Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Golden 0.298.0 — bake + publish, 2026-10-06 (release window 1 of the burn-down night)
Procedure: documentation/runbooks/RUNBOOK-manual-build.md §4.0 and §4.1 steps 1–4, in the drill VM on DooPlex.
Previous (../golden-0.297.0-2026-10-05/) |
This bake | |
|---|---|---|
build-golden.sh |
sha256 645b3b659cba… (v3.2.0) |
same file, unchanged |
| Controller | felhom-controller:0.297.0 |
felhom-controller:0.298.0 (MinAgent 0.131.0, unchanged) |
| Docker engine | the approved set os-docker-20261004-142842 |
same pinned set (PINNED line in bake.log; the hub's approved Docker release read on the System page 2026-10-06 00:41 = os-docker-20261004-142842) |
Said plainly: the first bake was unpinned, and was replaced before any vouch
The first run (00:33) was started WITHOUT GOLDEN_DOCKER_PKGS — the runbook's runner script did not name it — so it
installed the newest stable Docker set and printed GOLDEN_DOCKER_PKGS not set (log kept: bake-unpinned-not-vouched.log,
sha b524a96f…). It was NEVER vouched. The second run (00:40) pinned the set and re-published 0.298.0 over it (the
script pre-deletes its own version). The runbook now carries the step (§4.1 step 3).
Pass markers (from bake.log, this folder)
[golden] Docker engine set PINNED to the approved release: containerd.io=2.3.6-1~debian.13~trixie … docker-ce=5:29.8.2-1~debian.13~trixie …
docker OK (overlay2; data-root /var/lib/docker)
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
[golden] upload OK (HTTP 201)
GOLDEN_VERSION=0.298.0
GOLDEN_SHA256=a2e730e91148d390b6dc76221db9d19aa221ba3a27e2ccbc64df17793ea4470e
Round trip: the registry's file downloaded and hashed = the bake's sha (02-round-trip.txt).
Token: systemctl show … | grep -c -F <token> = 0 for both units; token grep on both saved logs = 0, with a working
control (the same grep on a copy with the token appended = 1).
Teardown
Build guest 9100 destroyed (pct list empty); token, runner script and logs shredded in the VM; VM powered off (no
qemu process); disk reverted to virgin.