1fa3250aa3
scripts/iso/: a DooPlex pipeline (build-felhom-iso.sh + Dockerfile.assistant) that turns the official PVE ISO into a Felhom auto-install ISO whose first-boot stub installs a retry-forever felhom-bootstrap unit which unattended-fetches felhom-host-install.sh from the public felhom.eu/scripts channel and runs it until the host is enrolled + a guest provisioned. host-install is UNMODIFIED (invoked only). - build gates the answer on validate-answer OUTPUT text, never $? (spike S1 exit-0 trap) - stub is from-iso, fully-up, exactly-once; retry unit owns all network work (S8a) - retry-vs-resume encoded once: plain first, --resume when install state exists (v1.11.3) - secret-bearing (embeds the retrieval passphrase): supervised/single-use; env shredded on success Validated on VM 310: build gate + red-proof, disk-filter fail-safe, chain + retry, resume-decision, exactly-once, no-net retry+recovery. Terminal host-install rc-0 success operator-gated (drill customer needs the password-gated create-UI). scripts v1.16.0; ROADMAP R-21 -> in-progress. Detail in REPORT.md.
13 lines
528 B
Plaintext
13 lines
528 B
Plaintext
# Felhom ISO build profile — nested-canary (Scenario D: disk-filter fail-safe regression).
|
|
#
|
|
# A udev filter that matches NOTHING. Proves the pipeline preserves the spike-proven S5c semantics:
|
|
# the installer aborts (exit 1, "filter did not match any device") and touches NO disk — verified by
|
|
# a host-side canary sha256 that stays byte-identical. NOT for real installs.
|
|
|
|
FELHOM_FQDN="felhom-host.local"
|
|
|
|
FELHOM_DISK_SETUP='[disk-setup]
|
|
filesystem = "ext4"
|
|
filter-match = "all"
|
|
filter.ID_SERIAL_SHORT = "no-such-disk-zzz"'
|