Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
OS-updates spike — 2026-10-04 (answers architecture/11-os-updates.md §7 Q1–Q10)
Venues: demo-hp host + its 9201 + scratch 9202 (changes: 9202 Part G, demo-hp host Part H); demo-felhom host + 9201
(read only). Apt indexes for every read-only step went to a throwaway directory (scripts/os-survey.sh), so no
box's lists or sources changed. Hosts are CEST, guests UTC.
| Folder | What |
|---|---|
partE/ |
read-only surveys of five systems (*-host.txt, *-guest.txt), host package-set diff |
partF/ |
apt-cache madison (host + guest), Debian DSA re-announcement analysis, snapshot.debian.org probe |
partG/ |
9202: Debian update, undo, killed update, Docker step ×3 — SUMMARY.md |
partH/ |
demo-hp host: package lists before/after, Debian-lane run, one-package undo, kernel install + 2 reboots, Proxmox simulation |
partI/ |
sample approved list (sample-approved-list.tsv) and its read-only simulation on demo-felhom |
scripts/ |
every helper used, as run |
The answers
Q1 — exact Debian version a week later. The live Debian archives keep two versions of a package at most: the
point-release version in trixie (main) and the newest in trixie-security — never the intermediate ones
(partF/madison-demo-hp-host.txt: openssl installed u1, main u2, security u3; u1 is gone). DSA history,
2026-07-04..10-04 (partF/dsa-supersede-analysis.txt): 167 trixie advisories; a second advisory for the same package
within 2 days: 3 (1.8 %), all chromium/webkit2gtk — none of them on a box. Restricted to the 517 source packages
installed on a box: 20 advisories over 16 packages, 0 re-announced within 2, 7 or 14 days. snapshot.debian.org
is reachable from a box: a dated apt-get update takes 2.3–3.0 s (10.1 MB), and the exact gone version
openssl 3.5.6-1~deb13u1 downloads in 2.0 s (partF/snapshot-debian-org.md; https needs ca-certificates,
present on boxes, absent in the bare debian:trixie image).
Q2 — Proxmox and Docker keep old versions. Yes, many: pve-manager 66, qemu-server 58, proxmox-kernel-7.0
33, pve-container 32, docker-ce 46, containerd.io 18 versions listed. Debian: two at most (Q1). One host undo
measured: rsync back to its pre-update 3.4.1+ds1-5+deb13u2 → E: Version … was not found; libpng16-16t64 back
to 1.6.48-1+deb13u5 worked because that version is the point-release one in main (partH/H3-undo-one-package.txt).
Q3 — Docker engine update. Without live-restore (today's baked setting): all 6 containers restart, the app's
front door is silent 26.5–30 s, everything healthy +42–45 s. With live-restore: 0 restarts, no gap,
also across a containerd change. systemctl reload turns it ON; it does NOT turn it off; and a restart that turns it
off stops every running container and starts none of them (partG/SUMMARY.md).
Q4 — kernel. Both demo hosts: UEFI, GRUB (no proxmox-boot-tool ESPs), root on LVM ext4; demo-hp has Secure Boot ON,
demo-felhom OFF (setup mode). Installing a kernel makes it the GRUB default at once (GRUB_DEFAULT=0, newest first).
proxmox-boot-tool kernel pin <ver> --next-boot on GRUB writes a normal GRUB_DEFAULT + update-grub (GRUB's own
one-shot next_entry stays empty); proxmox-boot-cleanup.service removes it after a boot reaches userspace.
Measured on demo-hp with the operator's word: old kernel pinned permanently first, new pinned for next boot → reboot
1 came up on 7.0.14-20-pve (60 s, Secure Boot on, all healthy); reboot 2 came back on 7.0.2-6-pve (76 s). So the
fallback works after a SUCCESSFUL boot; read from the code (not measured), a kernel that hangs before userspace stays
the default. Watchdog: only softdog is loaded (by watchdog-mux); demo-hp has an AMD FCH (SMBus 00:14.0) and the
sp5100_tco module ships with the kernel, not loaded. A softdog cannot rescue a kernel that never boots.
Q5 — interrupted apt. Killed after 15 unpacks: 5 packages iU, 4 triggers pending. It does NOT recover by itself —
the next apt-get install refuses (Unmet dependencies. Try 'apt --fix-broken install'). dpkg --configure -a
(1.4 s) + apt-get -f install (3.9 s) repaired it; the rest applied in 14.1 s. Containers stayed up throughout.
Q6 — how far behind. Hosts: 188 pending each (80/79 Proxmox, 66 Debian point release, 27 both, 15 security, +1 tailscale on demo-felhom); guests: 59 (31 point, 15 both, 7 security, 6 Docker) on both 9201s, 54 on 9202. Installed: host 746/747 packages, guest 278. Each guest runs a DIFFERENT Docker (29.7.1, 29.7.2, 29.8.0; golden 0.290.0 bakes 29.8.2). Catching up: guest Debian 24.0 s / 38.1 MB; host Debian 59.7 s / 76 MB; the kernel 47 s / 131 MB.
Q7 — what restarts. Guest Debian run: postfix, journald, networkd restarted by their scripts; dockerd, containerd, sshd, dbus, logind, cron, dhclient keep the OLD libc until restarted. Host Debian run: dnsmasq, postfix, journald restarted; systemd (PID 1), lxc-start, pveproxy, pvedaemon, pvestatd, pvescheduler, watchdog-mux, sshd, zed, chronyd keep the old libc. Proxmox packages (simulated, from their own maintainer scripts): pve-manager → pvedaemon, pveproxy, pvestatd, pvescheduler, spiceproxy; pve-cluster → pmxcfs; corosync; chrony; qemu-server → qmeventd; pve-firewall; pve-ha-manager → lrm, crm; zfs-zed.
Q8 — the night window. Guest (UTC, demo-hp, W = 02:30): db-dump 02:30, tier-2 03:30, off-site ~04:15, whole-guest
gate [04:30, 08:30), controller self-update 04:30, offsite-integrity 06:00. Host (CEST): apt-daily and
apt-daily-upgrade timers are enabled but install nothing (no unattended-upgrades, no APT::Periodic);
pve-daily-update refreshes the lists daily; restore-tests run at any hour (demo-felhom 10:38 daily, demo-hp
16:43 and 22:46) — they are cadence-driven, not windowed; agent updates arrive by signed job at any hour.
Q9 — cloudflared. Not on the host: a container in the guest, cloudflare/cloudflared:2026.6.0, pinned in the
controller (internal/infra/infra.go:26) since 2026-06-11 (v0.41.0) and baked into the golden. Upstream is at
2026.9.3 (2026-09-24). It moves only when someone edits the pin.
Q10 — Proxmox enterprise repository (proxmox.com pricing page, 2026-10-04, net, per CPU socket per year): Community €120, Basic €370, Standard €550, Premium €1,100. Every tier includes the Enterprise Repository; Community has no support tickets. Record only — a money decision.
Teardown
- 9202: Debian fully updated, Docker 29.8.2 / containerd 2.3.6 (= golden 0.290.0),
daemon.jsonbyte-identical to the baked one, live-restore false, all 6 containers healthy. Its backup in/mnt/hdd_1/dump-9202-spikedeleted. - demo-hp host: 108 Debian packages updated +
proxmox-kernel-7.0.14-20-pve-signedinstalled (110 package changes,partH/H-final-host-packages-after.tsv); running7.0.2-6-pve, next boot7.0.14-20-pve(no pins left). Proxmox packages NOT updated (78 pending). - Helper files removed from both hosts and all guests; no throwaway image or container left.