Files
felhom.eu/documentation/audits/evidence-r316-2026-08-13/F2-install.log
T

72 lines
4.7 KiB
Plaintext

[INFO] felhom-host-install v1.28.0 — mode=appliance customer=drill-r50 vmid=120
[STEP] 1/8 pre-flight
[INFO] pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve)
[INFO] node: drill-pve (auto)
[INFO] agent config: /etc/felhom-agent/agent.json
[INFO] agent: not installed yet — will be fetched + installed in step 5/8
[INFO] local-lvm free: ~75 GiB
[WARN] local-lvm free ~75 GiB < hard min 120 GiB
[INFO] free RAM: ~6220 MiB
[INFO] existing guests on this host: 0 (pct+qm)
[INFO] acl storage 'felhom-pbs' not present yet — expected: the PBS-DR tier creates it; the grant is pre-positioned deliberately
[INFO] dnsmasq: not present before Felhom — recorded; uninstall will remove it again if we install it
[INFO] hub reachable (https://hub.felhom.eu)
[OK] customer 'drill-r50' exists + passphrase valid
[INFO] golden (local): local:backup/vzdump-lxc-9100-2026_08_13-07_43_44.tar.zst
[INFO] --skip-provision: agent install/config only, no guest will be provisioned
[OK] pre-flight passed
[STEP] 2/8 Proxmox API token
[OK] token minted (secret captured, not logged)
[OK] scoped ACL applied (Base@/, Guest@/pool/felhom + /vms/990000..990009, Store@[local local-lvm felhom-pbs])
[SKIP] old broad role FelhomAgent already absent
[STEP] 3/8 compute volume grows
[INFO] auto-computed from ~75 GiB free (ONE volume since R-165)
[INFO] grows: rootfs +0G (->32G), data +46G (->70G, ONE volume)
[STEP] 4/8 host enrollment (POST /host-enroll)
[OK] host REUSED (idempotent — existing credential)
[INFO] host_id: drill-r50-0a4f9a (api_key captured, not logged)
[STEP] 4b/8 break-glass credential (root@pam console password → hub vault)
[OK] root@pam password set + vaulted to the hub (retrieve via the operator /admin path; never logged here)
[WARN] NOTE: the root@pam password just CHANGED — the old one now fails at the PVE web GUI (:8006).
[WARN] Retrieve the new one at hub → host page (vaulted recovery credential).
[STEP] 5/8 agent install (fetch + verify + install)
[OK] apt repos aligned to no-subscription (already aligned; apt-get update OK)
[WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
[INFO] manifest: agent v0.129.0 (sha 53a54f0620afbd6d…), golden v0.214.0
[INFO] fetching agent binary v0.129.0 from Gitea …
[OK] verified sha256 53a54f0620afbd6d… matches the hub manifest
[OK] installed /usr/local/bin/felhom-agent (felhom-agent 0.129.0)
[OK] created service user felhom-agent
[OK] added felhom-agent to systemd-journal (unprivileged journal read for NAS verify)
[OK] installed /usr/local/sbin/felhom-mkfs-guarded (0755, the guarded mkfs path)
[OK] installed /usr/local/sbin/felhom-selfupdate-guarded (0755, the guarded A/B binary-swap path)
[OK] installed /usr/local/sbin/felhom-pbs-apply (0755, the guarded PBS-DR apply path)
[OK] installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)
[OK] installed /etc/sudoers.d/felhom-agent (0440, visudo-validated)
[OK] installed /etc/systemd/system/felhom-agent.service + enabled (started in step 6 after config)
[OK] installed self-update rollback unit + start-limit drop-in (auto-rollback armed)
[OK] installed break-glass layers 1+2 (tmpfiles /run/sshd + agent-independent watchdog timer)
[OK] installed OOB felhom-sshd instance + static belt (agent renders config + fills sets once oob.enabled)
[STEP] 6/8 agent config + service
[WARN] backup target: DEGRADED — no eligible second drive, so the whole-system backup stays on the SYSTEM drive.
[WARN] It protects against file corruption but NOT against a disk failure. Attach a second drive and assign it in the dashboard.
[INFO] island bridge vmbr9 already present — leaving it
[INFO] R-50 island ON: local_api=169.254.253.1:8443 (vmbr9); guest net1=169.254.253.2/30; lan_resolver.host_ip=10.0.2.15
[INFO] node=drill-pve local_api=169.254.253.1:8443 tls_fp=C9:1F:AC:10:AE:62…
[OK] wrote /etc/felhom-agent/agent.json (0600 felhom-agent)
[OK] agent --selftest (read-only) passed
[OK] felhom-agent service active (non-root felhom-agent reads the config OK)
[STEP] 7/8 golden archive
[INFO] local golden digest matches the manifest (3a40379cb00d98c6…) — this IS the vouched artifact
[SKIP] using local golden: local:backup/vzdump-lxc-9100-2026_08_13-07_43_44.tar.zst
[SKIP] provision (--skip-provision) — agent install/config verified only
[STEP] verify (agent only)
[INFO] binary: felhom-agent 0.129.0
[INFO] runs as: felhom-agent (want felhom-agent)
[OK] service active
[OK] --selftest=hub OK (a host-report reached the hub)
[OK] Agent install SUCCESS — felhom-agent 0.129.0 as felhom-agent, host_id=drill-r50-0a4f9a customer=drill-r50