Files
felhom.eu/REPORT.md
T

28 lines
2.1 KiB
Markdown

# felhom.eu — task reports
> **Overwrite** this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in [hub/CHANGELOG.md](hub/CHANGELOG.md); the scripts history lives in [scripts/CHANGELOG.md](scripts/CHANGELOG.md).
## Controller-driven escrow ceremony — felhom.eu leg (installer + docs) — 2026-07-13
Companion commits to felhom-agent **v0.88.0** (`1c3a3ef`) + felhom-controller **v0.127.0**
(`08a966b`) — the customer-facing recovery-code wizard. felhom.eu commit `375cb08`.
- **host-install v1.16.0:** the `FELHOM_ESCROW` sudoers alias ships via the EXISTING canonical
sudoers fetch (no new step; header documents it). Hub `hostInstallVersion` synced to 1.16.0 in
the same commit (`hostinstall_gates.py` green; hub green gate run; **no hub deploy** — the
const rides the next hub train, display-only lag).
- **RUNBOOK-escrow-ceremony.md rewritten:** the controller wizard is the PRIMARY path; the CLI is
the operator fallback (text mode unchanged); **F1 threat-model paragraph** (R transits the CF
tunnel once at reveal — accepted 2026-07-13, same trust class as claim code/login password;
agent→controller leg never leaves the box; LAN-direct delivery PARKED); stale-blob warning +
supersede/void semantics documented; CLI staged-secret rule spelled out (a CLI run without the
staged secret mints a hash-less blob → the new Scenario-F warning).
- Deploy + live validation evidence: felhom-agent/REPORT.md + felhom-controller/REPORT.md
(agents 0.88.0 on demo host + drill VM, 63/63 capabilities; controllers 0.127.0 on both guests;
Scenario F fired live on BOTH boxes' hash-less blobs; the drill blob repaired —
`restic_pw_sha256` now covers the local password; one-shot claim + 410 proven endpoint-exact).
- **Operator follow-ups:** (1) one supervised wizard pass with Viktor's drill login (the full
browser leg incl. re-auth + reveal — CC cannot type the customer-owned password), ideally also
on the demo box to clear ITS legacy stale warning; (2) publish agent 0.88.0 + vouch in the
Day-0 manifest at the next publish train (deployed hosts got direct deploys).