Files
felhom.eu/REPORT.md
T

48 lines
3.3 KiB
Markdown

# felhom.eu — task reports
> **Overwrite** this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in [hub/CHANGELOG.md](hub/CHANGELOG.md).
## F2 (hub checkers) + prevention (host-install leaf preservation) — hub v0.21.0 + install script
**Date:** 2026-06-29. Companions: felhom-controller **v0.91.0** (Part A controller), felhom-agent
**v0.46.0** (Part B.1). This repo carries **Part A (hub checkers, F2)** + **Part B.2 (install script)**.
### Part A — hub F2 (`internal/monitor/host_capability.go`, `host_staleness.go`), hub v0.21.0
A host already **degraded** (capability) or **stale/down** (staleness) when the hub (re)started was
seeded silently and **never alerted**. Fix: the constructors now seed only HEALTHY hosts; an unhealthy
host is left **unseeded** so the first `Check()` emits once (`emitTransition(…, "unknown", newState,
…)`). The dispatcher's 1 h operator cooldown dedups the re-emit across a hub bounce. Healthy first-obs
still silent.
- Tests: born-degraded **red-proof** (degraded at construction → unseeded → one
`agent_capability_degraded` on first Check, no dup next); the staleness test updated to F2 (born-stale
→ unseeded → one `host_stale`). Build/vet/test green.
- **Live:** deployed v0.21.0; startup logs confirm the change —
`Host capability checker initialized: 1 ok, 0 degraded (degraded left unseeded → first Check emits)`
and the staleness sibling likewise.
### Part B.2 — `scripts/felhom-host-install.sh` (prevention)
- **`--preserve-state-from DIR`:** before the first agent start, copy `local-api.{crt,key}` +
`local-tokens.log` into `/var/lib/felhom-agent`, chown `felhom-agent`, modes 644/600/600, and
**validate the leaf parses** (`openssl x509 -noout`, else refuse). Keeps the pinned fingerprint
**stable** across a reinstall — no controller re-bootstrap. Distinct from `--preserve-from` (config
merge only).
- **Populated-host guard:** if the state dir has **no** leaf AND the host already runs guests AND
neither `--preserve-state-from` nor `--allow-new-leaf` was given → **refuse** with a clear message
(converts the silent 2026-06-28 footgun into a hard stop). A plain re-run on an intact host (leaf
present) is unaffected. `bash -n` clean.
- **Live logic validation (isolated, non-destructive — full installer not run):** on felhom-pve with
real openssl/pct — preserve copies with correct modes and the **fingerprint is preserved** across the
copy (`60b5974d…` source == dest); an unparseable leaf is rejected; the guard returns REFUSE for
leaf-absent + guests-present; the live agent state dir was untouched.
### NOT yet run — Part B live reinstall (B.4) — **awaiting supervised**
A full `felhom-host-install.sh` reinstall on felhom-pve (with `--preserve-state-from` → preserved fp,
channel stays up; without it on the populated host → guard refuses) is the operator's supervised call.
The agent B.1 loud-regenerate and the preserve/guard logic are proven; only the end-to-end reinstall
is deferred.
### Testrun residual fixed
The full-stack testrun's guest reboot had left guest 9201's `bootstrap.json` a placeholder (redeploy
blocked); restored the real file from the R1 aside copy (customer.id=demo-felhom) → the bootstrap
redeploy path works again (controller 0.91.0 deployed through it).