# Golden bake — 0.219.0 (2026-08-22) Baked in the drill VM on DooPlex per `documentation/runbooks/RUNBOOK-manual-build.md` §4.0/§4.1, carrying controller **v0.219.0** (R-356 — the off-site restore for the 40 apps with no data drive). | | | |---|---| | `GOLDEN_VERSION` | **0.219.0** | | `GOLDEN_SHA256` | **67b46f78f8ed9c7b1876265ab1bde9ec6798897898b1836acece9f3864a2aeb6** | | package | `https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.219.0/golden.tar.zst` | | size | 656 832 571 B | | controller image | `gitea.dooplex.hu/admin/felhom-controller:0.219.0` | | template | `debian-13-standard_13.6-1_amd64.tar.zst` (**listed fresh, not assumed** — `pveam available` re-run in this session; checksum verified on download) | | `build-golden.sh` | v3.0.0, from `felhom-agent` @ `40d857b52711` (clean tree, HEAD == origin/main) | | drill VM | `pve-manager/9.2.2`, reverted to `virgin` and **cold**-booted | | infra images baked (4) | `traefik:v3.6.7`, `cloudflare/cloudflared:2026.6.0`, `gtstef/filebrowser:1.3.3-stable`, `gitea.dooplex.hu/admin/felhom-samba:1.1.0` | | `MinAgent` | **0.129.0** (read from the controller CHANGELOG header — unchanged) | ## Pass markers — each checked, with the negative controls ``` docker OK (overlay2 : 1 -> " docker OK (overlay2; data-root /var/lib/docker)" including mount point : 2 -> rootfs ('/') and mp0 ('/var/lib/felhom') [there is no mp1] upload OK (HTTP 201) : 1 -> pre-delete returned HTTP 404 (404/204 expected) excluding : 0 <- negative control FATAL : 0 <- negative control ``` **The 404 pre-gate was itself controlled before it was believed.** A 404 can mean "absent" or "wrong URL". The same URL shape for **0.218.0 returned HTTP 200** in the same minute, so the 404 on 0.219.0 means absent. ## Verified by ROUND TRIP, not by the number the script printed The published object was downloaded again — **HTTP 200, 656 832 571 bytes** — and its sha256 recomputed: ``` downloaded : 67b46f78f8ed9c7b1876265ab1bde9ec6798897898b1836acece9f3864a2aeb6 bake printed: 67b46f78f8ed9c7b1876265ab1bde9ec6798897898b1836acece9f3864a2aeb6 MATCH ``` What a machine will receive is byte-identical to what was baked. ## Token hygiene The Gitea token was copied **file → file** (`scp`) and read by a runner script *inside* the VM, so it never crossed a shell or a unit property. Verified: `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F "$(cat /root/.gitea-token)"` → **0**, and that grep was **proved able to convict first** — the token was appended to a throwaway copy of the same output, grepped (**1**), and the copy shredded. **The leak grep on this committed log was controlled the same way**: `grep -c -F` on the committed `bake.log` → **0**; the token appended to a throwaway copy → **1**; copy shredded; only then was the **0** accepted. ## Teardown `pct destroy 9100 --purge` (both logical volumes removed, `pct list` empty afterwards); token, runner, build script and in-VM log `shred -u`'d **after** `bake.log` was copied out to this directory — all four confirmed absent; `poweroff`; waited for qemu to exit; `qemu-img snapshot -a virgin`. The revert was first attempted while qemu still held the image and **correctly refused** (`Failed to get "write" lock`) — that refusal is the runbook's own proof that no process holds the qcow2, so it was waited out rather than forced. ## NOT vouched The hub's Day-0 artifact manifest was **not** changed and the floor was **not** raised — both are the operator's decision, and the vouch is a **three-field** change: | field | value | |---|---| | `golden_version` | **0.219.0** | | `agent_version` | **0.130.0** (already published; must be ≥ `MinAgent`) | | `min_agent` | **0.129.0** | `golden_version` alone would ship this controller onto an agent older than it declares it needs.