c322bac21a
§5: add the standing note that a host's root@pam may be pinned to a known operator-chosen password instead of the random day-0 one — set via chpasswd + re-vault (PUT /hosts/<id>/recovery-credential, host api_key), guarded by the break_glass state marker so plain installer re-runs skip it. Caveats: never --rotate-recovery such a host; a full from-scratch reinstall wipes state.json and re-randomizes (re-run the set-and-vault). Captures why demo-felhom-01's root@pam "kept changing" until it was pinned 2026-07-12. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017CDMFpFx84pfviCTVuGGhf