# Golden 0.294.0 — bake + publish + vouch, 2026-10-05 Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–5, in the drill VM on DooPlex. | | Previous (`../golden-0.293.0-2026-10-04/`) | This bake | |---|---|---| | `build-golden.sh` | v3.2.0 (sha256 `645b3b659cba…`) | same file, unchanged (sha256 `645b3b659cba…`; VM copy matched) | | Controller | `felhom-controller:0.293.0` | **`felhom-controller:0.294.0`** (MinAgent 0.131.0, unchanged) | | Docker engine | the operator-approved set `os-docker-20261004-142842` | same pinned set (still in force) | | Guest packages | template | template — `GOLDEN_GUEST_PKGS` EMPTY: no guest release is in force (the earliest real approval is after ~11:07 UTC today, `audits/night-2026-10-04/PREDICTION.md`) | ## Launch - Drill VM reverted to `virgin`, cold-booted per §4.0 (05:50:06 UTC); `pveversion` = `pve-manager/9.2.2`. - `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst` (the only `_amd64` debian-13 entry), downloaded, `checksum verified`. - `/root/bake-run.sh` in the VM reads the token from the file; launched as transient unit `golden-bake`. - Token copied file → file (`scp`). `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F ` = **0** (control with the token appended = **1**). ## Pass markers (from `bake.log`) ``` [golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie … docker-ce=5:29.8.2-1~debian.13~trixie … [golden] no approved guest release given - the template versions stay; first-night count vs an approved release: n/a [golden] pending Debian upgrades in the baked guest (what a FUTURE approval may bring): 49 docker OK (overlay2; data-root /var/lib/docker) live-restore: on INFO: including mount point rootfs ('/') in backup INFO: including mount point mp0 ('/var/lib/felhom') in backup [golden] pre-delete existing: HTTP 404 (404/204 expected) [golden] upload OK (HTTP 201) GOLDEN_VERSION=0.294.0 GOLDEN_SHA256=ff7a174ffe58360e4f655e5a48de17b6aa51c1521199ef3cddd81140ad79a405 ``` No `excluding` and no `FATAL` in the log. ## Round trip Anonymous GET of `…/generic/felhom-golden/0.294.0/golden.tar.zst`: HTTP 200, **648148917 bytes**, sha256 `ff7a174ffe58360e4f655e5a48de17b6aa51c1521199ef3cddd81140ad79a405` = the printed sha (`02-round-trip.txt`). ## Secrets Saved-log leak grep for the literal token: **0**; positive control (a throwaway copy with the token appended): **1**, copy shredded. ## Vouch (step 5) `POST /configuration/artifacts` (operator Basic auth, the form the Configuration page posts): agent **0.144.1** (sha256 `6ccd521d…`), golden **0.294.0** (sha256 `ff7a174f…`), `min_agent` **0.131.0**, wrapper sha empty (as before). → `303 /configuration?flash=artifacts_set`; hub log `Artifact manifest set: agent=0.144.1 golden=0.294.0 min_agent="0.131.0" wrapper_sha=false bundle_sha="e89a9ddf…"` (the agent's config bundle, resolved by the hub). The controller floor stays per customer (demo-hp, demo-felhom, tester-1 at 0.294.0); the global floor is unchanged, so Tester 2's controller does not move. ## Teardown `pct destroy 9100 --purge`; `shred -u` of the token, the runner script and the log in the VM (log copied off first); `poweroff`; qemu gone (`ps -eo comm | grep -c qemu-system-x86` = 0); `qemu-img snapshot -a virgin`. Host: nothing provisioned.