Files
felhom.eu/documentation/tests/golden-0.292.0-2026-10-04-rebake/README.md
T
2026-10-04 17:39:28 +02:00

90 lines
4.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Golden 0.292.0 — RE-BAKE + re-publish, 2026-10-04
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM
on DooPlex, repeating the launch recorded in `../golden-0.292.0-2026-10-04/` (the first 0.292.0 bake
of the same day). Step 5 (vouching in the hub) and any floor change were **not** done here; they are
the main session's / operator's act.
## What changed, and why
| | First bake (`../golden-0.292.0-2026-10-04/`) | This re-bake |
|---|---|---|
| `build-golden.sh` | v3.0.0 (agent `2e2e8f56b843`) | **v3.1.0** (agent `42af3ab9bcb4`, sha256 `fdd1d83a313d…`, VM copy matched) |
| Docker engine | newest stable set, unpinned | **pinned** to the approved set via `GOLDEN_DOCKER_PKGS` |
| `live-restore` | not set | **on**, asserted fail-closed by the script (`09` decision 87) |
| Controller | `felhom-controller:0.292.0` | same (MinAgent 0.131.0, unchanged) |
Why: a box made from this golden starts with Docker `live-restore` already on (so a Docker engine update
restarts no app) and on the approved Docker engine set, instead of the newest stable one.
## Replacing the existing version
`felhom-golden/0.292.0` already existed (the first bake; anonymous GET before the re-bake: HTTP 200,
648187281 bytes, sha256 `d6cf8b33ad58…`). The documented procedure replaces it: `build-golden.sh`
publishes **delete-then-PUT** on its own version only (script comment: "re-publishing the same version
overwrites cleanly"; runbook §4.1 step 5: "the publish step's pre-delete targets only its own
version"). No manual delete was done. Log: `pre-delete existing: HTTP 204` then `upload OK (HTTP 201)`.
**Consequence for the hub:** the version string is unchanged but the bytes and sha256 are new. Any hub
record that still holds `0.292.0 / d6cf8b33…` no longer matches the published package until it is
re-vouched with the sha below.
## Launch
- Drill VM: reverted to `virgin`, cold-booted per §4.0; `pveversion` = `pve-manager/9.2.2`.
- `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst` (the only
`_amd64` debian-13 entry), downloaded, checksum verified.
- Runner script `/root/bake-run.sh` in the VM (reads the token from the file, exports
`GOLDEN_DOCKER_PKGS` with the six approved versions), launched as transient unit `golden-bake`.
- Token copied file → file (`scp`). `systemctl show golden-bake -p Environment -p ExecStart |
grep -c -F <token>` = **0** (control: same output with the token appended = **1**).
## Result
```
GOLDEN_VERSION=0.292.0
GOLDEN_SHA256=79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a
```
## Pass markers (quoted verbatim from `bake.log`)
```
26:[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie docker-buildx-plugin=0.37.1-1~debian.13~trixie docker-ce=5:29.8.2-1~debian.13~trixie docker-ce-cli=5:29.8.2-1~debian.13~trixie docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie docker-compose-plugin=5.6.0-1~debian.13~trixie
73: installed: containerd.io 2.3.6-1~debian.13~trixie
74: installed: docker-buildx-plugin 0.37.1-1~debian.13~trixie
75: installed: docker-ce 5:29.8.2-1~debian.13~trixie
76: installed: docker-ce-cli 5:29.8.2-1~debian.13~trixie
77: installed: docker-ce-rootless-extras 5:29.8.2-1~debian.13~trixie
78: installed: docker-compose-plugin 5.6.0-1~debian.13~trixie
89: docker OK (overlay2; data-root /var/lib/docker)
90: live-restore: on
327:INFO: including mount point rootfs ('/') in backup
328:INFO: including mount point mp0 ('/var/lib/felhom') in backup
333:[golden] pre-delete existing: HTTP 204 (404/204 expected)
334:[golden] upload OK (HTTP 201)
```
`grep -E 'excluding|FATAL' bake.log` → no matches. Infra images baked (unchanged from the first
bake): traefik:v3.7.13, cloudflare/cloudflared:2026.9.3, gtstef/filebrowser:1.5.6-stable,
felhom-samba:1.1.0.
## Token-leak grep
On the copy in this directory (the one committed): `grep -c -F "$(cat ~/.gitea-token)" bake.log` = **0**.
Positive control: a throwaway copy with the token appended → **1**; the copy was `shred -u`'d.
## Round trip
See `02-round-trip.txt`: the published package downloaded anonymously (HTTP 200, 648975434 bytes)
hashes to `79a1dce3bd3c5a636a03c82be0f4ef969a1e0e9cbb139c5890b84c98fd69d43a` — **matches** GOLDEN_SHA256.
## Teardown state
- Log copied off the VM before teardown.
- `pct destroy 9100 --purge` → rc 0 (both LVs removed); `pct list` empty; no `9100` LV left.
- `/root/.gitea-token`, `/root/bake-run.sh`, `/root/bake.log` in the VM: `shred -u`, confirmed absent.
- VM powered off; no `qemu-system-x86` process remained.
- `qemu-img snapshot -a virgin drill.qcow2` → OK; snapshot list shows only `virgin`.
- Hub, k3s, demo boxes, ep0, tester boxes, customer guests: not touched. No vouch, no floor change.
- `df -h`: `/mnt/5_hdd` 37 %, `/` 53 % (before and after).