Golden 0.246.0 — baked, published and vouched 2026-09-17
Operator decision: vouch agent 0.132.0 for Day-0 installs. The hub's R-120 gate refused that while the vouched golden (0.245.0) was older than the fleet's newest controller (0.246.0), so the operator chose to bake golden 0.246.0 first (RUNBOOK-manual-build §4.0/§4.1).
GOLDEN_VERSION |
0.246.0 (controller image gitea.dooplex.hu/admin/felhom-controller:0.246.0) |
GOLDEN_SHA256 |
05b7559dd119a1d527b459730f6d500fa396f01fea9f863f3c317ad1e2bc4bd6 |
| template | debian-13-standard_13.6-1_amd64.tar.zst, container architecture amd64 |
| markers | overlay2 1 · mount points 2 · upload HTTP 201 1 · FATAL 0 · excluding 0 · publish skipped 0 |
| token leak | 0 in the committed log; planted control 1 |
| registry | …/generic/felhom-golden/0.246.0/golden.tar.zst → 200, and only then teardown |
| teardown | CT 9100 destroyed, token/runner/log shredded in the VM, qemu exited, disk reverted to virgin |
| vouched | Artifact manifest set: agent=0.132.0 golden=0.246.0 min_agent="0.131.0" wrapper_sha=true (10:24:20Z CEST log 12:24:20); read back: agent 4afe8157…, golden 05b7559d…, wrapper 104db0a4… unchanged |
Two mistakes of mine on the way, both recorded, neither reached the registry:
- Attempt 1 picked the arm64 template (
sort -Vranksarm64afteramd64); aborted at „installing Docker", nothing built or uploaded. While stopping it,pkill -fmatched my own command line and killed the stopping shell (exit 144) — the self-match recorded on chaos night, repeated. - Attempt 2's host-side watcher was killed by the system for low memory (as in the 0.244.0 bake). The bake
ran inside the VM and finished (
Result=success); the post-bake steps were done by hand in the runbook's order — log off first, then checks, then the registry gate, then teardown.
Files: bake.log (the build's own log), bake-record.txt, bake-attempt1-ARM64-ABORTED.txt, vouch.txt.