Files
felhom.eu/REPORT-doorstep-1271.md
T

6.4 KiB
Raw Blame History

REPORT — the doorstep: installer 1.27.1, hub 0.113.0, walked again (2026-09-14)

Supervised task. STOPPED before publishing, as required. Findings: documentation/audits/DOORSTEP-walk-1270-2026-09-14.md. A parallel session owns root REPORT.md; this is a topic sibling.

0. Claims in the brief that turned out wrong — named first

  1. "The ISO is built to install itself with no questions." Wrong for the public image. --release builds carry no answer file by construction (G1); the 1.26.1 manifest says answer-file: NONE and automated-entry: NOT PRESENT. The README's auto-install text describes the old operator-built images. Nothing "failed to engage".
  2. "The installer installs itself, in Hungarian" / "no English reaches a volunteer." Not achievable under the operator's ruling: offered an install-time disk rule, he kept the interactive installer. The Proxmox auto-installer has no local chooser or stop page; its screens stay English. Felhom's own text is Hungarian (G16).
  3. "Tester 1, fully configured." It has no e-mail (R-508) and its tunnel gives a new box no routes (R-505).
  4. "The hub could create the tunnel later" as the only gap in A.1. day0-install.md A.1 also claimed the controller creates the hostnames; it does not (R-506, corrected).
  5. "Host a Hungarian chooser; else a Hungarian stop." Not built — follows from 2.

1. Baselines (re-verified)

felhom.eu 8c7f882 at start · ISO 1.26.1 · host installer 1.28.0 (unchanged) · hub 0.112.0 · controller 0.242.0, golden 0.242.0. Highest row R-501.

2. Operator decisions taken in this task

when question answer
Phase 0 reverse to auto-install, or keep interactive? keep interactive
Phase 4 test domain for the walk? use customer tester-1
Phase 4 tunnel has no routes — add, or continue? "works for me on mobile network … pi-hole" — see §5

3. What shipped, and what did not

artifact commit state
hub v0.113.0 — hand-over sentence on create + Credentials; self-bind mail names the operator (R-497) 6fd8c87 code, 63f29c6 deploy LIVE — ArgoCD Synced, image 0.113.0, page renders it
ISO 1.27.0 — console fix at first boot 6fd8c87 built, gated, superseded (first boot still showed the Proxmox block)
ISO 1.27.1 — postinst masks pvebanner + writes /etc/issue 27e8ec8 built, gate PASS, proven live, NOT PUBLISHED · sha256 25637007d5a7120ff9faa6b5b7ead3e33c0a361ac2d67e9fd4e0ee77c034c053
release gate G14–G16; domain + installer rulings in 01-topology-and-trust.md and CONTEXT.md; guide + day-0 A.1/A.2 aligned 6fd8c87, this commit committed
download page felhom.eu/letoltes — not written to the website — the website publishes on push; it goes with the ISO after yes

Tests: hub passphrase_handover_test.go red first, full go test ./... green; bootstrap harness 55/55, eight R-496 checks and scenario PI red first; shellcheck clean; felhom.eu gates green on every push; CI jobs 583, 585 success.

4. The walk

Interventions: 1 — reaching the dashboard by LAN address (R-505, filed 16:07:59Z before acting). Everything else held: install on 3 disks and 1, first-boot console Felhom-only on 1.27.1 with a proven reboot, deploy, use, backup-now, removal, byte-identical restore, power cut on the same versions, typo and lockout. Harness substitutions H1–H5 in the findings doc §4.

5. The tunnel, measured — the one thing that stops a volunteer

12 requests from DooPlex through public DNS → 12 × 503; the box's cloudflared logged 12 No ingress rules were defined in the same window and 0 remote-config updates since connecting. The guest's own front door answers the name. The operator's phone loads the dashboard — not explained by anything the session can see; a second connector reached from another Cloudflare location is the likeliest cause and is not established. The Pi-hole is excluded for these probes (public DNS, Cloudflare ray ids).

6. STOP — for the operator

  • Intervention count: 1. By the rule set for this task, do not publish.
  • The disk rule: the installer never picks; it lists every disk with size and model and erases the one you choose; unplug the backup drive; call the operator if unsure. One disk, three disks and nobody at the keyboard were each seen (findings §2).
  • Gate: 1.27.1 PASS on every criterion runnable before publish (G1–G10, G13–G16); G11/G12 are publish-time; the graphical entry is proven only to its password screen (R-507).
  • Ready: NO — until the tester-1 tunnel answers from our network, and the record has an e-mail.
  • What publishing would do, on yes: upload 1.27.1 + .sha256 + manifest to the bucket, add the download page to the website, round-trip the checksum over https://iso.felhom.eu/, keep 1.26.1 online so rollback is one link change.

7. Rows

Opened R-502 … R-508 (7). Closed R-497. Fixed awaiting publish R-496; answered awaiting publish R-495; R-493 open; R-494 narrowed to P3. Register table rows 209 → 216.

8. Teardown

Layers 1–2 done (VMs 331/332 destroyed; ≈12.8 GiB back on nvme-scratch; both ISOs and /root/doorstep gone; 9201/9202 untouched). Layer 3: appliance 27 discarded (16:20Z); host tester-1-8603a2 stale at 16:46:43Z (a true host_stale operator mail), deleted 16:46:52Z (host deleted: tester-1-8603a2 (escrow deleted: false); host page 404, gone from /hosts); its ep0 WireGuard peer 10.77.0.5 removed at the 16:49:13Z push (0 left, control peer 1). Customer tester-1 KEPT (page 200). Left on ep0 by the DR tier, read-only check 16:51Z: namespace tester-1 exists with 2 directories inside — backup data from the test box, plus token felhom@pbs!tester-1. Not removed: ep0 is protected, and the only product path (customer RESET) would also remove the tunnel. Retained for the operator's ruling. The hub's event stream and three operator mails are append-only and stay.

9. Observations

  • iso-release-gate.md's "both entries" proof depends on a person for the graphical entry today (R-507).
  • The bootstrap harness is run by hand only (R-502); the pairing banner had never been exercised.
  • A closed row still lives in the open register (R-497) until the next compression sweep — the gates accept it.