Files
felhom.eu/documentation/tests/golden-0.292.0-2026-10-04-rebake/README.md
T
2026-10-04 17:39:28 +02:00

4.8 KiB
Raw Blame History

Golden 0.292.0 — RE-BAKE + re-publish, 2026-10-04

Procedure: documentation/runbooks/RUNBOOK-manual-build.md §4.0 and §4.1 steps 1–4, in the drill VM on DooPlex, repeating the launch recorded in ../golden-0.292.0-2026-10-04/ (the first 0.292.0 bake of the same day). Step 5 (vouching in the hub) and any floor change were not done here; they are the main session's / operator's act.

What changed, and why

First bake (../golden-0.292.0-2026-10-04/) This re-bake
build-golden.sh v3.0.0 (agent 2e2e8f56b843) v3.1.0 (agent 42af3ab9bcb4, sha256 fdd1d83a313d…, VM copy matched)
Docker engine newest stable set, unpinned pinned to the approved set via GOLDEN_DOCKER_PKGS
live-restore not set on, asserted fail-closed by the script (09 decision 87)
Controller felhom-controller:0.292.0 same (MinAgent 0.131.0, unchanged)

Why: a box made from this golden starts with Docker live-restore already on (so a Docker engine update restarts no app) and on the approved Docker engine set, instead of the newest stable one.

Replacing the existing version

felhom-golden/0.292.0 already existed (the first bake; anonymous GET before the re-bake: HTTP 200, 648187281 bytes, sha256 d6cf8b33ad58…). The documented procedure replaces it: build-golden.sh publishes delete-then-PUT on its own version only (script comment: "re-publishing the same version overwrites cleanly"; runbook §4.1 step 5: "the publish step's pre-delete targets only its own version"). No manual delete was done. Log: pre-delete existing: HTTP 204 then upload OK (HTTP 201).

Consequence for the hub: the version string is unchanged but the bytes and sha256 are new. Any hub record that still holds 0.292.0 / d6cf8b33… no longer matches the published package until it is re-vouched with the sha below.

Launch

  • Drill VM: reverted to virgin, cold-booted per §4.0; pveversion = pve-manager/9.2.2.
  • pveam update → update successful; template debian-13-standard_13.6-1_amd64.tar.zst (the only _amd64 debian-13 entry), downloaded, checksum verified.
  • Runner script /root/bake-run.sh in the VM (reads the token from the file, exports GOLDEN_DOCKER_PKGS with the six approved versions), launched as transient unit golden-bake.
  • Token copied file → file (scp). systemctl show golden-bake -p Environment -p ExecStart | grep -c -F <token> = 0 (control: same output with the token appended = 1).

Result

GOLDEN_VERSION=0.292.0
GOLDEN_SHA256=79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a

Pass markers (quoted verbatim from bake.log)

26:[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
73:  installed: containerd.io	2.3.6-1~debian.13~trixie
74:  installed: docker-buildx-plugin	0.37.1-1~debian.13~trixie
75:  installed: docker-ce	5:29.8.2-1~debian.13~trixie
76:  installed: docker-ce-cli	5:29.8.2-1~debian.13~trixie
77:  installed: docker-ce-rootless-extras	5:29.8.2-1~debian.13~trixie
78:  installed: docker-compose-plugin	5.6.0-1~debian.13~trixie
89:  docker OK (overlay2; data-root /var/lib/docker)
90:  live-restore: on
327:INFO: including mount point rootfs ('/') in backup
328:INFO: including mount point mp0 ('/var/lib/felhom') in backup
333:[golden]   pre-delete existing: HTTP 204 (404/204 expected)
334:[golden]   upload OK (HTTP 201)

grep -E 'excluding|FATAL' bake.log → no matches. Infra images baked (unchanged from the first bake): traefik:v3.7.13, cloudflare/cloudflared:2026.9.3, gtstef/filebrowser:1.5.6-stable, felhom-samba:1.1.0.

Token-leak grep

On the copy in this directory (the one committed): grep -c -F "$(cat ~/.gitea-token)" bake.log = 0. Positive control: a throwaway copy with the token appended → 1; the copy was shred -u'd.

Round trip

See 02-round-trip.txt: the published package downloaded anonymously (HTTP 200, 648975434 bytes) hashes to 79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a — matches GOLDEN_SHA256.

Teardown state

  • Log copied off the VM before teardown.
  • pct destroy 9100 --purge → rc 0 (both LVs removed); pct list empty; no 9100 LV left.
  • /root/.gitea-token, /root/bake-run.sh, /root/bake.log in the VM: shred -u, confirmed absent.
  • VM powered off; no qemu-system-x86 process remained.
  • qemu-img snapshot -a virgin drill.qcow2 → OK; snapshot list shows only virgin.
  • Hub, k3s, demo boxes, ep0, tester boxes, customer guests: not touched. No vouch, no floor change.
  • df -h: /mnt/5_hdd 37 %, / 53 % (before and after).