# Golden 0.289.1 bake (2026-10-03) Baked in the drill VM on DooPlex per `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4. Step 5 (vouching in the hub) was NOT done here. - Controller image: `gitea.dooplex.hu/admin/felhom-controller:0.289.1` - Build script: `felhom-agent/configs/build-golden.sh` v3.0.0 at agent `main` d766666 (clean tree, equal to origin/main); sha256 `e4c9ede772e777efacdbc6a2bfb3b15d181d2e96bb82b40cee557b5bbe068834`, identical on DooPlex and inside the VM. - Template: `debian-13-standard_13.6-1_amd64.tar.zst` (from `pveam available`, filtered on `_amd64`). - Drill VM: `pve-manager/9.2.2`. **GOLDEN_VERSION=0.289.1** **GOLDEN_SHA256=59fa7beadbb17fbcd30524c47e34806d3122f57fb8c5e2618727b6781e874512** Package: `https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.289.1/golden.tar.zst` (652929857 bytes). ## Pass markers, quoted from `bake.log` ``` 82: docker OK (overlay2; data-root /var/lib/docker) 313:INFO: including mount point rootfs ('/') in backup 314:INFO: including mount point mp0 ('/var/lib/felhom') in backup 319:[golden] pre-delete existing: HTTP 404 (404/204 expected) 320:[golden] upload OK (HTTP 201) ``` `grep -c -E 'excluding|FATAL' bake.log` = `0`. No `mp1` line (none expected since v3.0.0). ## Token handling - Token copied file → file (`scp`); the bake ran from a runner script inside the VM that reads the token itself (`systemd-run --unit=golden-bake --collect`). - `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F ` = `0`; positive control (same output with the token appended) = `1`. - Leak grep on THIS saved `bake.log` (the committed copy): `0`. Positive control (a throwaway copy with the token appended) = `1`; the copy was `shred -u`'d. ## Teardown state - `pct destroy 9100 --purge` — rc 0, both LVs removed. - `/root/.gitea-token`, `/root/bake-run.sh`, `/root/bake.log` in the VM — `shred -u`, confirmed absent. - VM powered off; qemu process gone (no `qemu-system-x86` in `ps`). - `qemu-img snapshot -a virgin drill.qcow2` — OK; snapshot `virgin` still listed. ## Deviations from the runbook - `pveam update` was run before `pveam available` (the virgin snapshot's template index is stale); the runbook's step 2 does not list it. - The published package was not re-downloaded to verify its sha256; the evidence is the script's `upload OK (HTTP 201)` and its printed `GOLDEN_SHA256`.