[INFO] felhom-host-install v1.28.0 — mode=appliance customer=drill-r50 vmid=120 [STEP] 1/8 pre-flight [INFO] pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve) [INFO] node: drill-pve (auto) [INFO] agent config: /etc/felhom-agent/agent.json [INFO] agent: not installed yet — will be fetched + installed in step 5/8 [INFO] local-lvm free: ~75 GiB [WARN] local-lvm free ~75 GiB < hard min 120 GiB [INFO] free RAM: ~6310 MiB [INFO] existing guests on this host: 0 (pct+qm) [INFO] acl storage 'felhom-pbs' not present yet — expected: the PBS-DR tier creates it; the grant is pre-positioned deliberately [INFO] dnsmasq: already installed BEFORE Felhom — recorded; uninstall will not touch it [INFO] dnsmasq-base: already installed BEFORE Felhom — recorded; uninstall will leave it [INFO] hub reachable (https://hub.felhom.eu) [OK] customer 'drill-r50' exists + passphrase valid [INFO] golden (local): local:backup/vzdump-lxc-9100-2026_08_13-07_43_44.tar.zst [INFO] --skip-provision: agent install/config only, no guest will be provisioned [OK] pre-flight passed [STEP] 2/8 Proxmox API token [OK] token minted (secret captured, not logged) [OK] scoped ACL applied (Base@/, Guest@/pool/felhom + /vms/990000..990009, Store@[local local-lvm felhom-pbs]) [SKIP] old broad role FelhomAgent already absent [STEP] 3/8 compute volume grows [INFO] auto-computed from ~75 GiB free (ONE volume since R-165) [INFO] grows: rootfs +0G (->32G), data +46G (->70G, ONE volume) [STEP] 4/8 host enrollment (POST /host-enroll) [OK] host REUSED (idempotent — existing credential) [INFO] host_id: drill-r50-0a4f9a (api_key captured, not logged) [STEP] 4b/8 break-glass credential (root@pam console password → hub vault) [OK] root@pam password set + vaulted to the hub (retrieve via the operator /admin path; never logged here) [WARN] NOTE: the root@pam password just CHANGED — the old one now fails at the PVE web GUI (:8006). [WARN] Retrieve the new one at hub → host page (vaulted recovery credential). [STEP] 5/8 agent install (fetch + verify + install) [OK] apt repos aligned to no-subscription (already aligned; apt-get update OK) [WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged) [INFO] manifest: agent v0.129.0 (sha 53a54f0620afbd6d…), golden v0.214.0 [INFO] fetching agent binary v0.129.0 from Gitea … [OK] verified sha256 53a54f0620afbd6d… matches the hub manifest [OK] installed /usr/local/bin/felhom-agent (felhom-agent 0.129.0) [OK] created service user felhom-agent [OK] added felhom-agent to systemd-journal (unprivileged journal read for NAS verify) [OK] installed /usr/local/sbin/felhom-mkfs-guarded (0755, the guarded mkfs path) [OK] installed /usr/local/sbin/felhom-selfupdate-guarded (0755, the guarded A/B binary-swap path) [OK] installed /usr/local/sbin/felhom-pbs-apply (0755, the guarded PBS-DR apply path) [OK] installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path) [OK] installed /etc/sudoers.d/felhom-agent (0440, visudo-validated) [OK] installed /etc/systemd/system/felhom-agent.service + enabled (started in step 6 after config) [OK] installed self-update rollback unit + start-limit drop-in (auto-rollback armed) [OK] installed break-glass layers 1+2 (tmpfiles /run/sshd + agent-independent watchdog timer) [OK] installed OOB felhom-sshd instance + static belt (agent renders config + fills sets once oob.enabled) [STEP] 6/8 agent config + service [WARN] backup target: DEGRADED — no eligible second drive, so the whole-system backup stays on the SYSTEM drive. [WARN] It protects against file corruption but NOT against a disk failure. Attach a second drive and assign it in the dashboard. [INFO] island bridge vmbr9 already present — leaving it [INFO] R-50 island ON: local_api=169.254.253.1:8443 (vmbr9); guest net1=169.254.253.2/30; lan_resolver.host_ip=10.0.2.15 [INFO] node=drill-pve local_api=169.254.253.1:8443 tls_fp=C9:1F:AC:10:AE:62… [OK] wrote /etc/felhom-agent/agent.json (0600 felhom-agent) [OK] agent --selftest (read-only) passed [OK] felhom-agent service active (non-root felhom-agent reads the config OK) [STEP] 7/8 golden archive [INFO] local golden digest matches the manifest (3a40379cb00d98c6…) — this IS the vouched artifact [SKIP] using local golden: local:backup/vzdump-lxc-9100-2026_08_13-07_43_44.tar.zst [SKIP] provision (--skip-provision) — agent install/config verified only [STEP] verify (agent only) [INFO] binary: felhom-agent 0.129.0 [INFO] runs as: felhom-agent (want felhom-agent) [OK] service active [OK] --selftest=hub OK (a host-report reached the hub) [OK] Agent install SUCCESS — felhom-agent 0.129.0 as felhom-agent, host_id=drill-r50-0a4f9a customer=drill-r50