Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
8.5 KiB
DOORSTEP — the first hour again, on the unpublished installer (2026-09-14)
Interventions a volunteer could not have made: 1 — I1 again, now with a different cause (R-505).
Ready for a volunteer: NO — because on customer tester-1 the dashboard link answers 503 from our
network: the box's tunnel connects but receives no routes. Everything the task changed held.
Evidence: evidence-doorstep-walk-1270-2026-09-14/ — screens-331/, screens-332/, box-logs-331/,
A1-power-cut-331.txt, A2-typo-331.txt, step10-remove-observe-331.txt, G15-live-332-iso1271.txt,
teardown-*.txt. Gate records: ../tests/iso-release-1.27.0-2026-09-14/,
../tests/iso-release-1.27.1-2026-09-14/. Yesterday's walk for comparison:
DRILL-fresh-install-0242-2026-09-14.md and its screens/.
0. Phase 0 — why the installer asked questions (named first, because the brief assumed otherwise)
The auto-install never engaged, by construction. The public 1.26.1 manifest (downloaded from
iso.felhom.eu) reads answer-file : NONE — no answer.toml, no auto-installer-mode.toml (release gate G1) and automated-entry : NOT PRESENT; build-felhom-iso.sh --release refuses a profile and skips
prepare-iso; grub/grub-release.cfg.tmpl explains why — SPIKE-universal-iso-1 measured that no udev
property separates an internal disk from a USB backup drive and that a two-disk filter silently wipes
one. The operator's 2026-07-31 ruling made the interactive installer the product. Offered an
install-time disk rule on 2026-09-14, the operator kept that ruling. The auto-installer has no local
chooser or stop page (its modes are a static answer from the image or a partition, or an HTTP answer
service), so "no English reaches a volunteer" cannot hold on the installer's own screens; the
Felhom-written text around them is Hungarian (G16) and the guide answers each screen.
1. What was built
| artifact | change | status |
|---|---|---|
| ISO 1.27.0 | felhom-bootstrap.sh masks pvebanner + writes Felhom /etc/issue at first boot; banner names the Tulajdonosi jelmondat |
built, gated, superseded — its proof install still showed the Proxmox block on the first boot |
| ISO 1.27.1 | the postinst does the mask (symlink) and the issue write at install time; issue text without ő/ű | built, gated PASS, proven live on VM 332, NOT PUBLISHED |
| hub v0.113.0 | hand-over sentence on customer create + Credentials; self-bind mail names the operator | deployed, rendered live on tester-1's page |
2. The disk rule, and what a volunteer sees in each case
The installer never picks a disk for you. It lists every disk with size and model; you choose the one the system goes on, and that disk is erased. Unplug the external backup drive during the install. If you do not know which internal disk is right, stop and call the operator.
| case | what the screen shows (measured) |
|---|---|
| one disk (VM 332, TUI and graphical) | TUI: Target harddisk: /dev/sda (QEMU HARDDISK) (64.00 GiB); graphical: „Please verify the installation target … All existing partitions and data will be lost." with Target Harddisk /dev/sda (64.00GiB, QEMU HARDDISK) |
| three disks (VM 331, TUI) | the same field pre-set to /dev/sda (200.00 GiB); opening it lists /dev/sda (200.00 GiB), /dev/sdb (50.00 GiB), /dev/sdc (50.00 GiB) (screen 331-s07); the installer does not ask "which one?" by itself — the guide's disk row covers it |
| nobody at the keyboard (VM 332) | the 15 s menu boots the graphical installer, which stops at the EULA and waits (screen 332-s02) — nothing installs unattended |
| zero disks | not exercised |
3. The walk, step by step
Customer tester-1 (operator's choice), domain enkicsifelhom.hu, tunnel token set, DR tier on,
no e-mail registered. VM 331 = ISO 1.27.0, three disks, TUI. VM 332 = ISO 1.27.1, one disk.
| # | step | result | time |
|---|---|---|---|
| 1 | installer | built from main, not downloaded (unpublished) |
— |
| 2 | install (331) | same English Proxmox screens as yesterday; host name felhom.enkicsifelhom.hu per the guide |
copy ≤ 3 m 21 s |
| 3a | first screen (331, 1.27.0) | Proxmox :8006 block still on top; Felhom text below with ő/ű dropped → fixed in 1.27.1 |
registered at hub +41 s |
| 3b | first screen (332, 1.27.1) | Felhom text only — „Felhom otthoni szerver · Ezen a gépen most nincs dolgod, és bejelentkezni sem kell." — then the pairing banner naming the Tulajdonosi jelmondat; identical after a proven reboot (boot 16:14:11Z > reboot 16:13:56Z, pvebanner masked, /etc/issue 0 × 8006) |
— |
| 3c | bind + claim (331) | operator bind (no link: no e-mail); hub claim code generated … but customer tester-1 has NO registered email (R-508); dashboard 503 via the tunnel → I1 (R-505, filed 16:07:59Z before acting); claim by LAN + box-printed code (H1) → 302 |
controller 0.242.0 at +2 m 31 s after bind |
| 4 | version | controller 0.242.0, agent 0.130.0 — the vouched set | — |
| 5 | deploy | BookStack 68 s, PrivateBin 22 s | — |
| 6 | use | BookStack: default login → changed (old refused, new accepted), book, Hungarian page, 256 KiB attachment, sha equal; PrivateBin: encrypted paste round trip, wrong key InvalidTag |
— |
| 7 | backup pages | same honest warnings; R-499's „(PBS)" sentence still present (not this task) | — |
| 8 | backup now | points move to 16:11:56Z; page „18:11 (most)" | 16 s |
| 9 | versions | installed == catalog for both; no update offered — skipped | — |
| 10 | remove PrivateBin (stop → remove, every box) | volume, container, backup dir, restore points gone; front door 404 | <1 s |
| 11 | restore BookStack after deleting its page | page + attachment byte-identical, finish message „2 adatkötet és az adatbázis visszaállítva" | healthy 36 s |
| 12 | status pages | launcher BookStack + Filebrowser; dashboard 4 running | — |
| A1 | power cut | same six image tags, agent 0.130.0, data byte-identical, hub controller_started only |
dashboard +123 s, BookStack +133 s |
| A2 | typo | „Hibás vagy lejárt kód" → right code accepted → 6th attempt „Túl sok próbálkozás — próbáld újra 15 perc múlva."; claim_lockout + operator mail |
— |
4. Harness substitutions (not interventions)
H1 no mailbox (and tester-1 has none) → operator bind, box-printed codes · H2 U.S. keyboard on 331/332-TUI
· H3 auto-reboot unticked, ISO detached · H4 TUI entry. H5 (new): the graphical installer did not take
Tab or mouse input from qm sendkey/mouse_move; Alt+N worked — the 1.27.1 graphical path was proven
to boot, wait at the EULA, show the one-disk target and reach the password screen, not to install
(R-507).
5. Findings
| row | rank | |
|---|---|---|
| R-505 | P1 | tester-1's tunnel gives a fresh box no routes → 503 (12/12 probes, 12 box warnings, 0 config updates); operator's phone reaches it — cause not visible to the session |
| R-508 | P2 | tester-1 has no registered e-mail: the setup code and self-bind link cannot be delivered |
| R-506 | P3 | day0-install.md A.1 says the controller manages hostnames — it does not |
| R-507 | P3 | the proof-install harness cannot drive the graphical installer |
| R-502 | P3 | the bootstrap harness runs in no gate/CI; the banner was never tested |
| R-503 | P3 | spike for an install-time disk rule (not chosen) |
| R-504 | P3 | iso.felhom.eu/ has no index; download page goes on the website |
Closed with this evidence: R-497 (hub v0.113.0 live). Fixed, awaiting publish: R-496 (ISO 1.27.1), R-495 (answered by the guide + G14). R-493 stays open until the download page and ISO are live.
6. Teardown
Layers 1–2 measured in teardown-layers-1-2.txt (VMs 331/332 destroyed; nvme-scratch used 23 528 192
→ 10 132 924 KiB; local 26 489 992 → 23 033 320 KiB; ISOs and /root/doorstep gone; 9201/9202 running;
local-lvm 44.17 % unchanged). Layer 3 in teardown-layer3-hub.txt: appliance 27 discarded; host
tester-1-8603a2 deleted at 16:46:52Z once stale; its ep0 peer gone at the 16:49:13Z push (customer
tester-1 is KEPT — the operator's fixture; a RESET or DELETE would remove its tunnel and zone). Left on
ep0 by the DR tier, measured read-only: namespace tester-1 with 2 directories of backup data and
token felhom@pbs!tester-1; a host delete does not deprovision tenancy — only the customer RESET does,
which would also remove the tunnel. Disposition: retained with the customer, for the operator to rule.