Files
felhom.eu/REPORT.md
T

79 lines
5.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# felhom.eu — task reports
> **Overwrite** this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in [hub/CHANGELOG.md](hub/CHANGELOG.md); the scripts history lives in [scripts/CHANGELOG.md](scripts/CHANGELOG.md).
---
# REPORT — Golden rebuild 0.98.3 (drill B5 + B1) — docs half (2026-07-03)
Implementation half in `felhom-agent/REPORT.md` (build-golden.sh v2.0.0 @ `ceca355`). Full drill
evidence: **`documentation/audits/DRILL-golden-098-2026-07-03.md`** (AD transcripts, unit states,
resolution-order + fetch/sha proofs, cleanup, observations). This repo's changes are docs-only.
## Baselines
| Repo | Base → head |
|---|---|
| felhom.eu | `2e33a8b` → this push (docs) |
| felhom-agent | `c9f963d``ceca355` (script + CHANGELOG) |
| felhom-controller | untouched; **0.98.3** reconfirmed current + pullable, and is the baked tag |
## What shipped (system-level)
- **Golden 0.98.3** — bakes controller 0.98.3 + the `felhom-controller-bootstrap.path` unit;
published to Gitea (`felhom-golden/0.98.3/golden.tar.zst`, HTTP 201, round-trip sha
`b9a02ef1b6f02b9b58babc4c6aad9cf6c053ebdfba116c78c8e7830de757fd01`) and **operator-vouched** in
the Day-0 manifest (now: agent 0.63.0 + golden 0.98.3 — verified via `/api/v1/artifacts`).
- **B5 dead:** clean-room Day-0 install (Scenario C, local golden; Scenario D, vouched Gitea
fetch + sha verify) lands controller **0.98.3 on first boot**; `selfupdate/check` reports
up-to-date → the box self-manages; agent selftest clean; bentopdf deploys + answers 200.
- **B1 dead:** isolated proof — service condition-failed + path `active (waiting)` on a mount-less
boot; `pct set -mp9 …` against the RUNNING guest started the controller in ~1 s, no reboot
(`uptime -s` unchanged). Installer v1.9.1 reboot retained as belt (removal = recorded cleanup).
## Docs changed (this repo)
- `documentation/runbooks/day0-install.md`**D.1b retired** to a one-line `selfupdate/check`
verification; old procedure → Part F troubleshooting row keyed on "golden older than 0.86.0";
header versions line (script v1.9.1 / agent v0.63.0 / golden v0.98.3); A.3 drilled-known-good
pair + vouch-≥0.98.3 note; A.4 floor text rewritten + raise-floor recommendation.
- `documentation/audits/DRILL-day0-cleanroom-2026-07-03.md` — ledger **B1, B5 → FIXED**; R6
belt-note.
- `documentation/backlog/FOLLOWUP-golden-default-controller-tag.md` + `backlog/README.md`
**RESOLVED** (M18/M19 convention: file kept + annotated, README entry marked FIXED; the note's
`:0.43.0` numbers were history — the live default had already rotted to `:0.85.1`, which is the
form of the problem the mandatory arg kills).
- NEW `documentation/audits/DRILL-golden-098-2026-07-03.md` — the evidence doc.
## Key proofs (short form; transcripts in the evidence doc)
| Gate | Evidence |
|---|---|
| B5 red-proof | no-arg `build-golden.sh` dies with usage, exit 1, before any `pct` op (run on Windows + in the drill VM) |
| Scenario A | `[golden] build-golden.sh v2.0.0 — baking controller …0.98.3`; vzdump log: mp0 AND mp1 **included**; guest 9100 destroyed |
| Scenario B | before: `ConditionPathExists … not met` + path `active (waiting)`; after mp9 hot-plug: service SUCCESS @ +1 s, container `Up (healthy)` 0.98.3, boot time unchanged |
| Scenario C | `[SKIP] using local golden: …18_01_21.tar.zst` (resolution order); first boot 0.98.3; `update_available:false`; hub rows agent 0.63.0 / controller 0.98.3; bentopdf 200 |
| Publish | pre-delete 404 → PUT **201** → round-trip GET sha **matches** |
| Scenario D | `fetching golden v0.98.3 from Gitea``verified sha256 b9a02ef1… matches the hub manifest` → SUCCESS; first boot 0.98.3; up-to-date |
| Cleanup | all 8 drill-1 hub tables at count **0**, demo-felhom + peti-felhom intact; drill VM reverted to `virgin` (kept); bake cred file removed |
Secrets: registry read-cred via 0600 env file only; the bake script's in-guest
`docker logout + rm /root/.docker/config.json` line is present and ran before archiving; publish
used the build server's out-of-band Gitea admin credential; nothing committed.
## Observations / operator follow-ups
1. **SECURITY:** the customer-config `git.token` (held by every customer box) is a Gitea **admin**
token with **package-WRITE** — the bake proved it by successfully publishing with it. The
manifest-sha chain protects installs from tampered artifacts, but the capability shouldn't exist
customer-side: issue a scoped read-only account/token + rotate.
2. `build-golden.sh`'s publish block auto-fires whenever `REGISTRY_*` is set (needed for the pull
too) → it published BEFORE Scenario C; deleted (204) and re-published after the gate. Candidate
cleanup: a `GOLDEN_PUBLISH=1` opt-in flag.
3. The installer's post-provision reboot is now redundant (path unit wins first) — candidate
removal in a future installer version; kept per the task rules.
4. Recommended: raise the global controller floor to 0.98.3 (UI, 1 min) for drift protection.
5. Drill-environment note: launching the drill VM with `dhcpstart=10.0.2.30` (+ explicit
`hostfwd…-10.0.2.15:22`) eliminates the prior drill's slirp DHCP/IP-collision quirk — worth
using in every future drill.