# RUNBOOK — the config bundle: a box's root-owned files by a signed job (R-840) Design: `architecture/11-os-updates.md` §5.4.2. Decision 96 (`09` §3). Built 2026-10-04: agent v0.143.0, hub v0.133.0, installer 1.31.0. Evidence: `audits/r840-config-bundle-2026-10-04/`. ## What it is Every root-owned file the installer writes for the agent (both sudoers files, the five wrappers, the crash guard and its units, the agent and rollback units, the start-limit drop-in, the mgmt watchdog, the OOB belt's files) travels as ONE file, `felhom-config-bundle.json`, published beside the agent binary (`felhom-agent//`). A new box gets it from the installer; an installed box gets it by a signed `agent_config_update`. The box's own root-owned `felhom-os-apply` checks the signature, the sha, every path and every file before it writes anything, keeps the previous copies, self-checks, and puts everything back on a failure. **The trust root is never in a bundle.** `/etc/felhom/operator-signers` and `/etc/felhom/os-trust.json` decide who may sign; no bundle may add, remove or change them. A box that has no signers file gets exactly the installer's pinned key (`felhom-op-1`), and only through a job that key signed. Signer rotation is a separate act (`04` §3). ## Send a bundle to a box (CC or the operator, on DooPlex) 1. The bundle's sha: the release output (`release-agent.sh` prints `bundle :`), or the hub's Configuration page after vouching (the hub resolves it from the registry by exact name). 2. Sign and queue (key `felhom-op-1`; the hub key is Secret `felhom-system/report-api`, read into a file, never printed): ```bash felhom-opsign -op agent_config_update -host -key-id felhom-op-1 -key \ -agent-version -bundle-sha256 -ttl 45m -upload http://:8080 -hub-key "$(cat )" ``` 3. The agent takes it on its next job poll (measured 4–15 min). Positive observables in the box's journal: `os-apply: BUNDLE DONE agent= written= … self-check=ok`, then `capability probe after the config bundle ok=71 total=71`. The hub's System page "Root files" column shows the version. 4. **Undo** = send the previous release's bundle the same way. The previous copies also stay on the box in `/var/lib/felhom-os-apply/bundle-prev/