e95f4dfc",
|
||||
-rw-r--r-- 1 root root 2754 Oct 4 20:04 /etc/felhom/config-bundle.json
|
||||
@@ -0,0 +1,8 @@
|
||||
RED no 7-day wait
|
||||
RED unknown counted as behind
|
||||
RED clock never clears
|
||||
GREEN! alarm without a vouched bundle
|
||||
RED cell never red
|
||||
RED exact lookup falls back to the first file
|
||||
unmutated: ok
|
||||
RED alarm without a vouched bundle (test strengthened: a box WITH a bundle, nothing vouched)
|
||||
@@ -0,0 +1,24 @@
|
||||
RED R17 trust-path check removed -> test_a_bundle_that_changes_a_signer_is_refused
|
||||
RED R16 table check removed -> test_a_path_outside_the_table_is_refused
|
||||
RED bundle sha check removed -> test_wrong_sha_is_refused
|
||||
RED per-file sha check removed -> test_content_not_matching_its_sha_is_refused
|
||||
RED version pin removed -> test_version_mismatch_is_refused
|
||||
RED visudo/sh/nft content check removed -> test_sudoers_failing_visudo_is_refused
|
||||
RED python compile check removed -> test_python_syntax_error_is_refused
|
||||
RED RuntimeDirectory guard removed -> test_unit_with_runtime_directory_is_refused
|
||||
RED agent-unit User= check removed -> test_agent_unit_not_as_the_agent_user_is_refused
|
||||
RED route-line pre-check removed -> test_sudoers_dropping_the_route_is_refused
|
||||
RED wrapper bundle-mode pre-check removed -> test_wrapper_without_bundle_mode_is_refused
|
||||
RED table re-ordering removed -> test_sudoers_is_written_after_every_wrapper
|
||||
RED self-check sudo -l removed -> test_route_missing_after_install_puts_everything_back
|
||||
RED undo removed -> test_route_missing_after_install_puts_everything_back
|
||||
RED crash-guard kernel.panic self-check removed -> test_crash_guard_disagreeing_with_kernel_panic_puts_everything_back
|
||||
RED nonce burn removed -> test_fresh_box_gets_every_file_and_a_record
|
||||
RED nonce burned before the sha check -> test_wrong_sha_is_refused
|
||||
RED pinned-key bootstrap removed (always the file) -> test_missing_signers_verifies_against_the_pinned_key_and_creates_it
|
||||
RED signers written even when present -> test_present_signers_are_never_touched
|
||||
RED SUDO_UID refusal removed -> test_installer_entry_is_refused_through_sudo
|
||||
RED if-absent policy ignored -> test_tuned_crash_guard_conf_is_kept
|
||||
RED oob policy ignored -> test_fresh_box_gets_every_file_and_a_record
|
||||
unmutated: OK
|
||||
ALL RED
|
||||
@@ -0,0 +1,7 @@
|
||||
RED approval never marked
|
||||
RED a cancelled release is still served
|
||||
RED cancels while the override is still on
|
||||
RED superseded ones cancelled too
|
||||
RED no backfill
|
||||
RED ring-1 boxes not bumped
|
||||
unmutated: ok
|
||||
@@ -0,0 +1,41 @@
|
||||
+ date -u +%FT%TZ
|
||||
2026-10-04T17:19:25Z
|
||||
+ docker ps -q --no-trunc
|
||||
+ sort
|
||||
+ wc -l
|
||||
6
|
||||
+ pidof dockerd
|
||||
+ echo dockerd_pid=225
|
||||
+ stat -c host_sock_inode=%i /var/run/docker.sock
|
||||
dockerd_pid=225
|
||||
host_sock_inode=144
|
||||
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
|
||||
felhom-controller sees: 144
|
||||
+ echo felhom-controller sees: 144
|
||||
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
|
||||
traefik sees: 144
|
||||
+ echo traefik sees: 144
|
||||
+ systemctl restart docker
|
||||
+ date -u +%FT%TZ
|
||||
2026-10-04T17:19:31Z
|
||||
+ sleep 5
|
||||
+ pidof dockerd
|
||||
dockerd_pid=66020
|
||||
+ echo dockerd_pid=66020
|
||||
+ stat -c host_sock_inode=%i /var/run/docker.sock
|
||||
host_sock_inode=144
|
||||
+ docker ps -q --no-trunc
|
||||
+ sort
|
||||
+ diff /tmp/ids.before /tmp/ids.after
|
||||
IDS-SAME
|
||||
+ echo IDS-SAME
|
||||
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
|
||||
felhom-controller sees: 144
|
||||
+ echo felhom-controller sees: 144
|
||||
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
|
||||
traefik sees: 144
|
||||
+ echo traefik sees: 144
|
||||
+ docker exec felhom-controller docker version --format {{.Server.Version}}
|
||||
+ tail -1
|
||||
controller->docker: 29.8.2
|
||||
+ echo controller->docker: 29.8.2
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
After=network-online.target nss-lookup.target docker.socket firewalld.service containerd.service time-set.target
|
||||
Wants=network-online.target containerd.service
|
||||
Requires=docker.socket
|
||||
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
|
||||
Restart=always
|
||||
# specify ListenStream=/var/run/docker.sock instead.
|
||||
ListenStream=/run/docker.sock
|
||||
SocketMode=0660
|
||||
== kill -9 dockerd
|
||||
2026-10-04T17:19:52Z
|
||||
dockerd_pid=66638
|
||||
host_sock_inode=144
|
||||
IDS-SAME
|
||||
controller->docker: 29.8.2
|
||||
== systemctl restart docker.socket
|
||||
2026-10-04T17:20:00Z
|
||||
active
|
||||
active
|
||||
dockerd_pid=67121
|
||||
host_sock_inode=7202
|
||||
IDS-SAME
|
||||
felhom-controller sees: 144
|
||||
traefik sees: 144
|
||||
controller->docker: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
@@ -0,0 +1,30 @@
|
||||
2026-10-04T17:22:27Z
|
||||
felhom-controller Up 2 hours (healthy)
|
||||
traefik Up 2 hours
|
||||
(took 32ms)
|
||||
2026/10/04 17:22:09 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 32ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
2026/10/04 17:22:09 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo starting (hddPath="/mnt/felhom-drives/scratch_hdd", hasCPUCollector=true)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readMemInfo: totalKB=30714356 availKB=25620992 → total=29994MB avail=25020MB used=4974MB (16.6%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/" bsize=4096 total=68.4GB used=5.6GB avail=59.2GB (8.3%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/mnt/felhom-drives/scratch_hdd" bsize=4096 total=937.8GB used=15.1GB avail=875.0GB (1.6%)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readLoadAvg: raw="0.50 0.90 0.74 5/1182 23856" → 1m=0.50 5m=0.90 15m=0.74
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readThermalZones: /sys — found 1 zones
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readTemperature: found via hwmon at /sys — 52.9°C (hwmon1)
|
||||
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo done in 47ms — mem=4974MB/29994MB (16.6%), rootDisk=5.6GB/68.4GB (8.3%), load=0.50/0.90/0.74, temp=52.9°C (hwmon1), cpu=2.8%
|
||||
2026/10/04 17:22:19 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job ring-spill: execution starting
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job deadapp-check: execution starting
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job health-probes: execution starting
|
||||
2026/10/04 17:22:19 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: execution starting
|
||||
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
|
||||
2026/10/04 17:22:19 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
(took 24ms)
|
||||
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 24ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
|
||||
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
|
||||
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
|
||||
|
||||
dashboard=302
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
1502 /usr/local/bin/felhom-controller
|
||||
2026-10-04T17:22:40Z
|
||||
17:22:45 running 2026-10-04T17:22:41.057453139Z restarts=1
|
||||
controller sees: 7202 host: 7202
|
||||
controller->docker: 29.8.2
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
traefik before: 144
|
||||
[90m2026-10-04T17:22:38Z[0m [31mERR[0m [1mProvider error, retrying in 8.088174175s[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
[90m2026-10-04T17:22:46Z[0m [31mERR[0m [1mFailed to retrieve information of the docker client and server host[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
[90m2026-10-04T17:22:46Z[0m [31mERR[0m [1mProvider error, retrying in 11.956516688s[0m [36merror=[0m[31m[1m"Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?"[0m[0m [36mproviderName=[0mdocker
|
||||
traefik after: 7202
|
||||
@@ -0,0 +1,10 @@
|
||||
RED never-worked guard removed
|
||||
RED timeouts counted as refusals
|
||||
RED exit removed
|
||||
RED window ignored (exit at first refusal)
|
||||
RED a success does not reset
|
||||
RED CheckUsers acts while blind
|
||||
RED same-inode skip removed
|
||||
RED self not skipped
|
||||
RED ENOENT not a refusal
|
||||
unmutated: ok
|
||||
@@ -0,0 +1,41 @@
|
||||
T0 17:50:17 systemctl restart docker.socket
|
||||
host sock inode: 9108
|
||||
+10s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+16s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+21s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+26s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+31s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+36s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+41s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+47s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+52s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+57s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+62s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+67s controller->docker=
|
||||
BLIND traefik_inode=7202 host=9108
|
||||
+73s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+78s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+83s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+88s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+94s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+99s controller->docker=29.8.2 traefik_inode=7202 host=9108
|
||||
+104s controller->docker=29.8.2 traefik_inode=9108 host=9108
|
||||
HEALED
|
||||
== containers before/after (name id)
|
||||
== controller log
|
||||
2026/10/04 17:50:29 sockheal.go:118: [WARN] [sockheal] Docker refuses the socket (dial unix /var/run/docker.sock: connect: connection refused) — exiting after 1m0s of refusals so Docker restarts this controller on the current socket (R-860)
|
||||
2026/10/04 17:51:29 sockheal.go:123: [ERROR] [sockheal] Docker has refused the socket for 1m0s (dial unix /var/run/docker.sock: connect: connection refused) — the socket file was re-created and this container holds the old one; EXITING (code 75) so Docker's restart policy brings it back on the current socket (R-860)
|
||||
2026/10/04 17:52:00 sockheal.go:155: [WARN] [sockheal] traefik holds an old docker socket (inode 7202, current 9108) — restarting it (R-860)
|
||||
2026/10/04 17:52:01 sockheal.go:160: [INFO] [sockheal] traefik restarted onto the current docker socket
|
||||
controller restarts=1 started=2026-10-04T17:51:30.005016139Z
|
||||
@@ -0,0 +1,6 @@
|
||||
[golden] approved guest release: the template already runs every approved version
|
||||
[golden] first-night count vs the approved guest release: 0 (target 0)
|
||||
rc=0
|
||||
[golden] no approved guest release given ��� the template versions stay; first-night count vs an approved release: n/a
|
||||
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 1
|
||||
rc=0
|
||||
@@ -0,0 +1,39 @@
|
||||
Sun Oct 4 17:08:29 UTC 2026
|
||||
# GET /configs/drill-r50/delete (preview)
|
||||
{
|
||||
"claim_present": true,
|
||||
"cloudflare_manual": null,
|
||||
"customer_id": "drill-r50",
|
||||
"customer_name": "drill-r50",
|
||||
"dr_recipe_present": true,
|
||||
"has_config": true,
|
||||
"host_count": 1,
|
||||
"hosts": [
|
||||
{
|
||||
"host_id": "drill-r50-0a4f9a",
|
||||
"online": false,
|
||||
"status": "down"
|
||||
}
|
||||
],
|
||||
"offsite_enabled": false,
|
||||
"offsite_identifier": "",
|
||||
"offsite_type": "",
|
||||
"one_time_secret": false,
|
||||
"online_host_present": false,
|
||||
"pbs_tenancy_configured": true,
|
||||
"pending_journal": null,
|
||||
"residue": {
|
||||
"app_log_tails": 0,
|
||||
"app_telemetry": 185,
|
||||
"appliance_registrations": 1,
|
||||
"log_tail_requests": 0,
|
||||
"notification_prefs": 0,
|
||||
"reports": 185,
|
||||
"selfbind_tokens": 0
|
||||
},
|
||||
"residue_total": 371,
|
||||
"superseded_blobs": 0
|
||||
}
|
||||
# GET /hosts/drill-r50-0a4f9a/delete-impact
|
||||
{"deletable":true,"escrow_present":false,"guests":1,"log_bundles":0,"pbs_secret_present":false,"recovery_present":true,"reports":222,"status":"down","wg_peer_bound":true}
|
||||
# hub DB (read-only copy): wg peer 10.77.0.4 bound to drill-r50-0a4f9a; customer email empty (no mail can go out); dr_tier 0; host last report 2026-08-13 06:11:41Z, agent 0.129.0
|
||||
@@ -0,0 +1,5 @@
|
||||
HTTP/1.1 303 See Other
|
||||
Location: /configs?flash=deleted
|
||||
Date: Sun, 04 Oct 2026 17:08:35 GMT
|
||||
Content-Length: 0
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
2026/10/04 19:08:30 [INFO] customer DELETE cascade started for drill-r50 (journal #22, 1 host(s))
|
||||
2026/10/04 19:08:32 [INFO] delete drill-r50: host drill-r50-0a4f9a deleted (escrow DEMOTED to retained custody)
|
||||
2026/10/04 19:08:33 [INFO] tenantsync: deprovision ok for drill-r50 (ns=drill-r50, existed=false)
|
||||
2026/10/04 19:08:33 [INFO] reset drill-r50: PBS tenancy deprovisioned
|
||||
2026/10/04 19:08:33 [INFO] [claim] reset to unclaimed for drill-r50 (customer RESET) — next onboarding mints a fresh code
|
||||
2026/10/04 19:08:35 [INFO] delete drill-r50: residue purged (reports=185 app_telemetry=185 app_log_tails=0 log_tail_requests=0 notif_prefs=0 selfbind_tokens=0 appliance_registrations=1)
|
||||
2026/10/04 19:08:35 [INFO] customer DELETE cascade COMPLETE for drill-r50 (journal #22) — full teardown
|
||||
@@ -0,0 +1,6 @@
|
||||
Sun Oct 4 17:08:46 UTC 2026
|
||||
# /hosts after
|
||||
0
|
||||
# preview after
|
||||
404 page not found
|
||||
http=404
|
||||
Reference in New Issue
Block a user