Files
felhom.eu/documentation/audits/evidence-drill-retained-key-2026-08-12/B4-autodiscover-stale.log
T
admin 1d5f2b8bb6
gates / gates (push) Successful in 23s
DRILL: the retained key works, and the customer cannot reach it
Three verdicts, kept separate because collapsing them is how this assumption
survived a week.

(a) The material IS retained. host_escrow_superseded id 11 is the first retained
row in fleet history to carry identity_blob (572 B), byte-identical to the
pre-supersession row (sha256 a10032341c8584ed...).

(b) The retained material DOES open the old store. Unsealed with the old recovery
code it yielded a password byte-identical to the pre-change one, and restored
three planted files byte-identical from a store the box itself could no longer
open - including a Hungarian accented filename verified as raw bytes. Negative
control ran first and failed closed.

(c) The customer has NO route, and is misinformed. ListSupersededEscrow has zero
production callers; the recovery path selects FROM host_escrow. Asked with the
code that had just worked by hand, the product answered "the recovery code did
not open the sealed bundle". A valid code for retained history is reported as a
bad code - the R-224 class again. R-304, rank 1.

Both installer faults were watched happening first, so installer-v1.27.0 is now
published (tag + both webpage.yaml refs). Pre-fix: the box came up on controller
0.98.3 against a vouched 0.213.0, below the floor and below the version carrying
the recovery screen; and our own uninstall left dnsmasq on 0.0.0.0:53 so our own
next install refused. R-297 and R-300 CLOSED.

Also filed R-305 (the dnsmasq fix fires once per machine - the leftover returns
on the second reinstall, proven), R-306 (--preflight-only writes state it says it
does not), R-307 (a live abandon countdown on demo-felhom, firing 2026-08-24 -
operator decision), R-308 (stored controller password stale), R-309 (the day-0
runbook's publication claim has been false since R-110), R-310 (two edges).

Ceiling R-303 -> R-310. Capability map moved: the retention claim is now marked
operator-only. Phase A logs did not survive the intermediate revert; recorded.
2026-08-12 17:41:56 +02:00

115 lines
7.8 KiB
Plaintext

[INFO] felhom-host-install v1.27.0 — mode=appliance customer=drill-r50 vmid=120
[STEP] 1/8 pre-flight
[INFO] pve-manager/9.2.2/b9984c6d90a4bd80 (running kernel: 7.0.2-6-pve)
[INFO] node: drill-pve (auto)
[INFO] agent config: /etc/felhom-agent/agent.json
[INFO] agent (existing): felhom-agent 0.128.0
[INFO] local-lvm free: ~75 GiB
[WARN] local-lvm free ~75 GiB < hard min 120 GiB
[INFO] free RAM: ~6231 MiB
[INFO] existing guests on this host: 0 (pct+qm)
[INFO] archive storage 'local' present
[INFO] acl storage 'felhom-pbs' not present yet — expected: the PBS-DR tier creates it; the grant is pre-positioned deliberately
[INFO] dnsmasq: already installed BEFORE Felhom — recorded; uninstall will not touch it
[INFO] hub reachable (https://hub.felhom.eu)
[OK] customer 'drill-r50' exists + passphrase valid
[INFO] golden (local): local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst
[OK] pre-flight passed
[STEP] 2/8 Proxmox API token
[SKIP] pool felhom already exists
[INFO] user felhom-agent@pve exists
[INFO] existing agent config has a token — testing it (read-only --selftest)
[OK] existing token authenticates — REUSING (no rotation)
[INFO] role FelhomAgentBase exists — ensuring exact privileges
[INFO] role FelhomAgentGuest exists — ensuring exact privileges
[INFO] role FelhomAgentStore exists — ensuring exact privileges
[OK] scoped ACL applied (Base@/, Guest@/pool/felhom + /vms/990000..990009, Store@[local local-lvm felhom-pbs])
[SKIP] old broad role FelhomAgent already absent
[STEP] 3/8 compute volume grows
[INFO] auto-computed from ~75 GiB free (ONE volume since R-165)
[INFO] grows: rootfs +0G (->32G), data +46G (->70G, ONE volume)
[STEP] 4/8 host enrollment (POST /host-enroll)
[OK] host REUSED (idempotent — existing credential)
[INFO] host_id: drill-r50-0a4f9a (api_key captured, not logged)
[STEP] 4b/8 break-glass credential (root@pam console password → hub vault)
[SKIP] recovery credential already vaulted (use --rotate-recovery to regenerate)
[STEP] 5/8 agent install (fetch + verify + install)
[OK] apt repos aligned to no-subscription (already aligned; apt-get update OK)
[WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
[INFO] manifest: agent v0.128.0 (sha c6eba73bf9b9ad69…), golden v0.213.0
[SKIP] agent v0.128.0 already installed + service active — skipping binary install
[INFO] service user felhom-agent exists
[INFO] felhom-agent already in systemd-journal
[OK] installed /usr/local/sbin/felhom-mkfs-guarded (0755, the guarded mkfs path)
[OK] installed /usr/local/sbin/felhom-selfupdate-guarded (0755, the guarded A/B binary-swap path)
[OK] installed /usr/local/sbin/felhom-pbs-apply (0755, the guarded PBS-DR apply path)
[OK] installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)
[OK] installed /etc/sudoers.d/felhom-agent (0440, visudo-validated)
[OK] installed /etc/systemd/system/felhom-agent.service + enabled (started in step 6 after config)
[OK] installed self-update rollback unit + start-limit drop-in (auto-rollback armed)
[OK] installed break-glass layers 1+2 (tmpfiles /run/sshd + agent-independent watchdog timer)
[OK] installed OOB felhom-sshd instance + static belt (agent renders config + fills sets once oob.enabled)
[STEP] 6/8 agent config + service
[WARN] backup target: DEGRADED — no eligible second drive, so the whole-system backup stays on the SYSTEM drive.
[WARN] It protects against file corruption but NOT against a disk failure. Attach a second drive and assign it in the dashboard.
[INFO] island bridge vmbr9 already present — leaving it
[INFO] R-50 island ON: local_api=169.254.253.1:8443 (vmbr9); guest net1=169.254.253.2/30; lan_resolver.host_ip=10.0.2.15
[INFO] node=drill-pve local_api=169.254.253.1:8443 tls_fp=F7:CC:33:E6:CA:F5…
[OK] wrote /etc/felhom-agent/agent.json (0600 felhom-agent)
[OK] agent --selftest (read-only) passed
[OK] felhom-agent service active (non-root felhom-agent reads the config OK)
[STEP] 7/8 golden archive
[WARN] ignoring the local golden local:backup/vzdump-lxc-9100-2026_08_12-23_59_59.tar.zst — it is controller 0.98.3, but the vouched golden is 0.213.0
[WARN] fetching the vouched golden instead (this is what the manifest is for)
[WARN] no git credential in controller.yaml — fetching artifacts ANONYMOUSLY (they are world-readable; sha256 verification unchanged)
[INFO] fetching golden v0.213.0 from Gitea → /var/lib/vz/dump/vzdump-lxc-9100-2026_08_12-17_31_32.tar.zst
[OK] verified sha256 77429bfc7e39ffc8… matches the hub manifest
[OK] golden imported + verified: local:backup/vzdump-lxc-9100-2026_08_12-17_31_32.tar.zst
[STEP] 8/8 provision guest 120
[SKIP] pool felhom already exists
=== felhom-agent 0.128.0 selftest=provision (vmid=120 customer=drill-r50 hostname=drill-r50) ===
--- front half: bring-up (provision) local:backup/vzdump-lxc-9100-2026_08_12-17_31_32.tar.zst → vmid 120 ---
time=2026-08-12T17:32:57.812+02:00 level=INFO msg="bring-up: pool membership re-asserted" vmid=120 pool=felhom
[OK] front half: vmid 120 up (boot+running) in 1m10s; MAC=BC:24:11:D3:D7:8C
--- back half: mint per-guest token + populate bootstrap config mount ---
time=2026-08-12T17:33:03.626+02:00 level=INFO msg="provision: back-half complete" vmid=120 mount=mp9 guest_path=/etc/felhom-bootstrap endpoint=169.254.253.1:8443
[OK] back half: bootstrap mount mp9 → /etc/felhom-bootstrap on vmid 120 (host dir /var/lib/felhom-agent/guests/120/bootstrap)
local-api endpoint 169.254.253.1:8443 · leaf fp 0c7b12eec0ab8c4f8e879dba1af0f7203ef82aea92b023d543b7632b865ead58 · token: minted (not printed)
=== selftest=provision OK — guest 120 provisioned + bootstrap-mounted (KEPT) ===
next: reboot the guest → the golden's baked controller-bootstrap unit deploys the controller,
which PULLS its controller.yaml from the hub (retrieval passphrase) and merges in this local_api.
[OK] provision completed
[INFO] rebooting guest 120 so the baked controller-bootstrap unit picks up the mount
[STEP] verify
[OK] pct status: running
[OK] onboot: 1
mp0: local-lvm:vm-120-disk-1,mp=/var/lib/felhom,backup=1,size=70G
mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
rootfs: local-lvm:vm-120-disk-0,size=32G
[OK] pool: guest 120 is a member of felhom
[OK] acl: FelhomAgentBase@/ present (user+token)
[OK] acl: FelhomAgentGuest@/pool/felhom present (user+token)
[OK] acl: FelhomAgentStore@/storage/local present (user+token)
[OK] acl: FelhomAgentStore@/storage/local-lvm present (user+token)
[OK] acl: FelhomAgentStore@/storage/felhom-pbs present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990000 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990001 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990002 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990003 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990004 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990005 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990006 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990007 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990008 present (user+token)
[OK] acl: FelhomAgentGuest@/vms/990009 present (user+token)
[OK] authz signers: 2 (operator-signed self-update armed)
[OK] controller: Up 24 seconds (healthy) (after ~0s)
[INFO] controller image: gitea.dooplex.hu/admin/felhom-controller:0.213.0
[WARN] cloudflared not visible yet
[INFO] (confirm in the hub UI that host drill-r50-0a4f9a reports guest 120)
[OK] Day-0 provision SUCCESS — vmid=120 host_id=drill-r50-0a4f9a customer=drill-r50 golden=local:backup/vzdump-lxc-9100-2026_08_12-17_31_32.tar.zst
[INFO] root@pam was rotated + vaulted at step 4b — retrieve at hub → host page (the old GUI password no longer works).