Files
felhom.eu/documentation/tests/golden-0.217.0-2026-08-21/README.md
T
admin 059adfb8b8
gates / gates (push) Successful in 14s
golden 0.217.0 baked and published — evidence, markers and the token-leak proof
GOLDEN_VERSION = 0.217.0
GOLDEN_SHA256  = 0276c5f638d140a861daba4ef25129896e259937eec0ae5cba7af42391315ad0
archive volid  = local:backup/vzdump-lxc-9100-2026_08_21-21_40_05.tar.zst
MinAgent       = 0.129.0 (unchanged from 0.216.0)

Acceptance markers counted in this run's own bake.log, not paraphrased:
  docker OK (overlay2       1
  including mount point     2   (rootfs and mp0 — there is no mp1)
  upload OK (HTTP 201)      1
  excluding                 0
  FATAL                     0
Published package fetched back over HTTPS: HTTP 200.

Token handling: copied file->file, read by a runner script inside the VM, never on a command
line. systemctl show of the live unit contained it 0 times. The committed bake.log greps 0 for
the literal token AND the grep was first PROVEN to work on that same file by appending the token
to a throwaway copy (grep = 1) then shredding it — a 0 from an untested grep is not evidence.

Evidence copied off the VM BEFORE teardown. Then destroy 9100 --purge, shred token+runner+script
+log inside the VM (0 left), poweroff, waited for qemu using `ps -eo comm` (never `pgrep -f`,
which self-matches), and reverted the drill VM to `virgin`.

This unblocks the golden-currency gate, which correctly refused the previous push of the register
rows: "controller v0.217.0 is released and NO golden carries it". No --no-verify was used.

NOT DONE: the vouch. It is operator-gated and is a THREE-field change; vouching golden_version
alone would ship this controller onto an agent older than it declares it needs.
2026-08-21 21:43:16 +02:00

57 lines
2.6 KiB
Markdown

# Golden bake 0.217.0 — 2026-08-21
Baked from controller image `gitea.dooplex.hu/admin/felhom-controller:0.217.0` (R-351/R-352) in the
drill VM on DooPlex, per `documentation/runbooks/RUNBOOK-manual-build.md` §4.0/§4.1.
```
GOLDEN_VERSION = 0.217.0
GOLDEN_SHA256 = 0276c5f638d140a861daba4ef25129896e259937eec0ae5cba7af42391315ad0
archive volid = local:backup/vzdump-lxc-9100-2026_08_21-21_40_05.tar.zst
template = debian-13-standard_13.6-1_amd64.tar.zst (listed fresh; the point release rots)
MinAgent = 0.129.0 (from the controller CHANGELOG header — unchanged from 0.216.0)
```
## Acceptance markers, each counted in this run's own `bake.log`
| Marker | Required | Got |
|---|---|---|
| `docker OK (overlay2` | ≥1 | **1** |
| `including mount point` (rootfs **and** mp0 — there is no mp1) | 2 | **2** |
| `upload OK (HTTP 201)` | ≥1 | **1** |
| `excluding` | 0 | **0** |
| `FATAL` | 0 | **0** |
```
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
```
Published package fetched back over HTTPS: `HTTP 200` at
`https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.217.0/golden.tar.zst`
(the filename is `golden.tar.zst`, **not** `felhom-golden-<VER>.tar.zst`).
## Secret handling
The Gitea token was copied **file → file** (`scp`) and read by a runner script **inside** the VM, so
it never crossed a shell or a command line on either side.
`systemctl show golden-bake -p Environment -p ExecStart | grep -c -F "$(cat /root/.gitea-token)"`
returned **0** while the unit was live.
**The committed `bake.log` was grepped for the literal token: 0 occurrences — and the grep was first
shown to work**, by appending the token to a throwaway copy of *this same file* (grep returned **1**),
then `shred -u`-ing the copy. A `0` from an untested grep is not evidence. Other secret shapes
(`RESTIC_PASSWORD`, `PRIVATE KEY`, `Authorization:`) also 0.
## Teardown
Evidence was copied off the VM **before** teardown, not after. Then: `pct destroy 9100 --purge`,
`shred -u` of token + runner + build script + log inside the VM (0 files left), `poweroff`, waited for
qemu to exit (checked with `ps -eo comm`, never `pgrep -f`, which self-matches), and
`qemu-img snapshot -a virgin` — confirmed back to the single `virgin` snapshot.
## NOT done here
**The vouch is a separate, operator-gated act and has not been performed.** It is a THREE-field
change (`golden_version` + `agent_version` + `min_agent`); vouching `golden_version` alone would ship
this controller onto an agent older than it declares it needs.