208d21d18f
gates / gates (push) Successful in 37s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
90 lines
4.8 KiB
Markdown
90 lines
4.8 KiB
Markdown
# Golden 0.292.0 — RE-BAKE + re-publish, 2026-10-04
|
||
|
||
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM
|
||
on DooPlex, repeating the launch recorded in `../golden-0.292.0-2026-10-04/` (the first 0.292.0 bake
|
||
of the same day). Step 5 (vouching in the hub) and any floor change were **not** done here; they are
|
||
the main session's / operator's act.
|
||
|
||
## What changed, and why
|
||
|
||
| | First bake (`../golden-0.292.0-2026-10-04/`) | This re-bake |
|
||
|---|---|---|
|
||
| `build-golden.sh` | v3.0.0 (agent `2e2e8f56b843`) | **v3.1.0** (agent `42af3ab9bcb4`, sha256 `fdd1d83a313d…`, VM copy matched) |
|
||
| Docker engine | newest stable set, unpinned | **pinned** to the approved set via `GOLDEN_DOCKER_PKGS` |
|
||
| `live-restore` | not set | **on**, asserted fail-closed by the script (`09` decision 87) |
|
||
| Controller | `felhom-controller:0.292.0` | same (MinAgent 0.131.0, unchanged) |
|
||
|
||
Why: a box made from this golden starts with Docker `live-restore` already on (so a Docker engine update
|
||
restarts no app) and on the approved Docker engine set, instead of the newest stable one.
|
||
|
||
## Replacing the existing version
|
||
|
||
`felhom-golden/0.292.0` already existed (the first bake; anonymous GET before the re-bake: HTTP 200,
|
||
648187281 bytes, sha256 `d6cf8b33ad58…`). The documented procedure replaces it: `build-golden.sh`
|
||
publishes **delete-then-PUT** on its own version only (script comment: "re-publishing the same version
|
||
overwrites cleanly"; runbook §4.1 step 5: "the publish step's pre-delete targets only its own
|
||
version"). No manual delete was done. Log: `pre-delete existing: HTTP 204` then `upload OK (HTTP 201)`.
|
||
|
||
**Consequence for the hub:** the version string is unchanged but the bytes and sha256 are new. Any hub
|
||
record that still holds `0.292.0 / d6cf8b33…` no longer matches the published package until it is
|
||
re-vouched with the sha below.
|
||
|
||
## Launch
|
||
|
||
- Drill VM: reverted to `virgin`, cold-booted per §4.0; `pveversion` = `pve-manager/9.2.2`.
|
||
- `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst` (the only
|
||
`_amd64` debian-13 entry), downloaded, checksum verified.
|
||
- Runner script `/root/bake-run.sh` in the VM (reads the token from the file, exports
|
||
`GOLDEN_DOCKER_PKGS` with the six approved versions), launched as transient unit `golden-bake`.
|
||
- Token copied file → file (`scp`). `systemctl show golden-bake -p Environment -p ExecStart |
|
||
grep -c -F <token>` = **0** (control: same output with the token appended = **1**).
|
||
|
||
## Result
|
||
|
||
```
|
||
GOLDEN_VERSION=0.292.0
|
||
GOLDEN_SHA256=79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a
|
||
```
|
||
|
||
## Pass markers (quoted verbatim from `bake.log`)
|
||
|
||
```
|
||
26:[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
|
||
73: installed: containerd.io 2.3.6-1~debian.13~trixie
|
||
74: installed: docker-buildx-plugin 0.37.1-1~debian.13~trixie
|
||
75: installed: docker-ce 5:29.8.2-1~debian.13~trixie
|
||
76: installed: docker-ce-cli 5:29.8.2-1~debian.13~trixie
|
||
77: installed: docker-ce-rootless-extras 5:29.8.2-1~debian.13~trixie
|
||
78: installed: docker-compose-plugin 5.6.0-1~debian.13~trixie
|
||
89: docker OK (overlay2; data-root /var/lib/docker)
|
||
90: live-restore: on
|
||
327:INFO: including mount point rootfs ('/') in backup
|
||
328:INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||
333:[golden] pre-delete existing: HTTP 204 (404/204 expected)
|
||
334:[golden] upload OK (HTTP 201)
|
||
```
|
||
|
||
`grep -E 'excluding|FATAL' bake.log` → no matches. Infra images baked (unchanged from the first
|
||
bake): traefik:v3.7.13, cloudflare/cloudflared:2026.9.3, gtstef/filebrowser:1.5.6-stable,
|
||
felhom-samba:1.1.0.
|
||
|
||
## Token-leak grep
|
||
|
||
On the copy in this directory (the one committed): `grep -c -F "$(cat ~/.gitea-token)" bake.log` = **0**.
|
||
Positive control: a throwaway copy with the token appended → **1**; the copy was `shred -u`'d.
|
||
|
||
## Round trip
|
||
|
||
See `02-round-trip.txt`: the published package downloaded anonymously (HTTP 200, 648975434 bytes)
|
||
hashes to `79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a` — **matches** GOLDEN_SHA256.
|
||
|
||
## Teardown state
|
||
|
||
- Log copied off the VM before teardown.
|
||
- `pct destroy 9100 --purge` → rc 0 (both LVs removed); `pct list` empty; no `9100` LV left.
|
||
- `/root/.gitea-token`, `/root/bake-run.sh`, `/root/bake.log` in the VM: `shred -u`, confirmed absent.
|
||
- VM powered off; no `qemu-system-x86` process remained.
|
||
- `qemu-img snapshot -a virgin drill.qcow2` → OK; snapshot list shows only `virgin`.
|
||
- Hub, k3s, demo boxes, ep0, tester boxes, customer guests: not touched. No vouch, no floor change.
|
||
- `df -h`: `/mnt/5_hdd` 37 %, `/` 53 % (before and after).
|