hub v0.133.0 (R-859 test approvals end with the test; R-840 bundle on the System page, manifest, alarm); installer 1.31.0 (root files from the config bundle); bundle bootstrap script; golden 0.293.0 evidence; rulings 96–99; drill-r50 removed (evidence)
gates / gates (push) Successful in 29s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 20:18:37 +02:00
parent 6b820143f8
commit ff1db11db4
45 changed files with 1707 additions and 42 deletions
@@ -0,0 +1,64 @@
== demo-hp
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
SAME /usr/local/sbin/felhom-pbs-apply 755:root
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
DIFF /usr/local/sbin/felhom-os-apply 755:root
SAME /usr/local/sbin/felhom-crash-guard 755:root
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
SAME /etc/felhom/crash-guard.conf 644:root
SAME /etc/systemd/system/felhom-agent.service 644:root
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
SAME /etc/systemd/system/felhom-sshd.service 644:root
SAME /etc/felhom-oob.nft 644:root
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
SAME /etc/sudoers.d/felhom-op 440:root
SAME /etc/sudoers.d/felhom-agent 440:root
total 24
drwxr-xr-x 2 root root 4096 Oct 4 16:08 .
drwxr-xr-x 102 root root 4096 Oct 4 09:41 ..
-rw-r--r-- 1 root root 0 Aug 21 18:01 .bootstrap-done
-rw-r--r-- 1 root root 7 Aug 21 17:44 appliance-pairing-code
-rw-r--r-- 1 root root 456 Oct 4 16:08 crash-guard.conf
-rw-r--r-- 1 root root 131 Oct 4 16:08 operator-signers
-rw-r--r-- 1 root root 61 Oct 4 18:34 os-trust.json
felhom-agent 0.142.1
== felhom-pve
SAME /usr/local/sbin/felhom-mkfs-guarded 755:root
SAME /usr/local/sbin/felhom-selfupdate-guarded 755:root
SAME /usr/local/sbin/felhom-pbs-apply 755:root
SAME /usr/local/sbin/felhom-backup-target-apply 755:root
DIFF /usr/local/sbin/felhom-os-apply 755:root
SAME /usr/local/sbin/felhom-crash-guard 755:root
SAME /etc/systemd/system/felhom-crash-guard.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.service 644:root
SAME /etc/systemd/system/felhom-crash-guard-check.timer 644:root
SAME /etc/felhom/crash-guard.conf 644:root
SAME /etc/systemd/system/felhom-agent.service 644:root
SAME /etc/systemd/system/felhom-agent-rollback.service 644:root
SAME /etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf 644:root
SAME /usr/local/sbin/felhom-mgmt-watchdog 755:root
SAME /etc/tmpfiles.d/felhom-privsep.conf 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.service 644:root
SAME /etc/systemd/system/felhom-mgmt-watchdog.timer 644:root
SAME /etc/systemd/system/felhom-sshd.service 644:root
SAME /etc/felhom-oob.nft 644:root
SAME /etc/systemd/system/felhom-oob-nft.service 644:root
SAME /etc/sudoers.d/felhom-op 440:root
SAME /etc/sudoers.d/felhom-agent 440:root
total 24
drwxr-xr-x 2 root root 4096 Oct 4 16:12 .
drwxr-xr-x 102 root root 4096 Oct 4 13:35 ..
-rw-r--r-- 1 root root 0 Jul 18 18:32 .bootstrap-done
-rw-r--r-- 1 root root 7 Jul 18 18:17 appliance-pairing-code
-rw-r--r-- 1 root root 456 Oct 4 16:12 crash-guard.conf
-rw-r--r-- 1 root root 131 Oct 4 16:12 operator-signers
-rw-r--r-- 1 root root 65 Oct 4 18:34 os-trust.json
felhom-agent 0.142.1
@@ -0,0 +1,16 @@
--- wrong sha (red):
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
STOP: the bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, not 0000000000000000000000000000000000000000000000000000000000000000 — nothing changed
rc=1
bdf60f5c79a84db7ebcfe1620fe832436caab831259308906eda08627aac7260 /usr/local/sbin/felhom-os-apply
--- right sha:
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
2/4 take felhom-os-apply out of the bundle and check it
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
4/4 self-check
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba /usr/local/sbin/felhom-os-apply
@@ -0,0 +1,9 @@
1/4 download https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/0.143.0/felhom-config-bundle.json
sha256 OK (8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba)
2/4 take felhom-os-apply out of the bundle and check it
felhom-os-apply sha256 4c0d5f073b00c96891e2a9d4a50f2374dec38bc8c8ef37578027b1b399611dba
3/4 install it (the previous copy is kept as /usr/local/sbin/felhom-os-apply.pre-bundle)
4/4 self-check
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
@@ -0,0 +1,29 @@
felhom-os-apply ok bundle-format=1 files=22
DONE. This box can now take signed config bundles. Nothing else was changed.
rc=0
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=10242c3b… durable_id=""
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
Oct 04 20:04:34 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:34.923+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=1e60311ec9cad857 op=agent_config_update key_id=felhom-op-1 nonce=10242c3bac90859807c1ab3dfd497a9a
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.002+02:00 level=ERROR msg="signedjobs: signed op execution FAILED (nonce spent — clearing)" job=1e60311ec9cad857 op=agent_config_update err="agent_config_update: the downloaded bundle's sha256 is 8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba, the signed job pins 111111111111111111111111111111111111111111111
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="audit: gate decision" class=agent_config_update host=demo-hp-bb76ea guest="" source=one_shot_job disposition=destructive allowed=true reason=signed key_id=felhom-op-1 nonce=eb8a8219… durable_id=""
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=INFO msg="gate decision" class=agent_config_update guest="" source=one_shot_job disposition=destructive allowed=true reason=signed
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.016+02:00 level=WARN msg="signedjobs: AUTHORIZED signed op — executing" job=fa3df5a93740111e op=agent_config_update key_id=felhom-op-1 nonce=eb8a8219c7ab393e6702dc8a34cc578f
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.032+02:00 level=INFO msg="osupdate: config bundle downloaded; handing it to the root wrapper" op=agent_config_update agent_version=0.143.0 sha256=8d7273cf5313ef62 duration_ms=15
Oct 04 20:04:35 demo-hp felhom-os-apply[496014]: os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0
Oct 04 20:04:35 demo-hp felhom-os-apply[496158]: os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE START agent=0.143.0 sha=8d7273cf5313ef62 authority=signed files=22 write=0 same=21 kept=1 skipped=0"
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: BUNDLE DONE agent=0.143.0 written=0 same=21 self-check=ok signers-created=False"
Oct 04 20:04:35 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:35.985+02:00 level=WARN msg="osupdate: config bundle INSTALLED" op=agent_config_update agent_version=0.143.0 bundle="{\"agent_version\": \"0.143.0\", \"authority\": \"signed\", \"kept\": [\"/etc/felhom/crash-guard.conf\"], \"prev_dir\": \"/var/lib/felhom-os-apply/bundle-prev/20261004T180435Z-before-0.143.0\", \"same\": 21, \"self_
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="osupdate: capability probe after the config bundle" ok=71 total=71 degraded=""
Oct 04 20:04:36 demo-hp felhom-agent[447632]: time=2026-10-04T20:04:36.907+02:00 level=WARN msg="signedjobs: signed op COMPLETED" job=fa3df5a93740111e op=agent_config_update
[exited with code 0]
{
"agent_version": "0.143.0",
"authority": "signed",
"bundle_sha256": "8d7273cf5313ef62b867cb6f831c631923a436452d6f90b8ff7f0771170396ba",
"files": {
"/etc/felhom-oob.nft": "2c2b9cca89a439ac44efd353f4ea1936b3609ca43491b4c1853483e8321f238f",
"/etc/felhom/crash-guard.conf": "9b9d305b421f81d223f2ccc4594e67d41618239779d983a2f72c191a8b3b65f7",
"/etc/sudoers.d/felhom-agent": "02df92d751f1780aecbf600b2632b2366fcedeb3601852ebfa98c700e95f4dfc",
-rw-r--r-- 1 root root 2754 Oct 4 20:04 /etc/felhom/config-bundle.json
@@ -0,0 +1,8 @@
RED no 7-day wait
RED unknown counted as behind
RED clock never clears
GREEN! alarm without a vouched bundle
RED cell never red
RED exact lookup falls back to the first file
unmutated: ok
RED alarm without a vouched bundle (test strengthened: a box WITH a bundle, nothing vouched)
@@ -0,0 +1,24 @@
RED R17 trust-path check removed -> test_a_bundle_that_changes_a_signer_is_refused
RED R16 table check removed -> test_a_path_outside_the_table_is_refused
RED bundle sha check removed -> test_wrong_sha_is_refused
RED per-file sha check removed -> test_content_not_matching_its_sha_is_refused
RED version pin removed -> test_version_mismatch_is_refused
RED visudo/sh/nft content check removed -> test_sudoers_failing_visudo_is_refused
RED python compile check removed -> test_python_syntax_error_is_refused
RED RuntimeDirectory guard removed -> test_unit_with_runtime_directory_is_refused
RED agent-unit User= check removed -> test_agent_unit_not_as_the_agent_user_is_refused
RED route-line pre-check removed -> test_sudoers_dropping_the_route_is_refused
RED wrapper bundle-mode pre-check removed -> test_wrapper_without_bundle_mode_is_refused
RED table re-ordering removed -> test_sudoers_is_written_after_every_wrapper
RED self-check sudo -l removed -> test_route_missing_after_install_puts_everything_back
RED undo removed -> test_route_missing_after_install_puts_everything_back
RED crash-guard kernel.panic self-check removed -> test_crash_guard_disagreeing_with_kernel_panic_puts_everything_back
RED nonce burn removed -> test_fresh_box_gets_every_file_and_a_record
RED nonce burned before the sha check -> test_wrong_sha_is_refused
RED pinned-key bootstrap removed (always the file) -> test_missing_signers_verifies_against_the_pinned_key_and_creates_it
RED signers written even when present -> test_present_signers_are_never_touched
RED SUDO_UID refusal removed -> test_installer_entry_is_refused_through_sudo
RED if-absent policy ignored -> test_tuned_crash_guard_conf_is_kept
RED oob policy ignored -> test_fresh_box_gets_every_file_and_a_record
unmutated: OK
ALL RED
@@ -0,0 +1,7 @@
RED approval never marked
RED a cancelled release is still served
RED cancels while the override is still on
RED superseded ones cancelled too
RED no backfill
RED ring-1 boxes not bumped
unmutated: ok
@@ -0,0 +1,41 @@
+ date -u +%FT%TZ
2026-10-04T17:19:25Z
+ docker ps -q --no-trunc
+ sort
+ wc -l
6
+ pidof dockerd
+ echo dockerd_pid=225
+ stat -c host_sock_inode=%i /var/run/docker.sock
dockerd_pid=225
host_sock_inode=144
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
felhom-controller sees: 144
+ echo felhom-controller sees: 144
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
traefik sees: 144
+ echo traefik sees: 144
+ systemctl restart docker
+ date -u +%FT%TZ
2026-10-04T17:19:31Z
+ sleep 5
+ pidof dockerd
dockerd_pid=66020
+ echo dockerd_pid=66020
+ stat -c host_sock_inode=%i /var/run/docker.sock
host_sock_inode=144
+ docker ps -q --no-trunc
+ sort
+ diff /tmp/ids.before /tmp/ids.after
IDS-SAME
+ echo IDS-SAME
+ docker exec felhom-controller sh -c stat -c %i /var/run/docker.sock
felhom-controller sees: 144
+ echo felhom-controller sees: 144
+ docker exec traefik sh -c stat -c %i /var/run/docker.sock
traefik sees: 144
+ echo traefik sees: 144
+ docker exec felhom-controller docker version --format {{.Server.Version}}
+ tail -1
controller->docker: 29.8.2
+ echo controller->docker: 29.8.2
@@ -0,0 +1,24 @@
After=network-online.target nss-lookup.target docker.socket firewalld.service containerd.service time-set.target
Wants=network-online.target containerd.service
Requires=docker.socket
ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
Restart=always
# specify ListenStream=/var/run/docker.sock instead.
ListenStream=/run/docker.sock
SocketMode=0660
== kill -9 dockerd
2026-10-04T17:19:52Z
dockerd_pid=66638
host_sock_inode=144
IDS-SAME
controller->docker: 29.8.2
== systemctl restart docker.socket
2026-10-04T17:20:00Z
active
active
dockerd_pid=67121
host_sock_inode=7202
IDS-SAME
felhom-controller sees: 144
traefik sees: 144
controller->docker: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
@@ -0,0 +1,30 @@
2026-10-04T17:22:27Z
felhom-controller Up 2 hours (healthy)
traefik Up 2 hours
(took 32ms)
2026/10/04 17:22:09 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 32ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
2026/10/04 17:22:09 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo starting (hddPath="/mnt/felhom-drives/scratch_hdd", hasCPUCollector=true)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readMemInfo: totalKB=30714356 availKB=25620992 → total=29994MB avail=25020MB used=4974MB (16.6%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/" bsize=4096 total=68.4GB used=5.6GB avail=59.2GB (8.3%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readDiskUsage: path="/mnt/felhom-drives/scratch_hdd" bsize=4096 total=937.8GB used=15.1GB avail=875.0GB (1.6%)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readLoadAvg: raw="0.50 0.90 0.74 5/1182 23856" → 1m=0.50 5m=0.90 15m=0.74
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readThermalZones: /sys — found 1 zones
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] readTemperature: found via hwmon at /sys — 52.9°C (hwmon1)
2026/10/04 17:22:19 info.go:13: [DEBUG] [system] GetInfo done in 47ms — mem=4974MB/29994MB (16.6%), rootDisk=5.6GB/68.4GB (8.3%), load=0.50/0.90/0.74, temp=52.9°C (hwmon1), cpu=2.8%
2026/10/04 17:22:19 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job ring-spill: execution starting
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job deadapp-check: execution starting
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job health-probes: execution starting
2026/10/04 17:22:19 healthprobe.go:110: [DEBUG] [stacks] RunHealthProbes: collected 0 targets (0 skipped not due, 0 skipped no container)
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: execution starting
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
2026/10/04 17:22:19 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
(took 24ms)
2026/10/04 17:22:19 scheduler.go:67: [DEBUG] [scheduler] job status-refresh: failed after 24ms: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit status 1
stderr: Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
2026/10/04 17:22:19 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1
dashboard=302
@@ -0,0 +1,5 @@
1502 /usr/local/bin/felhom-controller
2026-10-04T17:22:40Z
17:22:45 running 2026-10-04T17:22:41.057453139Z restarts=1
controller sees: 7202 host: 7202
controller->docker: 29.8.2
@@ -0,0 +1,5 @@
traefik before: 144
2026-10-04T17:22:38Z ERR Provider error, retrying in 8.088174175s error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
2026-10-04T17:22:46Z ERR Failed to retrieve information of the docker client and server host error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
2026-10-04T17:22:46Z ERR Provider error, retrying in 11.956516688s error="Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?" providerName=docker
traefik after: 7202
@@ -0,0 +1,10 @@
RED never-worked guard removed
RED timeouts counted as refusals
RED exit removed
RED window ignored (exit at first refusal)
RED a success does not reset
RED CheckUsers acts while blind
RED same-inode skip removed
RED self not skipped
RED ENOENT not a refusal
unmutated: ok
@@ -0,0 +1,41 @@
T0 17:50:17 systemctl restart docker.socket
host sock inode: 9108
+10s controller->docker=
BLIND traefik_inode=7202 host=9108
+16s controller->docker=
BLIND traefik_inode=7202 host=9108
+21s controller->docker=
BLIND traefik_inode=7202 host=9108
+26s controller->docker=
BLIND traefik_inode=7202 host=9108
+31s controller->docker=
BLIND traefik_inode=7202 host=9108
+36s controller->docker=
BLIND traefik_inode=7202 host=9108
+41s controller->docker=
BLIND traefik_inode=7202 host=9108
+47s controller->docker=
BLIND traefik_inode=7202 host=9108
+52s controller->docker=
BLIND traefik_inode=7202 host=9108
+57s controller->docker=
BLIND traefik_inode=7202 host=9108
+62s controller->docker=
BLIND traefik_inode=7202 host=9108
+67s controller->docker=
BLIND traefik_inode=7202 host=9108
+73s controller->docker=29.8.2 traefik_inode=7202 host=9108
+78s controller->docker=29.8.2 traefik_inode=7202 host=9108
+83s controller->docker=29.8.2 traefik_inode=7202 host=9108
+88s controller->docker=29.8.2 traefik_inode=7202 host=9108
+94s controller->docker=29.8.2 traefik_inode=7202 host=9108
+99s controller->docker=29.8.2 traefik_inode=7202 host=9108
+104s controller->docker=29.8.2 traefik_inode=9108 host=9108
HEALED
== containers before/after (name id)
== controller log
2026/10/04 17:50:29 sockheal.go:118: [WARN] [sockheal] Docker refuses the socket (dial unix /var/run/docker.sock: connect: connection refused) — exiting after 1m0s of refusals so Docker restarts this controller on the current socket (R-860)
2026/10/04 17:51:29 sockheal.go:123: [ERROR] [sockheal] Docker has refused the socket for 1m0s (dial unix /var/run/docker.sock: connect: connection refused) — the socket file was re-created and this container holds the old one; EXITING (code 75) so Docker's restart policy brings it back on the current socket (R-860)
2026/10/04 17:52:00 sockheal.go:155: [WARN] [sockheal] traefik holds an old docker socket (inode 7202, current 9108) — restarting it (R-860)
2026/10/04 17:52:01 sockheal.go:160: [INFO] [sockheal] traefik restarted onto the current docker socket
controller restarts=1 started=2026-10-04T17:51:30.005016139Z
@@ -0,0 +1,6 @@
[golden] approved guest release: the template already runs every approved version
[golden] first-night count vs the approved guest release: 0 (target 0)
rc=0
[golden] no approved guest release given ��� the template versions stay; first-night count vs an approved release: n/a
[golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 1
rc=0
@@ -0,0 +1,39 @@
Sun Oct 4 17:08:29 UTC 2026
# GET /configs/drill-r50/delete (preview)
{
"claim_present": true,
"cloudflare_manual": null,
"customer_id": "drill-r50",
"customer_name": "drill-r50",
"dr_recipe_present": true,
"has_config": true,
"host_count": 1,
"hosts": [
{
"host_id": "drill-r50-0a4f9a",
"online": false,
"status": "down"
}
],
"offsite_enabled": false,
"offsite_identifier": "",
"offsite_type": "",
"one_time_secret": false,
"online_host_present": false,
"pbs_tenancy_configured": true,
"pending_journal": null,
"residue": {
"app_log_tails": 0,
"app_telemetry": 185,
"appliance_registrations": 1,
"log_tail_requests": 0,
"notification_prefs": 0,
"reports": 185,
"selfbind_tokens": 0
},
"residue_total": 371,
"superseded_blobs": 0
}
# GET /hosts/drill-r50-0a4f9a/delete-impact
{"deletable":true,"escrow_present":false,"guests":1,"log_bundles":0,"pbs_secret_present":false,"recovery_present":true,"reports":222,"status":"down","wg_peer_bound":true}
# hub DB (read-only copy): wg peer 10.77.0.4 bound to drill-r50-0a4f9a; customer email empty (no mail can go out); dr_tier 0; host last report 2026-08-13 06:11:41Z, agent 0.129.0
@@ -0,0 +1,5 @@
HTTP/1.1 303 See Other
Location: /configs?flash=deleted
Date: Sun, 04 Oct 2026 17:08:35 GMT
Content-Length: 0
@@ -0,0 +1,7 @@
2026/10/04 19:08:30 [INFO] customer DELETE cascade started for drill-r50 (journal #22, 1 host(s))
2026/10/04 19:08:32 [INFO] delete drill-r50: host drill-r50-0a4f9a deleted (escrow DEMOTED to retained custody)
2026/10/04 19:08:33 [INFO] tenantsync: deprovision ok for drill-r50 (ns=drill-r50, existed=false)
2026/10/04 19:08:33 [INFO] reset drill-r50: PBS tenancy deprovisioned
2026/10/04 19:08:33 [INFO] [claim] reset to unclaimed for drill-r50 (customer RESET) — next onboarding mints a fresh code
2026/10/04 19:08:35 [INFO] delete drill-r50: residue purged (reports=185 app_telemetry=185 app_log_tails=0 log_tail_requests=0 notif_prefs=0 selfbind_tokens=0 appliance_registrations=1)
2026/10/04 19:08:35 [INFO] customer DELETE cascade COMPLETE for drill-r50 (journal #22) — full teardown
@@ -0,0 +1,6 @@
Sun Oct 4 17:08:46 UTC 2026
# /hosts after
0
# preview after
404 page not found
http=404