1d5f2b8bb6
gates / gates (push) Successful in 23s
Three verdicts, kept separate because collapsing them is how this assumption survived a week. (a) The material IS retained. host_escrow_superseded id 11 is the first retained row in fleet history to carry identity_blob (572 B), byte-identical to the pre-supersession row (sha256 a10032341c8584ed...). (b) The retained material DOES open the old store. Unsealed with the old recovery code it yielded a password byte-identical to the pre-change one, and restored three planted files byte-identical from a store the box itself could no longer open - including a Hungarian accented filename verified as raw bytes. Negative control ran first and failed closed. (c) The customer has NO route, and is misinformed. ListSupersededEscrow has zero production callers; the recovery path selects FROM host_escrow. Asked with the code that had just worked by hand, the product answered "the recovery code did not open the sealed bundle". A valid code for retained history is reported as a bad code - the R-224 class again. R-304, rank 1. Both installer faults were watched happening first, so installer-v1.27.0 is now published (tag + both webpage.yaml refs). Pre-fix: the box came up on controller 0.98.3 against a vouched 0.213.0, below the floor and below the version carrying the recovery screen; and our own uninstall left dnsmasq on 0.0.0.0:53 so our own next install refused. R-297 and R-300 CLOSED. Also filed R-305 (the dnsmasq fix fires once per machine - the leftover returns on the second reinstall, proven), R-306 (--preflight-only writes state it says it does not), R-307 (a live abandon countdown on demo-felhom, firing 2026-08-24 - operator decision), R-308 (stored controller password stale), R-309 (the day-0 runbook's publication claim has been false since R-110), R-310 (two edges). Ceiling R-303 -> R-310. Capability map moved: the retention claim is now marked operator-only. Phase A logs did not survive the intermediate revert; recorded.
116 lines
7.7 KiB
Plaintext
116 lines
7.7 KiB
Plaintext
|
|
[INFO] felhom-host-install v1.25.0 — mode=appliance customer=drill-r50 vmid=120
|
|
|
|
[STEP] 1/8 pre-flight
|
|
[INFO] pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve)
|
|
[INFO] node: drill-pve (auto)
|
|
[INFO] agent config: /etc/felhom-agent/agent.json
|
|
[INFO] agent: not installed yet — will be fetched + installed in step 5/8
|
|
[INFO] local-lvm free: ~75 GiB
|
|
[WARN] local-lvm free ~75 GiB < hard min 120 GiB
|
|
[INFO] free RAM: ~6305 MiB
|
|
[INFO] existing guests on this host: 0 (pct+qm)
|
|
[INFO] archive storage 'local' present
|
|
[INFO] acl storage 'felhom-pbs' not present yet — expected: the PBS-DR tier creates it; the grant is pre-positioned deliberately
|
|
[INFO] hub reachable (https://hub.felhom.eu)
|
|
[OK] customer 'drill-r50' exists + passphrase valid
|
|
[INFO] golden (local): local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst
|
|
[OK] pre-flight passed
|
|
[STEP] 2/8 Proxmox API token
|
|
[OK] token minted (secret captured, not logged)
|
|
[OK] scoped ACL applied (Base@/, Guest@/pool/felhom + /vms/990000..990009, Store@[local local-lvm felhom-pbs])
|
|
[SKIP] old broad role FelhomAgent already absent
|
|
[STEP] 3/8 compute volume grows
|
|
[INFO] auto-computed from ~75 GiB free (ONE volume since R-165)
|
|
[INFO] grows: rootfs +0G (->32G), data +46G (->70G, ONE volume)
|
|
[STEP] 4/8 host enrollment (POST /host-enroll)
|
|
[OK] host REUSED (idempotent — existing credential)
|
|
[INFO] host_id: drill-r50-0a4f9a (api_key captured, not logged)
|
|
[STEP] 4b/8 break-glass credential (root@pam console password → hub vault)
|
|
[OK] root@pam password set + vaulted to the hub (retrieve via the operator /admin path; never logged here)
|
|
[WARN] NOTE: the root@pam password just CHANGED — the old one now fails at the PVE web GUI (:8006).
|
|
[WARN] Retrieve the new one at hub → host page (vaulted recovery credential).
|
|
[STEP] 5/8 agent install (fetch + verify + install)
|
|
[INFO] disabled pve-enterprise.sources (Enabled: no)
|
|
[INFO] disabled ceph.sources (Enabled: no)
|
|
[INFO] added pve-no-subscription.sources (suite=trixie)
|
|
[OK] apt repos aligned to no-subscription (changed; apt-get update OK)
|
|
[WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
|
|
[INFO] manifest: agent v0.128.0 (sha c6eba73bf9b9ad69…), golden v0.213.0
|
|
[INFO] fetching agent binary v0.128.0 from Gitea …
|
|
[OK] verified sha256 c6eba73bf9b9ad69… matches the hub manifest
|
|
[OK] installed /usr/local/bin/felhom-agent (felhom-agent 0.128.0)
|
|
[INFO] installing the 'sudo' package (required for the non-root agent model) …
|
|
[OK] sudo installed (Sudo version 1.9.16p2)
|
|
[INFO] installing the 'age' package (escrow ceremony identity-wrap dependency) …
|
|
[OK] age installed (1.2.1)
|
|
[OK] created service user felhom-agent
|
|
[OK] added felhom-agent to systemd-journal (unprivileged journal read for NAS verify)
|
|
[OK] installed /usr/local/sbin/felhom-mkfs-guarded (0755, the guarded mkfs path)
|
|
[OK] installed /usr/local/sbin/felhom-selfupdate-guarded (0755, the guarded A/B binary-swap path)
|
|
[OK] installed /usr/local/sbin/felhom-pbs-apply (0755, the guarded PBS-DR apply path)
|
|
[OK] installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)
|
|
[OK] installed /etc/sudoers.d/felhom-agent (0440, visudo-validated)
|
|
[OK] installed /etc/systemd/system/felhom-agent.service + enabled (started in step 6 after config)
|
|
[OK] installed self-update rollback unit + start-limit drop-in (auto-rollback armed)
|
|
[OK] installed break-glass layers 1+2 (tmpfiles /run/sshd + agent-independent watchdog timer)
|
|
[OK] installed OOB felhom-sshd instance + static belt (agent renders config + fills sets once oob.enabled)
|
|
[STEP] 6/8 agent config + service
|
|
[WARN] backup target: DEGRADED — no eligible second drive, so the whole-system backup stays on the SYSTEM drive.
|
|
[WARN] It protects against file corruption but NOT against a disk failure. Attach a second drive and assign it in the dashboard.
|
|
[INFO] creating island bridge vmbr9 (portless, 169.254.253.1/30)
|
|
[OK] vmbr9 up: 169.254.253.1/30
|
|
[INFO] R-50 island ON: local_api=169.254.253.1:8443 (vmbr9); guest net1=169.254.253.2/30; lan_resolver.host_ip=10.0.2.15
|
|
[INFO] node=drill-pve local_api=169.254.253.1:8443 tls_fp=F7:CC:33:E6:CA:F5…
|
|
[OK] wrote /etc/felhom-agent/agent.json (0600 felhom-agent)
|
|
[OK] agent --selftest (read-only) passed
|
|
[OK] felhom-agent service active (non-root felhom-agent reads the config OK)
|
|
[STEP] 7/8 golden archive
|
|
[SKIP] using local golden: local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst
|
|
[STEP] 8/8 provision guest 120
|
|
[SKIP] pool felhom already exists
|
|
=== felhom-agent 0.128.0 selftest=provision (vmid=120 customer=drill-r50 hostname=drill-r50) ===
|
|
--- front half: bring-up (provision) local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst → vmid 120 ---
|
|
time=2026-08-12T17:18:55.237+02:00 level=INFO msg="bring-up: pool membership re-asserted" vmid=120 pool=felhom
|
|
[OK] front half: vmid 120 up (boot+running) in 1m20s; MAC=BC:24:11:6A:90:26
|
|
--- back half: mint per-guest token + populate bootstrap config mount ---
|
|
time=2026-08-12T17:19:01.173+02:00 level=INFO msg="provision: back-half complete" vmid=120 mount=mp9 guest_path=/etc/felhom-bootstrap endpoint=169.254.253.1:8443
|
|
[OK] back half: bootstrap mount mp9 → /etc/felhom-bootstrap on vmid 120 (host dir /var/lib/felhom-agent/guests/120/bootstrap)
|
|
local-api endpoint 169.254.253.1:8443 · leaf fp e4cba31879281d094ea2ab492e412a9aa380854b99fd5792134658f7f0971dc5 · token: minted (not printed)
|
|
=== selftest=provision OK — guest 120 provisioned + bootstrap-mounted (KEPT) ===
|
|
next: reboot the guest → the golden's baked controller-bootstrap unit deploys the controller,
|
|
which PULLS its controller.yaml from the hub (retrieval passphrase) and merges in this local_api.
|
|
[OK] provision completed
|
|
[INFO] rebooting guest 120 so the baked controller-bootstrap unit picks up the mount
|
|
[STEP] verify
|
|
[OK] pct status: running
|
|
[OK] onboot: 1
|
|
mp0: local-lvm:vm-120-disk-1,mp=/var/lib/docker,backup=1,size=62G
|
|
mp1: local-lvm:vm-120-disk-2,mp=/mnt/sys_drive,backup=1,size=8G
|
|
mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
|
|
rootfs: local-lvm:vm-120-disk-0,size=32G
|
|
[OK] pool: guest 120 is a member of felhom
|
|
[OK] acl: FelhomAgentBase@/ present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/pool/felhom present (user+token)
|
|
[OK] acl: FelhomAgentStore@/storage/local present (user+token)
|
|
[OK] acl: FelhomAgentStore@/storage/local-lvm present (user+token)
|
|
[OK] acl: FelhomAgentStore@/storage/felhom-pbs present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990000 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990001 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990002 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990003 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990004 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990005 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990006 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990007 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990008 present (user+token)
|
|
[OK] acl: FelhomAgentGuest@/vms/990009 present (user+token)
|
|
[OK] authz signers: 2 (operator-signed self-update armed)
|
|
[OK] controller: Up 22 seconds (healthy) (after ~0s)
|
|
[INFO] controller image: gitea.dooplex.hu/admin/felhom-controller:0.98.3
|
|
[WARN] cloudflared not visible yet
|
|
[INFO] (confirm in the hub UI that host drill-r50-0a4f9a reports guest 120)
|
|
|
|
[OK] Day-0 provision SUCCESS — vmid=120 host_id=drill-r50-0a4f9a customer=drill-r50 golden=local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst
|
|
[INFO] root@pam was rotated + vaulted at step 4b — retrieve at hub → host page (the old GUI password no longer works).
|