diff --git a/runtime/history/CONTEXT-AUTO-20260922T091701Z.json b/runtime/history/CONTEXT-AUTO-20260922T091701Z.json new file mode 100644 index 00000000..f93b39cd --- /dev/null +++ b/runtime/history/CONTEXT-AUTO-20260922T091701Z.json @@ -0,0 +1 @@ +{"schema_version":1,"channel":"homelab-runtime","command_id":"CONTEXT-AUTO-20260922T091701Z","status":"OK","rc":0,"host":"pve01","mode":"read-only","component":"cluster-context","started_at_utc":"2026-09-22T09:17:01Z","finished_at_utc":"2026-09-22T09:17:02Z","reference_register_checked":true,"reference_sha256":"5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66","error_register_checked":true,"error_register_sha256":"3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0","changes_made":false,"sanitized":true,"secrets_included":false,"private_addresses_included":false,"output":"AUTOMATIC_CLUSTER_CONTEXT_REFRESH=OK"} diff --git a/runtime/history/CONTEXT-AUTO-20260922T091701Z.txt b/runtime/history/CONTEXT-AUTO-20260922T091701Z.txt new file mode 100644 index 00000000..ca95cb01 --- /dev/null +++ b/runtime/history/CONTEXT-AUTO-20260922T091701Z.txt @@ -0,0 +1,164 @@ +CHAT_OUTPUT_BEGIN +COMMAND_ID=CONTEXT-AUTO-[PRIVATE_IP]701Z +STATUS=OK +RC=0 +HOST=pve01 +COMPONENT=cluster-context +REFERENCE_SHA[PRIVATE_IP]e5154c41cb[PRIVATE_IP]aca68090be[PRIVATE_IP]bf[PRIVATE_IP]df[PRIVATE_IP] +ERROR_REGISTER_SHA[PRIVATE_IP]ec0f527ed3afeed[PRIVATE_IP]ee[PRIVATE_IP]bbfb[PRIVATE_IP]af4ba7ba0 +OUTPUT_BEGIN +GENERATED_AT_UTC=[PRIVATE_IP]T09:17:01Z +Cluster information +------------------- +Name: homelab +Config Version: 3 +Transport: knet +Secure auth: on + +Quorum information +------------------ +Date: Tue Sep [PRIVATE_IP] 2026 +Quorum provider: corosync_votequorum +Nodes: 3 +Node ID: [PRIVATE_IP] +Ring ID: 1.130 +Quorate: Yes + +Votequorum information +---------------------- +Expected votes: 3 +Highest expected: 3 +Total votes: 3 +Quorum: 2 +Flags: Quorate + +Membership information +---------------------- + Nodeid Votes Name +[PRIVATE_IP] [PRIVATE_IP].11 (local) +[PRIVATE_IP] [PRIVATE_IP].13 +[PRIVATE_IP] [PRIVATE_IP].12 + +Membership information +---------------------- + Nodeid Votes Name + 1 1 pve01 (local) + 2 1 pve03 + 3 1 pve02 +[{"cpu":[PRIVATE_IP]676692,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/100","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"pvepro-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":202588,"vmid":100},{"cpu":0,"disk":0,"diskread":0,"diskwrite":0,"id":"qemu/101","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":0,"memhost":0,"name":"pvepro-staging-v1","netin":0,"netout":0,"node":"pve01","status":"stopped","template":0,"type":"qemu","uptime":0,"vmid":101},{"cpu":[PRIVATE_IP][PRIVATE_IP],"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/110","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"dns1","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":110},{"cpu":[PRIVATE_IP]313741,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/111","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"dns2","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":111},{"cpu":[PRIVATE_IP]242e-05,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/112","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"unbound1","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":112},{"cpu":0,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/113","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"unbound2","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":113},{"cpu":[PRIVATE_IP]99279,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/130","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"edge-vm","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":130},{"cpu":[PRIVATE_IP]30577,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/150","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"snikket","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":150},{"cpu":[PRIVATE_IP]520399,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/160","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"forum-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":160},{"cpu":[PRIVATE_IP]9061,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/170","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"core-apps","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":170},{"cpu":[PRIVATE_IP]17419,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/171","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"monitoring","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":171},{"cpu":[PRIVATE_IP]574775,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/190","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"homelab-ops-worker","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":190},{"cpu":[PRIVATE_IP]245615,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/210","maxcpu":2,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"newfi-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":210},{"cpu":[PRIVATE_IP]556756,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/211","maxcpu":2,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"newfi-staging","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":211},{"cpu":0,"disk":0,"diskread":0,"diskwrite":0,"id":"qemu/9130","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":0,"memhost":0,"name":"edge-cold-standby","netin":0,"netout":0,"node":"pve02","status":"stopped","template":0,"type":"qemu","uptime":0,"vmid":9130},{"cgroup-mode":2,"cpu":[PRIVATE_IP]49907,"disk":[PRIVATE_IP],"id":"node/pve03","level":"","maxcpu":8,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve03","status":"online","type":"node","uptime":[PRIVATE_IP]},{"cgroup-mode":2,"cpu":[PRIVATE_IP]9249,"disk":[PRIVATE_IP],"id":"node/pve02","level":"","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve02","status":"online","type":"node","uptime":[PRIVATE_IP]},{"cgroup-mode":2,"cpu":[PRIVATE_IP]61285,"disk":[PRIVATE_IP],"id":"node/pve01","level":"","maxcpu":24,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve01","status":"online","type":"node","uptime":[PRIVATE_IP]},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve03/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve03","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve02/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve02","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve01/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve01","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve03/local","maxdisk":[PRIVATE_IP],"node":"pve03","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve02/local","maxdisk":[PRIVATE_IP],"node":"pve02","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve01/local","maxdisk":[PRIVATE_IP],"node":"pve01","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"id":"network/pve03/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve03","status":"ok","type":"network"},{"id":"network/pve02/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve02","status":"ok","type":"network"},{"id":"network/pve01/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve01","status":"ok","type":"network"}] +Name Type Status Total (KiB) Used (KiB) Available (KiB) % +local dir active [PRIVATE_IP] [PRIVATE_IP] [PRIVATE_IP] 37.35% +local-lvm lvmthin active [PRIVATE_IP] [PRIVATE_IP] [PRIVATE_IP] 15.68% + UNIT LOAD ACTIVE SUB DESCRIPTION +● homelab-backup-audit.service loaded failed failed Homelab unified backup and DR audit +● netbird-peers-health.service loaded failed failed NetBird peers health check +● skladchik-reports-monitor-supervisor.service loaded failed failed Skladchik reports monitor full supervisor + +Legend: LOAD → Reflects whether the unit definition was properly loaded. + ACTIVE → The high-level unit activation state, i.e. generalization of SUB. + SUB → The low-level unit activation state, values depend on unit type. + +3 loaded units listed. +NEXT LEFT LAST PASSED UNIT ACTIVATES +Tue [PRIVATE_IP] 12:17:36 MSK 33s Tue [PRIVATE_IP] 12:16:35 MSK 26s ago homelab-router-watchdog.timer homelab-router-watchdog.service +Tue [PRIVATE_IP] 12:17:59 MSK 56s Tue [PRIVATE_IP] 12:16:59 MSK 3s ago homelab-private-vpn-hosts-health.timer homelab-private-vpn-hosts-health.service +Tue [PRIVATE_IP] 12:17:59 MSK 56s Tue [PRIVATE_IP] 12:12:59 MSK 4min 3s ago homelab-smartctl-textfile.timer homelab-smartctl-textfile.service +Tue [PRIVATE_IP] 12:18:16 MSK 1min 13s Tue [PRIVATE_IP] 12:13:16 MSK 3min 46s ago netbird-peers-health.timer netbird-peers-health.service +Tue [PRIVATE_IP] 12:21:50 MSK 4min 47s Tue [PRIVATE_IP] 12:16:32 MSK 30s ago homelab-health-metrics.timer homelab-health-metrics.service +Tue [PRIVATE_IP] 12:22:16 MSK 5min Tue [PRIVATE_IP] 12:07:16 MSK 9min ago prometheus-node-exporter-apt.timer prometheus-node-exporter-apt.service +Tue [PRIVATE_IP] 12:22:32 MSK 5min Tue [PRIVATE_IP] 12:12:32 MSK 4min 30s ago skladchik-reports-monitor-supervisor.timer skladchik-reports-monitor-supervisor.service +Tue [PRIVATE_IP] 12:23:15 MSK 6min Tue [PRIVATE_IP] 11:44:22 MSK 32min ago homelab-backup-v2.timer homelab-backup-v2.service +Tue [PRIVATE_IP] 12:28:37 MSK 11min Tue [PRIVATE_IP] 12:13:37 MSK 3min 25s ago homelab-disk-space-health.timer homelab-disk-space-health.service +Tue [PRIVATE_IP] 12:28:37 MSK 11min Tue [PRIVATE_IP] 12:13:37 MSK 3min 25s ago prometheus-node-exporter-nvme.timer prometheus-node-exporter-nvme.service +Tue [PRIVATE_IP] 12:29:22 MSK 12min Tue [PRIVATE_IP] 12:13:59 MSK 3min 3s ago homelab-alertmanager-backup-health.timer homelab-alertmanager-backup-health.service +Tue [PRIVATE_IP] 12:30:00 MSK 12min Tue [PRIVATE_IP] 12:15:15 MSK 1min 47s ago homelab-incident-journal.timer homelab-incident-journal.service +Tue [PRIVATE_IP] 12:30:10 MSK 13min Tue [PRIVATE_IP] 12:15:58 MSK 1min 4s ago homelab-forum-snuffleupagus-health.timer homelab-forum-snuffleupagus-health.service +Tue [PRIVATE_IP] 12:30:15 MSK 13min Tue [PRIVATE_IP] 12:16:32 MSK 30s ago homelab-duty-admin-v2.timer homelab-duty-admin-v2.service +Tue [PRIVATE_IP] 12:30:50 MSK 13min Tue [PRIVATE_IP] 12:16:04 MSK 57s ago homelab-external-probe-vps-health.timer homelab-external-probe-vps-health.service +Tue [PRIVATE_IP] 12:30:58 MSK 13min Tue [PRIVATE_IP] 12:15:58 MSK 1min 4s ago homelab-pve03-staging-capacity-health.timer homelab-pve03-staging-capacity-health.service +Tue [PRIVATE_IP] 12:31:26 MSK 14min Tue [PRIVATE_IP] 12:02:16 MSK 14min ago homelab-mkdocs-auto-refresh.timer homelab-mkdocs-auto-refresh.service +Tue [PRIVATE_IP] 12:35:19 MSK 18min Tue [PRIVATE_IP] 12:05:58 MSK 11min ago homelab-backup-audit.timer homelab-backup-audit.service +Tue [PRIVATE_IP] 12:44:48 MSK 27min Tue [PRIVATE_IP] 12:11:32 MSK 5min ago homelab-reference-refresh.timer homelab-reference-refresh.service +Tue [PRIVATE_IP] 13:16:26 MSK 59min Tue [PRIVATE_IP] 07:09:07 MSK 5h 7min ago homelab-evidence-root.timer homelab-evidence-root.service +Tue [PRIVATE_IP] 13:30:00 MSK 1h 12min Tue [PRIVATE_IP] 11:30:02 MSK 47min ago homelab-app-cloud-quorum-queue.timer homelab-app-cloud-quorum-queue.service +Tue [PRIVATE_IP] 14:44:55 MSK 2h 27min Tue [PRIVATE_IP] 08:42:59 MSK 3h 34min ago homelab-mailru-trash-gc.timer homelab-mailru-trash-gc.service +Tue [PRIVATE_IP] 16:35:59 MSK 4h 18min Tue [PRIVATE_IP] 10:35:59 MSK 1h 41min ago homelab-vps-identity-audit.timer homelab-vps-identity-audit.service +Tue [PRIVATE_IP] 16:47:58 MSK 4h 30min Mon [PRIVATE_IP] 16:47:58 MSK 19h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Tue [PRIVATE_IP] 17:40:23 MSK 5h 23min Mon [PRIVATE_IP] 19:10:54 MSK 17h ago apt-daily.timer apt-daily.service +Wed [PRIVATE_IP] 00:00:00 MSK 11h Tue [PRIVATE_IP] 00:00:15 MSK 12h ago dpkg-db-backup.timer dpkg-db-backup.service +Wed [PRIVATE_IP] 00:04:00 MSK 11h Tue [PRIVATE_IP] 00:14:16 MSK 12h ago homelab-docker-health.timer homelab-docker-health.service +Wed [PRIVATE_IP] 00:05:26 MSK 11h Tue [PRIVATE_IP] 00:01:16 MSK 12h ago homelab-evidence-catalog.timer homelab-evidence-catalog.service +Wed [PRIVATE_IP] 00:09:18 MSK 11h Tue [PRIVATE_IP] 00:11:58 MSK 12h ago homelab-quality-gate.timer homelab-quality-gate.service +Wed [PRIVATE_IP] 00:11:10 MSK 11h Tue [PRIVATE_IP] 00:13:45 MSK 12h ago homelab-storage-capacity.timer homelab-storage-capacity.service +Wed [PRIVATE_IP] 00:23:23 MSK 12h Tue [PRIVATE_IP] 00:17:32 MSK 11h ago logrotate.timer logrotate.service +Wed [PRIVATE_IP] 01:43:37 MSK 13h Tue [PRIVATE_IP] 01:58:53 MSK 10h ago pve-daily-update.timer pve-daily-update.service +Wed [PRIVATE_IP] 03:23:23 MSK 15h Tue [PRIVATE_IP] 03:23:32 MSK 8h ago homelab-backup-retention-gc.timer homelab-backup-retention-gc.service +Wed [PRIVATE_IP] 06:05:55 MSK 17h Tue [PRIVATE_IP] 06:01:58 MSK 6h ago apt-daily-upgrade.timer apt-daily-upgrade.service +Wed [PRIVATE_IP] 07:00:09 MSK 18h Tue [PRIVATE_IP] 07:05:52 MSK 5h 11min ago homelab-drift-check.timer homelab-drift-check.service +Wed [PRIVATE_IP] 07:37:32 MSK 19h Tue [PRIVATE_IP] 07:32:58 MSK 4h 44min ago homelab-service-registry-check.timer homelab-service-registry-check.service +Wed [PRIVATE_IP] 07:41:08 MSK 19h Tue [PRIVATE_IP] 07:55:16 MSK 4h 21min ago homelab-dependency-map-check.timer homelab-dependency-map-check.service +Wed [PRIVATE_IP] 07:45:08 MSK 19h Tue [PRIVATE_IP] 07:53:32 MSK 4h 23min ago homelab-alerting-health.timer homelab-alerting-health.service +Wed [PRIVATE_IP] 07:49:54 MSK 19h Tue [PRIVATE_IP] 07:52:16 MSK 4h 24min ago homelab-runbook-generate.timer homelab-runbook-generate.service +Wed [PRIVATE_IP] 07:54:04 MSK 19h Tue [PRIVATE_IP] 08:00:58 MSK 4h 16min ago homelab-desired-state-sync.timer homelab-desired-state-sync.service +Wed [PRIVATE_IP] 08:06:21 MSK 19h Tue [PRIVATE_IP] 08:01:32 MSK 4h 15min ago homelab-duty-admin-report.timer homelab-duty-admin-report.service +Wed [PRIVATE_IP] 08:13:48 MSK 19h Tue [PRIVATE_IP] 08:11:58 MSK 4h 5min ago homelab-overall-health.timer homelab-overall-health.service +Wed [PRIVATE_IP] 08:16:23 MSK 19h Tue [PRIVATE_IP] 08:12:58 MSK 4h 4min ago homelab-kuma-monitor-policy.timer homelab-kuma-monitor-policy.service +Wed [PRIVATE_IP] 08:18:31 MSK 20h Tue [PRIVATE_IP] 08:19:32 MSK 3h 57min ago homelab-final-readiness-gate.timer homelab-final-readiness-gate.service +Wed [PRIVATE_IP] 08:39:26 MSK 20h Tue [PRIVATE_IP] 08:28:45 MSK 3h 48min ago homelab-capacity-risk.timer homelab-capacity-risk.service +Wed [PRIVATE_IP] 08:40:06 MSK 20h Tue [PRIVATE_IP] 08:43:32 MSK 3h 33min ago homelab-secret-exposure-guard.timer homelab-secret-exposure-guard.service +Wed [PRIVATE_IP] 08:48:42 MSK 20h Tue [PRIVATE_IP] 08:51:11 MSK 3h 25min ago homelab-cluster-passport.timer homelab-cluster-passport.service +Wed [PRIVATE_IP] 08:49:21 MSK 20h Tue [PRIVATE_IP] 09:01:45 MSK 3h 15min ago homelab-golden-state-index.timer homelab-golden-state-index.service +Wed [PRIVATE_IP] 10:15:00 MSK 21h Tue [PRIVATE_IP] 10:15:00 MSK 2h 2min ago skladchik-reports-monitor-monthly-selftest-watch.timer skladchik-reports-monitor-monthly-selftest-watch.service +Wed [PRIVATE_IP] 11:04:23 MSK 22h Tue [PRIVATE_IP] 08:22:45 MSK 3h 54min ago man-db.timer man-db.service +Sun [PRIVATE_IP] 03:10:02 MSK 4 days Sun [PRIVATE_IP] 03:10:58 MSK 2 days ago xfs_scrub_all.timer xfs_scrub_all.service +Sun [PRIVATE_IP] 03:10:39 MSK 4 days Sun [PRIVATE_IP] 03:10:12 MSK 2 days ago e2scrub_all.timer e2scrub_all.service +Sun [PRIVATE_IP] 06:43:52 MSK 4 days Sun [PRIVATE_IP] 07:40:22 MSK 2 days ago homelab-rotating-boot-drill.timer homelab-rotating-boot-drill.service +Mon [PRIVATE_IP] 00:01:03 MSK 5 days Mon [PRIVATE_IP] 00:04:44 MSK 1 day 12h ago homelab-secret-sanity.timer homelab-secret-sanity.service +Mon [PRIVATE_IP] 00:15:22 MSK 5 days Mon [PRIVATE_IP] 00:09:14 MSK 1 day 12h ago fstrim.timer fstrim.service +- - - - prometheus-node-exporter-ipmitool-sensor.timer prometheus-node-exporter-ipmitool-sensor.service +- - - - prometheus-node-exporter-mellanox-hca-temp.timer prometheus-node-exporter-mellanox-hca-temp.service +- - - - prometheus-node-exporter-smartmon.timer prometheus-node-exporter-smartmon.service + +58 timers listed. +RUNTIME_MANIFEST_ID=df[PRIVATE_IP]ac9b5abd[PRIVATE_IP]b[PRIVATE_IP]d89496fb2bde[PRIVATE_IP] +EXPERIMENT_ID=5462ee[PRIVATE_IP]ebe[PRIVATE_IP]feb2ad[PRIVATE_IP]1ad87bbac0b8108 +COLLECTION_START_AT=[PRIVATE_IP]T[PRIVATE_IP]:00 +FIRST_COMPLETE_D1_CLOSE=[PRIVATE_IP]T[PRIVATE_IP]:00 +PRODUCTION_LAUNCH_ALLOWED=False +EXECUTION_AUTHORITY=False +RISK_AUTHORITY=False +STAGE_A_HEALTH=AWAITING_PRIMARY_FINALITY +FORENSIC_PREVIOUS_EPOCH_PRESERVED=YES + +## NEWFI_TASK6_AUTH_CHECKPOINT_V[PRIVATE_IP] +- Scope: historical accepted AUTH test, not a current SMTP connection test. +- Newfi approved SMTP account/sender: aleisaev@yandex.ru. +- Endpoint used by accepted test: smtp.yandex.ru:465 with certificate verification; single PLAIN initial response accepted with code 235. +- Evidence: incident ledger ### NEWFI_TASK6_YANDEX_AUTH_V2_OBSERVATION and ### NEWFI_TASK6_AUTH_PROOF_CLOSE_V1. +- No password file written, no application configuration changed, no mail sent by the accepted AUTH test. +- Persistent transport installation and application delivery are not proven by this checkpoint. Task6 is not complete. +- AUTH challenge and missing-file incidents closed; launch/session incident remains OPEN with original cause unproven. +- This update does not change VM211, VM160, routing, board state or Git. +- Other incidents and infrastructure health were not assessed. + + +## NEWFI_PRIVATE_STRUCTURE92_WRONG_MARKER_SCOPE_[PRIVATE_IP] CLOSURE +- Status: CLOSED +- RCA: NEWFI92 inspected the pve01 NEWFI90 attempt marker, which had not been finalized because the outer shell exited immediately after the guest returned RC3 following its successful rollback. The guest marker contained the true final rollback state. +- Correction: NEWFI93 required both the guest FINISHED/ROLLED_BACK record and a fresh exact demo-state readback before reconciling the outer NEWFI90 marker. NEWFI92 itself never reserved an attempt or mutated state. + + +## NEWFI_PRIVATE_NEWFI95_NESTED_TRIPLE_QUOTE_PARSE_[PRIVATE_IP] +- Status: OPEN +- Command: NEWFI95 +- Symptom: after the content-structure precheck passed, the pve03 Python wrapper failed to parse at the PHP line beginning with $root. No Portal discovery or application mutation was reached. +- RCA: an outer raw triple-single-quoted guest Python payload contained an inner raw triple-single-quoted PHP payload. The inner delimiter terminated the outer Python string, causing PHP source to be parsed as Python. +- Safety: NEWFI95 was read-only, created no attempt marker, and did not reach the intended nested guest execution. Do not replay NEWFI95. + + +## NEWFI_PRIVATE_NEWFI95_NESTED_TRIPLE_QUOTE_PARSE_[PRIVATE_IP] CLOSURE +- Status: CLOSED +- RCA: an inner triple-single-quoted PHP literal terminated the outer triple-single-quoted Python guest payload in NEWFI95. The wrapper therefore failed parsing before the intended Portal discovery executed. +- Correction: NEWFI96 removed the nested Python payload layer entirely and passed one Python program directly to VM211 through qm guest exec stdin. The read-only Portal contract completed with QGA exit 0 and the implementation worktree remained unchanged. +OUTPUT_END +CHAT_OUTPUT_END diff --git a/runtime/latest.json b/runtime/latest.json index 1d832bd3..f93b39cd 100644 --- a/runtime/latest.json +++ b/runtime/latest.json @@ -1,38 +1 @@ -{ - "schema_version": 1, - "channel": "homelab-runtime", - "command_id": "SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1", - "status": "OK", - "rc": 0, - "host": "pve01", - "mode": "read-only", - "component": "homelab-backup-moldova-control-rca", - "started_at_utc": "2026-09-22T09:05:02Z", - "finished_at_utc": "2026-09-22T09:05:02Z", - "reference_register_checked": true, - "reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66", - "error_register_checked": true, - "error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0", - "command_sha256": "0988f0ccf22795188f482b9de7d6e5bbd0042f96af78f459db72983c90a6fc99", - "duplicate_failed_command_blocked": false, - "block_reason": null, - "execution_started": true, - "change_declared": false, - "result_contract_valid": true, - "result_contract_status": null, - "result_contract_error": null, - "command_rc": 0, - "changes_made": false, - "rollback_started": false, - "rollback_restored": null, - "mutation_outcome": "NO_MUTATION", - "sanitized": true, - "secrets_included": false, - "private_addresses_included": false, - "raw_evidence_retained_locally": true, - "raw_evidence_sha256": "e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25", - "sanitized_output_sha256": "e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25", - "output_truncated_in_json": false, - "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", - "output": "WORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_BEGIN=1\nCOMMAND_ID=SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1\nMODE=read-only\nCOMPONENT=homelab-backup-moldova-control-rca\nMUTATION_BOUNDARY=NONE;STATIC_CONTROL_PATH_CLASSIFICATION_ONLY;NO_PROVIDER_CALL;NO_NETWORK_MUTATION;NO_TARGET_SSH;NO_BACKUP;NO_SYSTEMD_ACTION;NO_GIT_WRITE;NO_SECRET_VALUE_READOUT\nREFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66\nERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0\nRUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d\nWRAPPER_SHA256=5077444065c732451cb84898680f62361b21a24ef9eb4f191253e82ead524ea2\nAUDIT_SHA256=5777bbb204708ffcebba0753506b819833b76370ecda59b4574e1aff3b9e4593\nLEGACY_SHA256=b6e79f087b9f1d21dac4f77a7b46b743299bbb85bc716e80d2ea67c2e038bcd7\nSCHEDULER_RC=0\nSELFTEST_REPLACEMENT486=PASS\nSCHEDULER_LIVE_SELECTION={\"due_seconds\":86400,\"enabled\":true,\"logical_id\":\"xf-newfi\"}\nTARGETS_CONFIG_SHA256=aa4a75455bbfe92afaf666e8d404b35c5b41e70bc014e770c9301865ee84e221\n{\"logical_id\":\"us-netbird\",\"type\":\"vps_us\",\"scope\":\"vps\",\"user\":\"root\",\"port\":22,\"enabled\":true,\"due_seconds\":86400}\nCONTROL_PATH_CLASSIFICATION_BEGIN=1\n{\"bytes\":20163,\"executable\":true,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh\",\"sha256\":\"9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868\"}\n{\"bytes\":20006,\"executable\":true,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771s_edge_capi_netbird_20260702T170251Z.sh\",\"sha256\":\"c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5\"}\n{\"bytes\":8977,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771p_netbird_vps_peer_repair.sh\",\"sha256\":\"f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747\"}\n{\"bytes\":6970,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771ad_final_crowdsec_capi_netbird_closure.sh\",\"sha256\":\"c99d08385f5d7c0a266c1c8002b3c7b054e1bb561eb48b1f8a227f37fe430ab6\"}\n{\"bytes\":28134,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771l_crowdsec_capi_netbird_vps_egress.sh\",\"sha256\":\"401396a25d4a5cfa487f67b355b45b27140ed1ac6b49b41e342306cb618dfdb5\"}\n{\"bytes\":24918,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771l_crowdsec_capi_netbird_vps_egress_remote_20260702T151045Z.sh\",\"sha256\":\"6a6df3cc085363c2bbbb92b8c3083123fb0e583e14e242c583a321bdb5612002\"}\n{\"bytes\":31306,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771m_purge_warp_fix_netbird_egress.sh\",\"sha256\":\"0ae3b0e1e8016da55cf1756e868c51a23fe12328fae6ef4baa61c50b9e48e715\"}\n{\"bytes\":27881,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771m_purge_warp_fix_netbird_remote_20260702T151637Z.sh\",\"sha256\":\"941f683d148a01d9af9ef6ce938c8ee6874d7af1ac1ac5ee96c7d9ca7cc262a4\"}\n{\"bytes\":12586,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771n_netbird_usa_moldova_egress_only.sh\",\"sha256\":\"420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e\"}\n{\"bytes\":10125,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771n_netbird_usa_moldova_egress_remote_20260702T152139Z.sh\",\"sha256\":\"1c25cbc13f524d0f6974a71c255c5634c69380818cb1b5ad4f8f6ea9bf8c6a01\"}\n{\"bytes\":7440,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771o_netbird_management_acl_discovery.sh\",\"sha256\":\"50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322\"}\n{\"bytes\":25955,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771q_netbird_public_vps_repair_then_capi.sh\",\"sha256\":\"0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071\"}\n{\"bytes\":26359,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771r_netbird_public_vps_fixed_then_capi.sh\",\"sha256\":\"dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7\"}\n{\"bytes\":28279,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771s_vps_identity_repair_netbird_capi.sh\",\"sha256\":\"16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9\"}\n{\"bytes\":25344,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771t_temp_hostkey_netbird_identity_then_capi.sh\",\"sha256\":\"0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da\"}\n{\"bytes\":27834,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771u_find_key_fix_netbird_egress_capi.sh\",\"sha256\":\"6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb\"}\n{\"bytes\":30154,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771v_deep_key_backup_netbird_capi.sh\",\"sha256\":\"92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170\"}\n{\"bytes\":13072,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/root/771z_after_manual_netbird_egress_capi.sh\",\"sha256\":\"f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee\"}\n{\"bytes\":9197,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/01_CURRENT_AUTHORITATIVE_STATE.md\",\"sha256\":\"844a17f9af701211699b078f5a5e8ff28bb401b377acc10fe364aa78aa3bfc9b\"}\n{\"bytes\":38895,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/index\",\"sha256\":\"93bd029aaadbac051ea3e9c7266ae0d0643ec8d0eff24a02ccb44805dc9764d2\"}\n{\"bytes\":38895,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0095/index\",\"sha256\":\"6327b174188ff5b751c03ba3e6b14d884a1d61dda42df86d8cf2e2151d74efe1\"}\n{\"bytes\":53159,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0096/index\",\"sha256\":\"0f244e69df78feba15d92d1c45c7d456e62726609ff45a6000cc5f11cc6b8e64\"}\n{\"bytes\":75082,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-1005/index\",\"sha256\":\"d7c61f503b6b7494e9aa4dde883d5a42493d81c346ba30938fe86386002dc388\"}\n{\"bytes\":31037,\"executable\":false,\"has_http\":true,\"has_netbird\":false,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md\",\"sha256\":\"f42b0e0be98c7f6d9f0e06d5565ec1cfc277e4221cbc164f21c157fe4121ad72\"}\n{\"bytes\":3587,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT.md\",\"sha256\":\"5fc43e34a1f0714ddacf7c00ed5c4bbaf788df3b8407dcfebd1333a23a623acc\"}\n{\"bytes\":1322,\"executable\":false,\"has_http\":false,\"has_netbird\":false,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/current/03_ACCESS_AND_SECRETS.md\",\"sha256\":\"e750284217dc41b5809268a0bbc54ed0948bdd14680fe2f282f307640937496c\"}\n{\"bytes\":805,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/current/04_P0_NEXT.md\",\"sha256\":\"0f6eb8b23382becc1868e8a22318d5b7629184568205bad47c3c38967a346b8f\"}\n{\"bytes\":3063,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/README_FIRST.md\",\"sha256\":\"02f7db5a75d4371a430a0034dc3e74a61ea355064fe44a1a221e8e175422a008\"}\n{\"bytes\":33401,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/SHA256SUMS\",\"sha256\":\"0939f8b9ab4de481c6e68a6abd16cb14ae5348a94e3af0d0e3f107815d0d3169\"}\n{\"bytes\":2726,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/00_START_HERE.md\",\"sha256\":\"4c4e4c85805aa00bd5f94f64fc9c2c985c44bf467058546e3cbe9d8d166d044f\"}\n{\"bytes\":3259,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/04_NETWORK_DNS_INGRESS.md\",\"sha256\":\"e3edd29ea8754ce340929f531c0ff8c1ebda4fbbf7d20a53445a665e014fbc85\"}\n{\"bytes\":3828,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/11_OPEN_ISSUES_AND_FUTURE_WORK.md\",\"sha256\":\"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647\"}\n{\"bytes\":2056,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/12_NEW_CHAT_FIRST_MESSAGE.txt\",\"sha256\":\"380315d5793449c258356145e7cff7dee7493d2c462dff3ca6f6d9eabfb673e0\"}\n{\"bytes\":1744,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/13_PROVENANCE_AND_FRESHNESS.md\",\"sha256\":\"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089\"}\n{\"bytes\":1740,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md\",\"sha256\":\"ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\"}\n{\"bytes\":3638,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/18_P0_CLOSEOUT_MASTER_PLAN_2026-08-19.md\",\"sha256\":\"0ce52a34278e57ff3dba122e2e65c57251e75484025ba13588971d0979d78ec6\"}\n{\"bytes\":1792,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md\",\"sha256\":\"12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\"}\n{\"bytes\":2265,\"executable\":false,\"has_http\":true,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md\",\"sha256\":\"fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\"}\n{\"bytes\":3828,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":true,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/24_GLOBAL_BACKLOG_MASTER_2026-08-19.md\",\"sha256\":\"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647\"}\n{\"bytes\":1733,\"executable\":false,\"has_http\":false,\"has_netbird\":false,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/25_OPERATOR_CHAT_RULES_2026-08-19.md\",\"sha256\":\"69bec1f0893c32c2ea67100355f8702f20bb6671177c6c1da69e1d2407c71232\"}\n{\"bytes\":1744,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":true,\"has_secret_reference\":false,\"has_ssh\":false,\"path\":\"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/28_PROVENANCE_AND_FRESHNESS_2026-08-19.md\",\"sha256\":\"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089\"}\n{\"bytes\":700,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":false,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/runbooks/04_NETBIRD_USA.md\",\"sha256\":\"725e2068337b379ebdf47822d5871aa5f4d5ec5956546674b2cf55b3250fb7a3\"}\n{\"bytes\":4057,\"executable\":false,\"has_http\":false,\"has_netbird\":true,\"has_power_action\":true,\"has_provider_hint\":false,\"has_secret_reference\":true,\"has_ssh\":true,\"path\":\"/srv/homelab-ops/kb/scripts/command_guard.py\",\"sha256\":\"33c59d92a2b9c380d9208a0e2fd1353029e6edc4878053df95dbd7b9dd987d0b\"}\nCONTROL_PATH_CLASSIFICATION_END=1\nCONTROL_TOTAL_ROWS=43\nCONTROL_EXEC_ROWS=2\nCONTROL_EXTERNAL_PROVIDER_ACTION_CANDIDATES=0\nCONTROL_SSH_DEPENDENT_CANDIDATES=2\nCONTROL_NETBIRD_ONLY_CANDIDATES=0\nKNOWN_771_SAFE_STATIC_BEGIN=1\nKNOWN_SCRIPT=/root/771n_netbird_usa_moldova_egress_only.sh SHA256=420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e EXECUTABLE=false\n20:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n22:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n41: echo \"CHECK=crowdsec-capi\"\n53: DISABLE_ONLINE_API: \"true\"\n54: ARGS: \"-no-capi\"\n93: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n95:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n102:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n103:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n104:Restart=always\n105:RestartSec=5\n111: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n115:base=/etc/homelab-crowdsec-capi-netbird-egress\n123:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n124:systemctl restart privoxy 2>/dev/null || true\n126:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n128: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n131: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n132: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n134: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n146: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n149: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n160:out.append(\"# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n163:out.append(\"# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_END\")\n168: systemctl restart privoxy\n189: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new \"$user@$ip\" \"echo SSH_OK; hostname; uname -a | cut -c1-120\" 2>&1 | redact; then\n192: if ssh -n -fN -M -S \"$ctl\" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D \"[PRIVATE_IP]:${port}\" \"$user@$ip\" 2>/tmp/771n_tunnel_${profile}.err; then\n194: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771n_capi_${profile}.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n195: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n196: echo \"SOCKS_CAPI_HTTP=$code\"\n200: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n232:docker exec crowdsec cscli lapi status 2>&1 | redact || true\n233:docker exec crowdsec cscli capi status 2>&1 | redact || true\n236:netbird status 2>&1 | redact || true\n239:systemctl restart netbird 2>/dev/null || true\n241:netbird status 2>&1 | redact || true\n244:USA_IP=\"$(awk '$1 ~ /^e3qxxx\\.netbird\\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)\"\n245:MOLDOVA_IP=\"$(awk '$1 ~ /^e3qxxx-183-106\\.netbird\\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)\"\n261: write_health \"REVIEW_USA_MOLDOVA_NETBIRD_PEERS_NOT_REACHABLE\" \"WARP purged; USA/Moldova NetBird VPS peers are not reachable or do not allow SSH from edge\"\n262: echo \"NEEDED_ON_VPS=NetBird peer online, SSH reachable over NetBird, and outbound TLS to api.crowdsec.net working\"\n276:proxy_code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771n_active_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n277:echo \"ACTIVE_HTTP_PROXY_CAPI_HTTP=$proxy_code\"\n280: write_health \"REVIEW_NETBIRD_EGRESS_PROXY_FAILED\" \"NetBird VPS SSH SOCKS profile exists but HTTP proxy did not reach CrowdSec CAPI\"\n286:write_health \"OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT\" \"NetBird VPS egress profile=$profile is ready; next command can register CrowdSec CAPI through proxy http://${b}:${HTTP_PROXY_PORT}\"\n287:echo \"READY_PROXY=http://${b}:${HTTP_PROXY_PORT}\"\n288:echo \"READY_SWITCH=homelab-crowdsec-capi-egress-switch $profile\"\n290:echo \"REMOTE_STATUS=OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT\"\n306: scp -q \"$LOCAL_REMOTE_SCRIPT\" \"debian@$EDGE:$REMOTE_SCRIPT\"\n315: ssh \"debian@$EDGE\" \"sudo bash '$REMOTE_SCRIPT' '$TS'\"\nKNOWN_SCRIPT=/root/771o_netbird_management_acl_discovery.sh SHA256=50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322 EXECUTABLE=false\n25: ssh debian@$EDGE \"sudo bash -lc '\n35: netbird status --json >/tmp/771o_netbird_status.json 2>/tmp/771o_netbird_status_json.err || true\n109: ssh -o BatchMode=yes -o ConnectTimeout=8 \"$user@$host\" \"sudo bash -lc '\nKNOWN_SCRIPT=/root/771p_netbird_vps_peer_repair.sh SHA256=f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747 EXECUTABLE=false\n19: echo \"RULE=NO_WARP_FIX_NETBIRD_USA_MOLDOVA_PEERS_FOR_CROWDSEC_CAPI\"\n23: echo \"CONFIG_CHANGE=YES_RESTART_NETBIRD_ON_VPS_IF_PUBLIC_SSH_FOUND\"\n36: ssh debian@$EDGE \"sudo bash -lc '\n46: netbird status --json >/tmp/771p_edge_nb.json 2>/tmp/771p_edge_nb.err || true\n80: grep -nEi 'e3qxxx|183-106|moldova|молдов|usa|america|vps|netbird|alexhost|aeza|hetzner|public ip|external ip|ssh' /etc/pve/31_HOMELAB_REFERENCE.md 2>/dev/null | sed -n '1,260p' || true\n138: echo \"TEST_PUBLIC_SSH_AND_RESTART_NETBIRD_ON_VPS_IF_FOUND\"\n158: ssh debian@$EDGE \"sudo bash -lc '\n159: systemctl restart netbird 2>/dev/null || true\n174: ssh debian@$EDGE \"sudo bash -lc '\n182: echo \"STATUS=OK_771P_VPS_PUBLIC_ACCESS_FOUND_RESTARTED_NETBIRD_REVIEW_RECHECK\"\nKNOWN_SCRIPT=/root/771q_netbird_public_vps_repair_then_capi.sh SHA256=0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI_${TS}_PROOF.txt\"\n16: echo \"STEP=771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI\"\n19: echo \"RULE=NO_WARP_REPAIR_NETBIRD_USA_MOLDOVA_THEN_CROWDSEC_CAPI\"\n23: echo \"CONFIG_CHANGE=YES_RESTART_PUBLIC_VPS_NETBIRD_AND_CAPI_IF_ROUTE_READY\"\n33: if timeout 18 ssh -n \\\n38: \"echo SSH_OK; echo HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n53: ssh debian@$EDGE \"sudo bash -lc 'command -v warp-cli >/dev/null 2>&1 && echo WARP_CLI_STILL_PRESENT || echo WARP_CLI_ABSENT=YES; dpkg -l 2>/dev/null | grep -E \\\"^ii[[:space:]]+cloudflare-warp\\\" || echo CLOUDFLARE_WARP_PACKAGE_ABSENT=YES; ss -ltnp | grep -E \\\":(40000|40001)\\\\b\\\" || echo WARP_PROXY_PORTS_ABSENT=YES'\"\n74: echo \"RESTART_NETBIRD_ON_REAL_PUBLIC_VPS_ONLY\"\n75: : >/tmp/771q_restarted.tsv\n80: echo \"RESTART_ATTEMPT profile=$profile user=$user host=$host\"\n81: out=\"/tmp/771q_restart_${profile}_${user}_$(echo \"$host\" | tr -c A-Za-z0-9 _).out\"\n82: if timeout 45 ssh -n \\\n87: \"echo BEFORE_HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; (sudo systemctl restart netbird 2>/dev/null || systemctl restart netbird 2>/dev/null || true); sleep 15; echo AFTER; command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi_after.body -w 'DIRECT_CAPI_HTTP_AFTER=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n91: printf '%s\\t%s\\t%s\\n' \"$profile\" \"$user\" \"$host\" >>/tmp/771q_restarted.tsv\n94: echo \"RESTART_FAILED profile=$profile user=$user host=$host\"\n103: echo \"PUBLIC_VPS_RESTARTED\"\n104: cat /tmp/771q_restarted.tsv || true\n106: echo \"RECHECK_EDGE_USA_MOLDOVA_AFTER_PUBLIC_RESTART\"\n107: ssh debian@$EDGE \"sudo bash -lc '\n109: systemctl restart netbird 2>/dev/null || true\n112: netbird status --json >/tmp/771q_edge_nb.json 2>/tmp/771q_edge_nb.err || true\n139: echo \"EDGE_BUILD_NETBIRD_EGRESS_AND_REGISTER_CAPI_IF_REACHABLE\"\n140: ssh debian@$EDGE \"sudo bash -s\" <<'EDGE_SCRIPT'\n146:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n148:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n167: echo \"CHECK=crowdsec-capi\"\n173:force_no_capi_stable() {\n179: DISABLE_ONLINE_API: \"true\"\n180: ARGS: \"-no-capi\"\n201:wait_lapi() {\n203: echo \"WAIT_LAPI=$label\"\n206: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771q_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n208: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n209: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}\"\n271: raise SystemExit(\"api.server block not found\")\n274: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n310: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771q_compose.yml || true\n311: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771q_compose.yml\n321: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new \"$user@$ip\" \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" 2>&1 | redact; then\n324: if ssh -n -fN -M -S \"$ctl\" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D \"[PRIVATE_IP]:${port}\" \"$user@$ip\" 2>/tmp/771q_tunnel.err; then\n326: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771q_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n327: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n328: echo \"SOCKS_CAPI_HTTP=$code\"\n332: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n360: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n362:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n369:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n370:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n371:Restart=always\n372:RestartSec=5\n378: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n382:base=/etc/homelab-crowdsec-capi-netbird-egress\n390:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n391:systemctl restart privoxy 2>/dev/null || true\n393:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n395: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n398: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n399: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n401: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n415: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n417: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n427:out.append(\"# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n430:out.append(\"# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_END\")\n435: systemctl restart privoxy\n440: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771q_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n441: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n445:register_capi() {\n447: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n448: echo \"REGISTER_CAPI proxy=$proxy_url\"\n450: force_no_capi_stable\n451: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n455: if test -f config/online_api_credentials.yaml; then\n456: mkdir -p /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-\"$TS\"\n457: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n462: wait_lapi \"REGISTER_MODE\" || return 13\n467: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n468: timeout 240 cscli capi register -y >/tmp/771q_register.out 2>&1\n470: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771q_register.out 2>&1\n483: if ! test -f config/online_api_credentials.yaml; then\n487: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\nKNOWN_SCRIPT=/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh SHA256=9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868 EXECUTABLE=true\n7:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n9:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n29: echo \"CHECK=crowdsec-capi\"\n35:force_no_capi_stable() {\n41: DISABLE_ONLINE_API: \"true\"\n42: ARGS: \"-no-capi\"\n65:wait_lapi() {\n68: echo \"WAIT_LAPI=$label\"\n71: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n73: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n74: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n75: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n149: raise SystemExit(\"api.server block not found\")\n153: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n192: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true\n193: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml\n207: timeout 12 ssh -n \\\n212: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n224: if ssh -n -fN -M -S \"$ctl\" \\\n234: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n235: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n236: echo \"SOCKS_CAPI_HTTP=$code\"\n240: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n273: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n275:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n282:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n283:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n284:Restart=always\n285:RestartSec=5\n291: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n295:base=/etc/homelab-crowdsec-capi-netbird-egress\n303:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n304:systemctl restart privoxy 2>/dev/null || true\n306:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n308: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n311: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n312: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n314: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n328: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n330: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n340:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n343:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END\")\n348: systemctl restart privoxy\n353: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n354: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n358:register_capi() {\n359: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after\n361: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n362: echo \"REGISTER_CAPI proxy=$proxy_url\"\n364: force_no_capi_stable\n365: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n369: if test -f config/online_api_credentials.yaml; then\n370: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"\n371: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n376: wait_lapi \"REGISTER_MODE\" || return 13\n381: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n382: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1\n384: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771r_register.out 2>&1\n397: if ! test -f config/online_api_credentials.yaml; then\n401: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n402: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n404: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n411: echo \"VALIDATE_CAPI\"\n415: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n416: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n418: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n419: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n420: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n421: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n422: printf '%s\\n' \"$capi_out\"\n423: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n430: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n432: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n433: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n434: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n435: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771r_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n436: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n437: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n439: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n441: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\nKNOWN_SCRIPT=/root/771r_netbird_public_vps_fixed_then_capi.sh SHA256=dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771R_NETBIRD_PUBLIC_VPS_FIXED_THEN_CAPI_${TS}_PROOF.txt\"\n10:EDGE_REMOTE=\"/tmp/771r_edge_netbird_egress_capi_${TS}.sh\"\n11:EDGE_LOCAL=\"/root/771r_edge_netbird_egress_capi_${TS}.sh\"\n26: timeout 20 ssh -n \\\n31: \"echo SSH_OK; echo USER=\\$(id -un); echo HOSTNAME=\\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n51:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n53:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n73: echo \"CHECK=crowdsec-capi\"\n79:force_no_capi_stable() {\n85: DISABLE_ONLINE_API: \"true\"\n86: ARGS: \"-no-capi\"\n109:wait_lapi() {\n112: echo \"WAIT_LAPI=$label\"\n115: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n117: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n118: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n119: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n193: raise SystemExit(\"api.server block not found\")\n197: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n236: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true\n237: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml\n251: timeout 12 ssh -n \\\n256: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n268: if ssh -n -fN -M -S \"$ctl\" \\\n278: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n279: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n280: echo \"SOCKS_CAPI_HTTP=$code\"\n284: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n317: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n319:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n326:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n327:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n328:Restart=always\n329:RestartSec=5\n335: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n339:base=/etc/homelab-crowdsec-capi-netbird-egress\n347:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n348:systemctl restart privoxy 2>/dev/null || true\n350:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n352: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n355: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n356: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n358: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n372: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n374: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n384:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n387:out.append(\"# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END\")\n392: systemctl restart privoxy\n397: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n398: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n402:register_capi() {\n403: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after\n405: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n406: echo \"REGISTER_CAPI proxy=$proxy_url\"\n408: force_no_capi_stable\n409: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n413: if test -f config/online_api_credentials.yaml; then\n414: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"\n415: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n420: wait_lapi \"REGISTER_MODE\" || return 13\n425: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n426: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1\n428: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771r_register.out 2>&1\n441: if ! test -f config/online_api_credentials.yaml; then\n445: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n446: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n448: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n455: echo \"VALIDATE_CAPI\"\n459: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n460: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n462: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n463: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n464: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n465: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n466: printf '%s\\n' \"$capi_out\"\n467: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n474: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n476: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n477: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n478: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\nKNOWN_SCRIPT=/root/771s_edge_capi_netbird_20260702T170251Z.sh SHA256=c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5 EXECUTABLE=true\n9:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n11:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n30: echo \"CHECK=crowdsec-capi\"\n36:force_no_capi_stable() {\n42: DISABLE_ONLINE_API: \"true\"\n43: ARGS: \"-no-capi\"\n65:wait_lapi() {\n67: echo \"WAIT_LAPI=$label\"\n70: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n72: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n73: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n74: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n149: raise SystemExit(\"api.server block not found\")\n153: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n191: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true\n192: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml\n204: timeout 12 ssh -n \\\n209: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n221: if ssh -n -fN -M -S \"$ctl\" \\\n231: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n232: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n233: echo \"SOCKS_CAPI_HTTP=$code\"\n237: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n269: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n271:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n278:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n279:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n280:Restart=always\n281:RestartSec=5\n287: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n291:base=/etc/homelab-crowdsec-capi-netbird-egress\n299:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n300:systemctl restart privoxy 2>/dev/null || true\n302:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n304: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n307: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n308: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n310: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n325: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n328: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n339:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n342:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END\")\n347: systemctl restart privoxy\n352: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n353: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n357:register_capi() {\n359: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n360: echo \"REGISTER_CAPI proxy=$proxy_url\"\n362: force_no_capi_stable\n363: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n367: if test -f config/online_api_credentials.yaml; then\n368: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"\n369: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n374: wait_lapi \"REGISTER_MODE\" || return 13\n379: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n380: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1\n382: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771s_register.out 2>&1\n395: if ! test -f config/online_api_credentials.yaml; then\n399: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n400: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n402: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n409: echo \"VALIDATE_CAPI\"\n413: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n414: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n416: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n417: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n418: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n419: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n420: printf '%s\\n' \"$capi_out\"\n421: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n428: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n430: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n431: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n432: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n433: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n434: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n435: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n437: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n439: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n443:echo \"STEP=771S_EDGE_NETBIRD_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771s_vps_identity_repair_netbird_capi.sh SHA256=16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771S_VPS_IDENTITY_REPAIR_NETBIRD_CAPI_${TS}_PROOF.txt\"\n13:EDGE_REMOTE=\"/tmp/771s_edge_capi_netbird_${TS}.sh\"\n14:EDGE_LOCAL=\"/root/771s_edge_capi_netbird_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n171: raise SystemExit(\"api.server block not found\")\n175: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n213: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true\n214: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml\n226: timeout 12 ssh -n \\\n231: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" \\\n243: if ssh -n -fN -M -S \"$ctl\" \\\n253: code=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n254: trace=\"$(curl -sk --proxy \"socks5h://[PRIVATE_IP]:${port}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)\"\n255: echo \"SOCKS_CAPI_HTTP=$code\"\n259: ssh -S \"$ctl\" -O exit \"$user@$ip\" >/dev/null 2>&1 || true\n291: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n293:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n300:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n301:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n302:Restart=always\n303:RestartSec=5\n309: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n313:base=/etc/homelab-crowdsec-capi-netbird-egress\n321:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n322:systemctl restart privoxy 2>/dev/null || true\n324:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n326: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n329: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n330: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n332: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n347: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n350: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n361:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n364:out.append(\"# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END\")\n369: systemctl restart privoxy\n374: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n375: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n379:register_capi() {\n381: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n382: echo \"REGISTER_CAPI proxy=$proxy_url\"\n384: force_no_capi_stable\n385: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n389: if test -f config/online_api_credentials.yaml; then\n390: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"\n391: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n396: wait_lapi \"REGISTER_MODE\" || return 13\n401: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n402: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1\n404: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771s_register.out 2>&1\n417: if ! test -f config/online_api_credentials.yaml; then\n421: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n422: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n424: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n431: echo \"VALIDATE_CAPI\"\n435: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n436: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n438: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n439: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n440: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n441: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n442: printf '%s\\n' \"$capi_out\"\n443: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n450: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n452: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n453: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n454: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n455: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n456: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n457: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\nKNOWN_SCRIPT=/root/771t_temp_hostkey_netbird_identity_then_capi.sh SHA256=0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da EXECUTABLE=false\n8:PROOF=\"/root/evidence/771T_TEMP_HOSTKEY_NETBIRD_IDENTITY_THEN_CAPI_${TS}_PROOF.txt\"\n11:EDGE_SCRIPT_LOCAL=\"/root/771t_edge_capi_${TS}.sh\"\n12:EDGE_SCRIPT_REMOTE=\"/tmp/771t_edge_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n50: echo \"CHECK=crowdsec-capi\"\n56:force_no_capi_stable() {\n62: DISABLE_ONLINE_API: \"true\"\n63: ARGS: \"-no-capi\"\n85:wait_lapi() {\n87: echo \"WAIT_LAPI=$label\"\n90: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n92: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n93: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n94: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n166: raise SystemExit(\"api.server block not found\")\n169: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771t_compose.yml || true\n208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771t_compose.yml\n217: timeout 15 ssh -n -o BatchMode=yes -o ConnectTimeout=8 -o StrictHostKeyChecking=accept-new \"$TARGET_USER@$TARGET_NB\" \\\n218: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771t_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n236: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n238:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n245:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n246:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n247:Restart=always\n248:RestartSec=5\n254: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n258:base=/etc/homelab-crowdsec-capi-netbird-egress\n266:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n267:systemctl restart privoxy 2>/dev/null || true\n269:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n271: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n274: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n275: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n277: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n293: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n296: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n307:out.append(\"# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n310:out.append(\"# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_END\")\n315: systemctl restart privoxy\n320: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771t_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n321: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n322: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n329:register_capi() {\n331: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n332: echo \"REGISTER_CAPI proxy=$proxy_url\"\n334: force_no_capi_stable\n335: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n339: if test -f config/online_api_credentials.yaml; then\n340: mkdir -p /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-\"$TS\"\n341: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n346: wait_lapi \"REGISTER_MODE\" || return 13\n351: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n352: timeout 240 cscli capi register -y >/tmp/771t_register.out 2>&1\n354: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771t_register.out 2>&1\n367: if ! test -f config/online_api_credentials.yaml; then\n371: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n372: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n374: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n381: echo \"VALIDATE_CAPI\"\n385: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n386: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n388: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n389: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n390: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n391: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n392: printf '%s\\n' \"$capi_out\"\n393: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n400: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n402: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n403: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n404: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n405: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771t_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n406: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n407: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n409: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n411: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n415:echo \"STEP=771T_EDGE_CAPI_VIA_VERIFIED_NETBIRD_PEER\"\n418:systemctl restart netbird 2>/dev/null || true\nKNOWN_SCRIPT=/root/771u_find_key_fix_netbird_egress_capi.sh SHA256=6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb EXECUTABLE=false\n8:PROOF=\"/root/evidence/771U_FIND_KEY_FIX_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt\"\n11:EDGE_REMOTE=\"/tmp/771u_edge_register_capi_${TS}.sh\"\n12:EDGE_LOCAL=\"/root/771u_edge_register_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n167: raise SystemExit(\"api.server block not found\")\n170: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771u_compose.yml || true\n208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771u_compose.yml\n213: ssh-keygen -q -t ed25519 -N \"\" -C \"homelab-crowdsec-capi-netbird-egress-edge\" -f \"$SSH_KEY\"\n227: timeout 15 ssh -n \\\n234: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771u_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n253: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n255:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n262:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n263:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i \"${SSH_KEY}\" -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n264:Restart=always\n265:RestartSec=5\n271: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n275:base=/etc/homelab-crowdsec-capi-netbird-egress\n283:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n284:systemctl restart privoxy 2>/dev/null || true\n286:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n288: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n291: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n292: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n294: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n310: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n313: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n324:out.append(\"# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n327:out.append(\"# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_END\")\n332: systemctl restart privoxy\n337: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771u_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n338: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n339: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n346:register_capi() {\n348: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n349: echo \"REGISTER_CAPI proxy=$proxy_url\"\n351: force_no_capi_stable\n352: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n356: if test -f config/online_api_credentials.yaml; then\n357: mkdir -p /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-\"$TS\"\n358: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n363: wait_lapi \"REGISTER_MODE\" || return 13\n368: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n369: timeout 240 cscli capi register -y >/tmp/771u_register.out 2>&1\n371: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771u_register.out 2>&1\n384: if ! test -f config/online_api_credentials.yaml; then\n388: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n389: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n391: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n398: echo \"VALIDATE_CAPI\"\n402: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n403: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n405: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n406: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n407: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n408: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n409: printf '%s\\n' \"$capi_out\"\n410: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n417: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n419: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n420: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n421: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n422: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771u_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n423: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n424: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n426: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n428: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n432:echo \"STEP=771U_EDGE_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771v_deep_key_backup_netbird_capi.sh SHA256=92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170 EXECUTABLE=false\n8:PROOF=\"/root/evidence/771V_DEEP_KEY_BACKUP_NETBIRD_CAPI_${TS}_PROOF.txt\"\n11:EDGE_LOCAL=\"/root/771v_edge_netbird_capi_${TS}.sh\"\n12:EDGE_REMOTE=\"/tmp/771v_edge_netbird_capi_${TS}.sh\"\n31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress\n33:HEALTH_FILE=\"$HEALTH_DIR/crowdsec-capi.txt\"\n52: echo \"CHECK=crowdsec-capi\"\n58:force_no_capi_stable() {\n64: DISABLE_ONLINE_API: \"true\"\n65: ARGS: \"-no-capi\"\n87:wait_lapi() {\n89: echo \"WAIT_LAPI=$label\"\n92: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n94: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n95: fatal=\"$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)\"\n96: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal\"\n168: raise SystemExit(\"api.server block not found\")\n172: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n210: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771v_compose.yml || true\n211: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771v_compose.yml\n216: ssh-keygen -q -t ed25519 -N \"\" -C \"homelab-crowdsec-capi-netbird-egress-edge\" -f \"$SSH_KEY\"\n230: timeout 15 ssh -n \\\n237: \"echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771v_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\\n' https://api.crowdsec.net/v3/watchers/login || true\" >\"$out\" 2>&1\n256: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF'\n258:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress\n265:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env\n266:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i \"${SSH_KEY}\" -D \"${SOCKS_BIND}:${SOCKS_PORT}\" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new \"${SSH_USER}@${SSH_HOST}\"'\n267:Restart=always\n268:RestartSec=5\n274: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF'\n278:base=/etc/homelab-crowdsec-capi-netbird-egress\n286:systemctl restart homelab-crowdsec-capi-netbird-egress.service\n287:systemctl restart privoxy 2>/dev/null || true\n289:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p'\n291: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch\n294: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service\n295: systemctl restart homelab-crowdsec-capi-netbird-egress.service\n297: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true\n313: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"BEGIN\" in line:\n316: if \"HOMELAB_771\" in line and \"CROWDSEC_CAPI\" in line and \"END\" in line:\n327:out.append(\"# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_BEGIN\")\n330:out.append(\"# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_END\")\n335: systemctl restart privoxy\n340: code=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 -o /tmp/771v_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n341: trace=\"$(curl -sk --proxy \"http://${b}:${HTTP_PROXY_PORT}\" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n342: echo \"HTTP_PROXY_CAPI_HTTP=$code\"\n349:register_capi() {\n351: proxy_url=\"http://${b}:${HTTP_PROXY_PORT}\"\n352: echo \"REGISTER_CAPI proxy=$proxy_url\"\n354: force_no_capi_stable\n355: wait_lapi \"BEFORE_CAPI_REGISTER\" || return 10\n359: if test -f config/online_api_credentials.yaml; then\n360: mkdir -p /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-\"$TS\"\n361: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-\"$TS\"/online_api_credentials.yaml.before-register\n366: wait_lapi \"REGISTER_MODE\" || return 13\n371: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n372: timeout 240 cscli capi register -y >/tmp/771v_register.out 2>&1\n374: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771v_register.out 2>&1\n387: if ! test -f config/online_api_credentials.yaml; then\n391: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n392: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n394: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22\n401: echo \"VALIDATE_CAPI\"\n405: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n406: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n408: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n409: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n410: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n411: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n412: printf '%s\\n' \"$capi_out\"\n413: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n420: rc_before=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n422: rc_after=\"$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)\"\n423: health_after=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n424: lapi_after=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n425: capi_after=\"$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771v_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)\"\n426: fatal_after=\"$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)\"\n427: env_after=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n429: echo \"FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}\"\n431: test \"$rc_before\" = \"$rc_after\" && test \"$health_after\" = \"200\" && test \"${lapi_after:-NA}\" = \"0\" && test \"${capi_after:-NA}\" = \"0\" && test \"$fatal_after\" = \"0\" && test -z \"$env_after\"\n435:echo \"STEP=771V_EDGE_NETBIRD_EGRESS_CAPI\"\nKNOWN_SCRIPT=/root/771z_after_manual_netbird_egress_capi.sh SHA256=f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee EXECUTABLE=false\n8:PROOF=\"/root/evidence/771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt\"\n14: echo \"STEP=771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI\"\n17: echo \"RULE=VERIFY_RELAY_MAIL_EGRESS_AND_REGISTER_CROWDSEC_CAPI\"\n21: ssh debian@$EDGE \"sudo bash -s\" <<'EDGE'\n27:HEALTH=/var/lib/homelab-health/crowdsec-capi.txt\n38: echo \"CHECK=crowdsec-capi\"\n44:wait_lapi() {\n46: echo \"WAIT_LAPI=$label\"\n49: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n51: rc=\"$(printf '%s\\n' \"$out\" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)\"\n52: echo \"LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}\"\n59:force_no_capi() {\n65: DISABLE_ONLINE_API: \"true\"\n66: ARGS: \"-no-capi\"\n87:enable_capi_compose() {\n112: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|socket-proxy|published:|target:' /tmp/771z_compose.yml || true\n113: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771z_compose.yml\n180: raise SystemExit(\"api.server block not found\")\n183: \" credentials_path: /etc/crowdsec/online_api_credentials.yaml\",\n194:echo \"NETBIRD_RESTART\"\n195:systemctl restart netbird 2>/dev/null || true\n199:netbird status 2>&1 | redact || true\n202:netbird status --json >/tmp/771z_nb.json 2>/tmp/771z_nb.err || true\n229:echo \"CAPI_DIRECT_TEST_AFTER_MANUAL_NETBIRD\"\n230:capi_code=\"$(curl -4 -sk --http1.1 --connect-timeout 12 --max-time 45 -o /tmp/771z_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)\"\n231:trace=\"$(curl -4 -sk --connect-timeout 12 --max-time 30 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)\"\n232:echo \"CAPI_DIRECT_HTTP=$capi_code\"\n237:if test \"$capi_code\" = \"000\"; then\n238: force_no_capi\n239: wait_lapi \"CAPI_ROUTE_NOT_READY_SAFE\" || true\n240: write_health \"REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY\" \"After manual NetBird setup, edge still cannot reach api.crowdsec.net; CrowdSec remains LAPI-only no-capi\"\n241: echo \"EDGE_STATUS=REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY_CAPI_NOT_DONE\"\n246:echo \"CAPI_ROUTE_READY_REGISTER_NOW\"\n248:mkdir -p \"manual-backups/771z-$TS\"\n249:test -f config/config.yaml && cp -a config/config.yaml \"manual-backups/771z-$TS/config.yaml.before\" || true\n250:test -f config/user.yaml && cp -a config/user.yaml \"manual-backups/771z-$TS/user.yaml.before\" || true\n251:test -f config/online_api_credentials.yaml && mv config/online_api_credentials.yaml \"manual-backups/771z-$TS/online_api_credentials.yaml.before\" || true\n254:enable_capi_compose || {\n255: force_no_capi\n256: wait_lapi \"COMPOSE_FAIL_SAFE\" || true\n257: write_health \"REVIEW_CAPI_COMPOSE_ENABLE_FAILED\" \"Direct CAPI route works, but compose CAPI enable failed\"\n262:wait_lapi \"REGISTER_MODE\" || exit 73\n266: if cscli capi register --help 2>&1 | grep -q -- \"-y\"; then\n267: timeout 240 cscli capi register -y >/tmp/771z_register.out 2>&1\n269: timeout 240 sh -c \"yes | cscli capi register\" >/tmp/771z_register.out 2>&1\n281:if test \"${reg_rc:-NA}\" != \"0\" || ! test -f config/online_api_credentials.yaml; then\n282: force_no_capi\n283: wait_lapi \"REGISTER_FAIL_SAFE\" || true\n284: write_health \"REVIEW_CAPI_ROUTE_READY_BUT_REGISTER_FAILED\" \"Direct CAPI route works, but cscli capi register failed; restored no-capi\"\n285: echo \"EDGE_STATUS=REVIEW_CAPI_REGISTER_FAILED_NOT_DONE\"\n290:stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true\n291:awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \\t]+|[ \\t]+$/, \"\", $1); print $1 \": REDACTED\"}' config/online_api_credentials.yaml | sed -n '1,40p'\n294:enable_capi_compose || exit 75\n300: health=\"$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)\"\n301: lapi_rc=\"$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771z_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)\"\n303: capi_rc=\"$(printf '%s\\n' \"$capi_out\" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)\"\n304: fatal=\"$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml' || true)\"\n305: envbad=\"$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)\"\n306: echo \"VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}\"\n307: printf '%s\\n' \"$capi_out\"\n308: if test \"$health\" = \"200\" && test \"${lapi_rc:-NA}\" = \"0\" && test \"${capi_rc:-NA}\" = \"0\" && test \"$fatal\" = \"0\" && test -z \"$envbad\"; then\n315: write_health \"OK_CAPI_REGISTERED_ENABLED_STABLE_MANUAL_NETBIRD_EGRESS\" \"CrowdSec CAPI registered and stable after manual NetBird egress via relay/mail\"\n316: echo \"EDGE_STATUS=OK_CROWDSEC_CAPI_100_PERCENT_REGISTERED_ENABLED_STABLE\"\n321:force_no_capi\n322:wait_lapi \"VALIDATION_FAIL_SAFE\" || true\n323:write_health \"REVIEW_CAPI_REGISTERED_BUT_NOT_STABLE_RESTORED_NO_CAPI\" \"CAPI registration happened but stability validation failed; restored no-capi\"\n324:echo \"EDGE_STATUS=REVIEW_CAPI_NOT_STABLE_RESTORED_NO_CAPI\"\n331: code=$(curl -sk --connect-timeout 8 --max-time 20 --resolve \"$h:443:$EDGE\" -o \"/tmp/771z_$h.html\" -w \"%{http_code}\" \"https://$h/\" || true)\n337: echo STATUS=OK_771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_DONE\nKNOWN_771_SAFE_STATIC_END=1\nPOLICY_DOCS_BEGIN=1\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\n1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD\n9:NetBird:\n14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures.\n16:Current:\n17:`/usr/local/sbin/pvepro-relay-healthcheck`\n27:- new NetBird TCP 80/443\n37:`PASS_RELAY_HEALTHCHECK_OK`\n40:enabled/active.\n48:Old USA observer had been converted to Gotify-only before retirement.\n50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon.\n78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf`\n86:- timer active\n89:Rollback backup:\n92:Old USA observer then:\n93:- backup created\n95:- service inactive\n96:- 80-second freeze proved no further health-file updates\n98:- old NetBird server still stopped\n99:- old host NetBird client still connected\n100:- Moldova peer reachable\n102:Old observer backup:\n103:`/root/retired-homelab-dr-observer-20260818T221046Z`\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\n1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD\n5:Old USA mail/NetBird VPS:\n7:- secondary NetBird IPv4 `[PRIVATE_IP]`\n10:Old NetBird server stack stopped after successful migration.\n11:Host-level NetBird client left running for rollback/peer observation.\n33:NetBird:\n36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`.\n56:- Moldova synthetic check passes\n59:Important health discovery:\n60:- `/api/health` 404 on exact deployed version\n61:- `:9000/health` 503 in combined relay/server mode\n62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy\n65:Backups on new server include migration/cutover snapshots such as:\n66:`/root/netbird-cutover-20260818T145807Z`\n69:- upgrade NetBird\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\n1:# CRITICAL KEEP / RETIRE DECISIONS\n3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof.\n11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore |\n12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect |\n16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup |\n18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first |\n19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties |\n20:| Moldova relay | KEEP | independent relay/external health |\n21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII |\n24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement |\n27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active |\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5\n1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD\n9:NetBird:\n14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures.\n16:Current:\n17:`/usr/local/sbin/pvepro-relay-healthcheck`\n27:- new NetBird TCP 80/443\n37:`PASS_RELAY_HEALTHCHECK_OK`\n40:enabled/active.\n48:Old USA observer had been converted to Gotify-only before retirement.\n50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon.\n78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf`\n86:- timer active\n89:Rollback backup:\n92:Old USA observer then:\n93:- backup created\n95:- service inactive\n96:- 80-second freeze proved no further health-file updates\n98:- old NetBird server still stopped\n99:- old host NetBird client still connected\n100:- Moldova peer reachable\n102:Old observer backup:\n103:`/root/retired-homelab-dr-observer-20260818T221046Z`\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552\n1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD\n5:Old USA mail/NetBird VPS:\n7:- secondary NetBird IPv4 `[PRIVATE_IP]`\n10:Old NetBird server stack stopped after successful migration.\n11:Host-level NetBird client left running for rollback/peer observation.\n33:NetBird:\n36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`.\n56:- Moldova synthetic check passes\n59:Important health discovery:\n60:- `/api/health` 404 on exact deployed version\n61:- `:9000/health` 503 in combined relay/server mode\n62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy\n65:Backups on new server include migration/cutover snapshots such as:\n66:`/root/netbird-cutover-20260818T145807Z`\n69:- upgrade NetBird\nPOLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af\n1:# CRITICAL KEEP / RETIRE DECISIONS\n3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof.\n11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore |\n12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect |\n16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup |\n18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first |\n19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties |\n20:| Moldova relay | KEEP | independent relay/external health |\n21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII |\n24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement |\n27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active |\nPOLICY_DOCS_END=1\nCONTROL_UNIT_REFERENCES_BEGIN=1\nCONTROL_UNIT_REFERENCES_END=1\nDECISION=PASS_BACKUP_1123_NO_EXTERNAL_PROVIDER_CONTROL_PATH_PROVEN\nNEXT_GATE=RETIRE_US_NETBIRD_TARGET_FROM_ACTIVE_BACKUPV2_POLICY_THEN_COMBINED_REPAIR\nTASK_RESULT=PASS_HOMELAB_BACKUP_MOLDOVA_CONTROL_RCA\nCHANGES_MADE_BY_1123=false\nPRODUCT_MUTATION_BY_1123=false\nVM_MUTATION_BY_1123=false\nCLOUD_MUTATION_BY_1123=false\nHOMELAB_RESULT_CONTRACT={\"version\":1,\"command_id\":\"SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1\",\"status\":\"OK\",\"changes_made\":false,\"rollback_started\":false,\"rollback_restored\":null}\nWORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_END=1\n" -} +{"schema_version":1,"channel":"homelab-runtime","command_id":"CONTEXT-AUTO-20260922T091701Z","status":"OK","rc":0,"host":"pve01","mode":"read-only","component":"cluster-context","started_at_utc":"2026-09-22T09:17:01Z","finished_at_utc":"2026-09-22T09:17:02Z","reference_register_checked":true,"reference_sha256":"5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66","error_register_checked":true,"error_register_sha256":"3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0","changes_made":false,"sanitized":true,"secrets_included":false,"private_addresses_included":false,"output":"AUTOMATIC_CLUSTER_CONTEXT_REFRESH=OK"} diff --git a/runtime/latest.txt b/runtime/latest.txt index 6e5e9562..ca95cb01 100644 --- a/runtime/latest.txt +++ b/runtime/latest.txt @@ -1,998 +1,164 @@ CHAT_OUTPUT_BEGIN -COMMAND_ID=SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1 +COMMAND_ID=CONTEXT-AUTO-[PRIVATE_IP]701Z STATUS=OK RC=0 HOST=pve01 -MODE=read-only -COMPONENT=homelab-backup-moldova-control-rca -REFERENCE_REGISTER_CHECK=OK -REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 -ERROR_REGISTER_CHECK=OK -ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 -COMMAND_SHA256=0988f0ccf22795188f482b9de7d6e5bbd0042f96af78f459db72983c90a6fc99 -DUPLICATE_FAILED_COMMAND_BLOCKED=false -EXECUTION_STARTED=true -CHANGE_DECLARED=false -RESULT_CONTRACT_VALID=true -RESULT_CONTRACT_STATUS=NOT_APPLICABLE -RESULT_CONTRACT_ERROR=NONE -COMMAND_RC=0 -CHANGES_MADE=false -ROLLBACK_STARTED=false -ROLLBACK_RESTORED=null -MUTATION_OUTCOME=NO_MUTATION -SANITIZED=yes -SECRETS_INCLUDED=no -PRIVATE_ADDRESSES_INCLUDED=no -RAW_EVIDENCE_SHA256=e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25 -SANITIZED_OUTPUT_SHA256=e6275a6d7a9af5aa0706e1fc384f1c4cd5d89bdba7691222cc0ad8bbf480bf25 +COMPONENT=cluster-context +REFERENCE_SHA[PRIVATE_IP]e5154c41cb[PRIVATE_IP]aca68090be[PRIVATE_IP]bf[PRIVATE_IP]df[PRIVATE_IP] +ERROR_REGISTER_SHA[PRIVATE_IP]ec0f527ed3afeed[PRIVATE_IP]ee[PRIVATE_IP]bbfb[PRIVATE_IP]af4ba7ba0 OUTPUT_BEGIN -WORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_BEGIN=1 -COMMAND_ID=SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1 -MODE=read-only -COMPONENT=homelab-backup-moldova-control-rca -MUTATION_BOUNDARY=NONE;STATIC_CONTROL_PATH_CLASSIFICATION_ONLY;NO_PROVIDER_CALL;NO_NETWORK_MUTATION;NO_TARGET_SSH;NO_BACKUP;NO_SYSTEMD_ACTION;NO_GIT_WRITE;NO_SECRET_VALUE_READOUT -REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66 -ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0 -RUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d -WRAPPER_SHA256=5077444065c732451cb84898680f62361b21a24ef9eb4f191253e82ead524ea2 -AUDIT_SHA256=5777bbb204708ffcebba0753506b819833b76370ecda59b4574e1aff3b9e4593 -LEGACY_SHA256=b6e79f087b9f1d21dac4f77a7b46b743299bbb85bc716e80d2ea67c2e038bcd7 -SCHEDULER_RC=0 -SELFTEST_REPLACEMENT486=PASS -SCHEDULER_LIVE_SELECTION={"due_seconds":86400,"enabled":true,"logical_id":"xf-newfi"} -TARGETS_CONFIG_SHA256=aa4a75455bbfe92afaf666e8d404b35c5b41e70bc014e770c9301865ee84e221 -{"logical_id":"us-netbird","type":"vps_us","scope":"vps","user":"root","port":22,"enabled":true,"due_seconds":86400} -CONTROL_PATH_CLASSIFICATION_BEGIN=1 -{"bytes":20163,"executable":true,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh","sha256":"9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868"} -{"bytes":20006,"executable":true,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771s_edge_capi_netbird_20260702T170251Z.sh","sha256":"c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5"} -{"bytes":8977,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/root/771p_netbird_vps_peer_repair.sh","sha256":"f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747"} -{"bytes":6970,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771ad_final_crowdsec_capi_netbird_closure.sh","sha256":"c99d08385f5d7c0a266c1c8002b3c7b054e1bb561eb48b1f8a227f37fe430ab6"} -{"bytes":28134,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771l_crowdsec_capi_netbird_vps_egress.sh","sha256":"401396a25d4a5cfa487f67b355b45b27140ed1ac6b49b41e342306cb618dfdb5"} -{"bytes":24918,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771l_crowdsec_capi_netbird_vps_egress_remote_20260702T151045Z.sh","sha256":"6a6df3cc085363c2bbbb92b8c3083123fb0e583e14e242c583a321bdb5612002"} -{"bytes":31306,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771m_purge_warp_fix_netbird_egress.sh","sha256":"0ae3b0e1e8016da55cf1756e868c51a23fe12328fae6ef4baa61c50b9e48e715"} -{"bytes":27881,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771m_purge_warp_fix_netbird_remote_20260702T151637Z.sh","sha256":"941f683d148a01d9af9ef6ce938c8ee6874d7af1ac1ac5ee96c7d9ca7cc262a4"} -{"bytes":12586,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771n_netbird_usa_moldova_egress_only.sh","sha256":"420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e"} -{"bytes":10125,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771n_netbird_usa_moldova_egress_remote_20260702T152139Z.sh","sha256":"1c25cbc13f524d0f6974a71c255c5634c69380818cb1b5ad4f8f6ea9bf8c6a01"} -{"bytes":7440,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771o_netbird_management_acl_discovery.sh","sha256":"50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322"} -{"bytes":25955,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771q_netbird_public_vps_repair_then_capi.sh","sha256":"0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071"} -{"bytes":26359,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771r_netbird_public_vps_fixed_then_capi.sh","sha256":"dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7"} -{"bytes":28279,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771s_vps_identity_repair_netbird_capi.sh","sha256":"16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9"} -{"bytes":25344,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771t_temp_hostkey_netbird_identity_then_capi.sh","sha256":"0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da"} -{"bytes":27834,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771u_find_key_fix_netbird_egress_capi.sh","sha256":"6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb"} -{"bytes":30154,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771v_deep_key_backup_netbird_capi.sh","sha256":"92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170"} -{"bytes":13072,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/root/771z_after_manual_netbird_egress_capi.sh","sha256":"f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee"} -{"bytes":9197,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/01_CURRENT_AUTHORITATIVE_STATE.md","sha256":"844a17f9af701211699b078f5a5e8ff28bb401b377acc10fe364aa78aa3bfc9b"} -{"bytes":38895,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/.git/index","sha256":"93bd029aaadbac051ea3e9c7266ae0d0643ec8d0eff24a02ccb44805dc9764d2"} -{"bytes":38895,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0095/index","sha256":"6327b174188ff5b751c03ba3e6b14d884a1d61dda42df86d8cf2e2151d74efe1"} -{"bytes":53159,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-0096/index","sha256":"0f244e69df78feba15d92d1c45c7d456e62726609ff45a6000cc5f11cc6b8e64"} -{"bytes":75082,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/.git/worktrees/homelab-ops-cr-2026-1005/index","sha256":"d7c61f503b6b7494e9aa4dde883d5a42493d81c346ba30938fe86386002dc388"} -{"bytes":31037,"executable":false,"has_http":true,"has_netbird":false,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md","sha256":"f42b0e0be98c7f6d9f0e06d5565ec1cfc277e4221cbc164f21c157fe4121ad72"} -{"bytes":3587,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/AI_CONTEXT.md","sha256":"5fc43e34a1f0714ddacf7c00ed5c4bbaf788df3b8407dcfebd1333a23a623acc"} -{"bytes":1322,"executable":false,"has_http":false,"has_netbird":false,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/kb/current/03_ACCESS_AND_SECRETS.md","sha256":"e750284217dc41b5809268a0bbc54ed0948bdd14680fe2f282f307640937496c"} -{"bytes":805,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/current/04_P0_NEXT.md","sha256":"0f6eb8b23382becc1868e8a22318d5b7629184568205bad47c3c38967a346b8f"} -{"bytes":3063,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/README_FIRST.md","sha256":"02f7db5a75d4371a430a0034dc3e74a61ea355064fe44a1a221e8e175422a008"} -{"bytes":33401,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":true,"has_secret_reference":false,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/SHA256SUMS","sha256":"0939f8b9ab4de481c6e68a6abd16cb14ae5348a94e3af0d0e3f107815d0d3169"} -{"bytes":2726,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/00_START_HERE.md","sha256":"4c4e4c85805aa00bd5f94f64fc9c2c985c44bf467058546e3cbe9d8d166d044f"} -{"bytes":3259,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/04_NETWORK_DNS_INGRESS.md","sha256":"e3edd29ea8754ce340929f531c0ff8c1ebda4fbbf7d20a53445a665e014fbc85"} -{"bytes":3828,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/11_OPEN_ISSUES_AND_FUTURE_WORK.md","sha256":"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647"} -{"bytes":2056,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":false,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/12_NEW_CHAT_FIRST_MESSAGE.txt","sha256":"380315d5793449c258356145e7cff7dee7493d2c462dff3ca6f6d9eabfb673e0"} -{"bytes":1744,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":true,"has_secret_reference":false,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/13_PROVENANCE_AND_FRESHNESS.md","sha256":"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089"} -{"bytes":1740,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md","sha256":"ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af"} -{"bytes":3638,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/18_P0_CLOSEOUT_MASTER_PLAN_2026-08-19.md","sha256":"0ce52a34278e57ff3dba122e2e65c57251e75484025ba13588971d0979d78ec6"} -{"bytes":1792,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":true,"has_secret_reference":false,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md","sha256":"12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552"} -{"bytes":2265,"executable":false,"has_http":true,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md","sha256":"fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5"} -{"bytes":3828,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":true,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/24_GLOBAL_BACKLOG_MASTER_2026-08-19.md","sha256":"8621c33341c93f6104e58821daeda1e534353290c685a273620b884014ddd647"} -{"bytes":1733,"executable":false,"has_http":false,"has_netbird":false,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/25_OPERATOR_CHAT_RULES_2026-08-19.md","sha256":"69bec1f0893c32c2ea67100355f8702f20bb6671177c6c1da69e1d2407c71232"} -{"bytes":1744,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":true,"has_secret_reference":false,"has_ssh":false,"path":"/srv/homelab-ops/kb/private/archive/2026-08-19/docs/28_PROVENANCE_AND_FRESHNESS_2026-08-19.md","sha256":"804a09f8ae5fe307c3fb96243246ef4817bb98695068a80f181978933ee70089"} -{"bytes":700,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":false,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/runbooks/04_NETBIRD_USA.md","sha256":"725e2068337b379ebdf47822d5871aa5f4d5ec5956546674b2cf55b3250fb7a3"} -{"bytes":4057,"executable":false,"has_http":false,"has_netbird":true,"has_power_action":true,"has_provider_hint":false,"has_secret_reference":true,"has_ssh":true,"path":"/srv/homelab-ops/kb/scripts/command_guard.py","sha256":"33c59d92a2b9c380d9208a0e2fd1353029e6edc4878053df95dbd7b9dd987d0b"} -CONTROL_PATH_CLASSIFICATION_END=1 -CONTROL_TOTAL_ROWS=43 -CONTROL_EXEC_ROWS=2 -CONTROL_EXTERNAL_PROVIDER_ACTION_CANDIDATES=0 -CONTROL_SSH_DEPENDENT_CANDIDATES=2 -CONTROL_NETBIRD_ONLY_CANDIDATES=0 -KNOWN_771_SAFE_STATIC_BEGIN=1 -KNOWN_SCRIPT=/root/771n_netbird_usa_moldova_egress_only.sh SHA256=420d835318960ae2644dafc93e0427584505acaffa9786927623aeb59ba6ac0e EXECUTABLE=false -20:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -22:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -41: echo "CHECK=crowdsec-capi" -53: DISABLE_ONLINE_API: "true" -54: ARGS: "-no-capi" -93: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -95:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -102:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -103:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -104:Restart=always -105:RestartSec=5 -111: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -115:base=/etc/homelab-crowdsec-capi-netbird-egress -123:systemctl restart homelab-crowdsec-capi-netbird-egress.service -124:systemctl restart privoxy 2>/dev/null || true -126:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -128: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -131: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -132: systemctl restart homelab-crowdsec-capi-netbird-egress.service -134: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -146: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -149: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -160:out.append("# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_BEGIN") -163:out.append("# HOMELAB_771N_CROWDSEC_CAPI_NETBIRD_END") -168: systemctl restart privoxy -189: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new "$user@$ip" "echo SSH_OK; hostname; uname -a | cut -c1-120" 2>&1 | redact; then -192: if ssh -n -fN -M -S "$ctl" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D "[PRIVATE_IP]:${port}" "$user@$ip" 2>/tmp/771n_tunnel_${profile}.err; then -194: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771n_capi_${profile}.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -195: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -196: echo "SOCKS_CAPI_HTTP=$code" -200: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -232:docker exec crowdsec cscli lapi status 2>&1 | redact || true -233:docker exec crowdsec cscli capi status 2>&1 | redact || true -236:netbird status 2>&1 | redact || true -239:systemctl restart netbird 2>/dev/null || true -241:netbird status 2>&1 | redact || true -244:USA_IP="$(awk '$1 ~ /^e3qxxx\.netbird\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)" -245:MOLDOVA_IP="$(awk '$1 ~ /^e3qxxx-183-106\.netbird\.selfhosted$/ {print $2}' < <(netbird status 2>/dev/null || true) | head -1)" -261: write_health "REVIEW_USA_MOLDOVA_NETBIRD_PEERS_NOT_REACHABLE" "WARP purged; USA/Moldova NetBird VPS peers are not reachable or do not allow SSH from edge" -262: echo "NEEDED_ON_VPS=NetBird peer online, SSH reachable over NetBird, and outbound TLS to api.crowdsec.net working" -276:proxy_code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771n_active_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -277:echo "ACTIVE_HTTP_PROXY_CAPI_HTTP=$proxy_code" -280: write_health "REVIEW_NETBIRD_EGRESS_PROXY_FAILED" "NetBird VPS SSH SOCKS profile exists but HTTP proxy did not reach CrowdSec CAPI" -286:write_health "OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT" "NetBird VPS egress profile=$profile is ready; next command can register CrowdSec CAPI through proxy http://${b}:${HTTP_PROXY_PORT}" -287:echo "READY_PROXY=http://${b}:${HTTP_PROXY_PORT}" -288:echo "READY_SWITCH=homelab-crowdsec-capi-egress-switch $profile" -290:echo "REMOTE_STATUS=OK_NETBIRD_EGRESS_PROFILE_READY_CAPI_REGISTRATION_NEXT" -306: scp -q "$LOCAL_REMOTE_SCRIPT" "debian@$EDGE:$REMOTE_SCRIPT" -315: ssh "debian@$EDGE" "sudo bash '$REMOTE_SCRIPT' '$TS'" -KNOWN_SCRIPT=/root/771o_netbird_management_acl_discovery.sh SHA256=50526afeaeb99fa9a8018374abe82731dcb9e93eac4be64934d0c6a8610be322 EXECUTABLE=false -25: ssh debian@$EDGE "sudo bash -lc ' -35: netbird status --json >/tmp/771o_netbird_status.json 2>/tmp/771o_netbird_status_json.err || true -109: ssh -o BatchMode=yes -o ConnectTimeout=8 "$user@$host" "sudo bash -lc ' -KNOWN_SCRIPT=/root/771p_netbird_vps_peer_repair.sh SHA256=f37aac25cac5b1c3983392070ddaff09e28497efa28884b03d23efc09a825747 EXECUTABLE=false -19: echo "RULE=NO_WARP_FIX_NETBIRD_USA_MOLDOVA_PEERS_FOR_CROWDSEC_CAPI" -23: echo "CONFIG_CHANGE=YES_RESTART_NETBIRD_ON_VPS_IF_PUBLIC_SSH_FOUND" -36: ssh debian@$EDGE "sudo bash -lc ' -46: netbird status --json >/tmp/771p_edge_nb.json 2>/tmp/771p_edge_nb.err || true -80: grep -nEi 'e3qxxx|183-106|moldova|молдов|usa|america|vps|netbird|alexhost|aeza|hetzner|public ip|external ip|ssh' /etc/pve/31_HOMELAB_REFERENCE.md 2>/dev/null | sed -n '1,260p' || true -138: echo "TEST_PUBLIC_SSH_AND_RESTART_NETBIRD_ON_VPS_IF_FOUND" -158: ssh debian@$EDGE "sudo bash -lc ' -159: systemctl restart netbird 2>/dev/null || true -174: ssh debian@$EDGE "sudo bash -lc ' -182: echo "STATUS=OK_771P_VPS_PUBLIC_ACCESS_FOUND_RESTARTED_NETBIRD_REVIEW_RECHECK" -KNOWN_SCRIPT=/root/771q_netbird_public_vps_repair_then_capi.sh SHA256=0b6e42e5b4013f7ee2191b140c5c507877fb05e2a4fdd7b39bea7b7c6b108071 EXECUTABLE=false -8:PROOF="/root/evidence/771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI_${TS}_PROOF.txt" -16: echo "STEP=771Q_NETBIRD_PUBLIC_VPS_REPAIR_THEN_CAPI" -19: echo "RULE=NO_WARP_REPAIR_NETBIRD_USA_MOLDOVA_THEN_CROWDSEC_CAPI" -23: echo "CONFIG_CHANGE=YES_RESTART_PUBLIC_VPS_NETBIRD_AND_CAPI_IF_ROUTE_READY" -33: if timeout 18 ssh -n \ -38: "echo SSH_OK; echo HOSTNAME=\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -53: ssh debian@$EDGE "sudo bash -lc 'command -v warp-cli >/dev/null 2>&1 && echo WARP_CLI_STILL_PRESENT || echo WARP_CLI_ABSENT=YES; dpkg -l 2>/dev/null | grep -E \"^ii[[:space:]]+cloudflare-warp\" || echo CLOUDFLARE_WARP_PACKAGE_ABSENT=YES; ss -ltnp | grep -E \":(40000|40001)\\b\" || echo WARP_PROXY_PORTS_ABSENT=YES'" -74: echo "RESTART_NETBIRD_ON_REAL_PUBLIC_VPS_ONLY" -75: : >/tmp/771q_restarted.tsv -80: echo "RESTART_ATTEMPT profile=$profile user=$user host=$host" -81: out="/tmp/771q_restart_${profile}_${user}_$(echo "$host" | tr -c A-Za-z0-9 _).out" -82: if timeout 45 ssh -n \ -87: "echo BEFORE_HOSTNAME=\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; (sudo systemctl restart netbird 2>/dev/null || systemctl restart netbird 2>/dev/null || true); sleep 15; echo AFTER; command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || true; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi_after.body -w 'DIRECT_CAPI_HTTP_AFTER=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -91: printf '%s\t%s\t%s\n' "$profile" "$user" "$host" >>/tmp/771q_restarted.tsv -94: echo "RESTART_FAILED profile=$profile user=$user host=$host" -103: echo "PUBLIC_VPS_RESTARTED" -104: cat /tmp/771q_restarted.tsv || true -106: echo "RECHECK_EDGE_USA_MOLDOVA_AFTER_PUBLIC_RESTART" -107: ssh debian@$EDGE "sudo bash -lc ' -109: systemctl restart netbird 2>/dev/null || true -112: netbird status --json >/tmp/771q_edge_nb.json 2>/tmp/771q_edge_nb.err || true -139: echo "EDGE_BUILD_NETBIRD_EGRESS_AND_REGISTER_CAPI_IF_REACHABLE" -140: ssh debian@$EDGE "sudo bash -s" <<'EDGE_SCRIPT' -146:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -148:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -167: echo "CHECK=crowdsec-capi" -173:force_no_capi_stable() { -179: DISABLE_ONLINE_API: "true" -180: ARGS: "-no-capi" -201:wait_lapi() { -203: echo "WAIT_LAPI=$label" -206: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771q_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -208: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -209: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}" -271: raise SystemExit("api.server block not found") -274: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -310: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771q_compose.yml || true -311: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771q_compose.yml -321: if timeout 12 ssh -n -o BatchMode=yes -o ConnectTimeout=7 -o StrictHostKeyChecking=accept-new "$user@$ip" "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771q_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" 2>&1 | redact; then -324: if ssh -n -fN -M -S "$ctl" -o BatchMode=yes -o ConnectTimeout=8 -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new -D "[PRIVATE_IP]:${port}" "$user@$ip" 2>/tmp/771q_tunnel.err; then -326: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771q_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -327: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -328: echo "SOCKS_CAPI_HTTP=$code" -332: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -360: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -362:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -369:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -370:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -371:Restart=always -372:RestartSec=5 -378: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -382:base=/etc/homelab-crowdsec-capi-netbird-egress -390:systemctl restart homelab-crowdsec-capi-netbird-egress.service -391:systemctl restart privoxy 2>/dev/null || true -393:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -395: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -398: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -399: systemctl restart homelab-crowdsec-capi-netbird-egress.service -401: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -415: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -417: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -427:out.append("# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_BEGIN") -430:out.append("# HOMELAB_771Q_CROWDSEC_CAPI_NETBIRD_END") -435: systemctl restart privoxy -440: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771q_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -441: echo "HTTP_PROXY_CAPI_HTTP=$code" -445:register_capi() { -447: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -448: echo "REGISTER_CAPI proxy=$proxy_url" -450: force_no_capi_stable -451: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -455: if test -f config/online_api_credentials.yaml; then -456: mkdir -p /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-"$TS" -457: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771q-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -462: wait_lapi "REGISTER_MODE" || return 13 -467: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -468: timeout 240 cscli capi register -y >/tmp/771q_register.out 2>&1 -470: timeout 240 sh -c "yes | cscli capi register" >/tmp/771q_register.out 2>&1 -483: if ! test -f config/online_api_credentials.yaml; then -487: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -KNOWN_SCRIPT=/root/771r_edge_netbird_egress_capi_20260702T165517Z.sh SHA256=9c6f911768869c984ec41016b3134be75620100fac8c60a8b21ef6bde58c6868 EXECUTABLE=true -7:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -9:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -29: echo "CHECK=crowdsec-capi" -35:force_no_capi_stable() { -41: DISABLE_ONLINE_API: "true" -42: ARGS: "-no-capi" -65:wait_lapi() { -68: echo "WAIT_LAPI=$label" -71: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -73: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -74: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -75: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -149: raise SystemExit("api.server block not found") -153: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -192: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true -193: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml -207: timeout 12 ssh -n \ -212: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -224: if ssh -n -fN -M -S "$ctl" \ -234: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -235: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -236: echo "SOCKS_CAPI_HTTP=$code" -240: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -273: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -275:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -282:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -283:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -284:Restart=always -285:RestartSec=5 -291: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -295:base=/etc/homelab-crowdsec-capi-netbird-egress -303:systemctl restart homelab-crowdsec-capi-netbird-egress.service -304:systemctl restart privoxy 2>/dev/null || true -306:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -308: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -311: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -312: systemctl restart homelab-crowdsec-capi-netbird-egress.service -314: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -328: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -330: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -340:out.append("# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN") -343:out.append("# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END") -348: systemctl restart privoxy -353: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -354: echo "HTTP_PROXY_CAPI_HTTP=$code" -358:register_capi() { -359: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after -361: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -362: echo "REGISTER_CAPI proxy=$proxy_url" -364: force_no_capi_stable -365: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -369: if test -f config/online_api_credentials.yaml; then -370: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-"$TS" -371: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -376: wait_lapi "REGISTER_MODE" || return 13 -381: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -382: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1 -384: timeout 240 sh -c "yes | cscli capi register" >/tmp/771r_register.out 2>&1 -397: if ! test -f config/online_api_credentials.yaml; then -401: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -402: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -404: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -411: echo "VALIDATE_CAPI" -415: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -416: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -418: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -419: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -420: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -421: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -422: printf '%s\n' "$capi_out" -423: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -430: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -432: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -433: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -434: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -435: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771r_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -436: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -437: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -439: echo "FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}" -441: test "$rc_before" = "$rc_after" && test "$health_after" = "200" && test "${lapi_after:-NA}" = "0" && test "${capi_after:-NA}" = "0" && test "$fatal_after" = "0" && test -z "$env_after" -KNOWN_SCRIPT=/root/771r_netbird_public_vps_fixed_then_capi.sh SHA256=dc8119b6815d60e08f442e77faba6ce6e9899c4120d78490886e222b8510efa7 EXECUTABLE=false -8:PROOF="/root/evidence/771R_NETBIRD_PUBLIC_VPS_FIXED_THEN_CAPI_${TS}_PROOF.txt" -10:EDGE_REMOTE="/tmp/771r_edge_netbird_egress_capi_${TS}.sh" -11:EDGE_LOCAL="/root/771r_edge_netbird_egress_capi_${TS}.sh" -26: timeout 20 ssh -n \ -31: "echo SSH_OK; echo USER=\$(id -un); echo HOSTNAME=\$(hostname); command -v netbird >/dev/null 2>&1 && netbird status 2>&1 || echo NETBIRD_CLI_MISSING; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -51:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -53:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -73: echo "CHECK=crowdsec-capi" -79:force_no_capi_stable() { -85: DISABLE_ONLINE_API: "true" -86: ARGS: "-no-capi" -109:wait_lapi() { -112: echo "WAIT_LAPI=$label" -115: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -117: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -118: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -119: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -193: raise SystemExit("api.server block not found") -197: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -236: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771r_compose.yml || true -237: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771r_compose.yml -251: timeout 12 ssh -n \ -256: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771r_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -268: if ssh -n -fN -M -S "$ctl" \ -278: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771r_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -279: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -280: echo "SOCKS_CAPI_HTTP=$code" -284: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -317: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -319:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -326:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -327:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -328:Restart=always -329:RestartSec=5 -335: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -339:base=/etc/homelab-crowdsec-capi-netbird-egress -347:systemctl restart homelab-crowdsec-capi-netbird-egress.service -348:systemctl restart privoxy 2>/dev/null || true -350:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -352: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -355: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -356: systemctl restart homelab-crowdsec-capi-netbird-egress.service -358: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -372: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -374: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -384:out.append("# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_BEGIN") -387:out.append("# HOMELAB_771R_CROWDSEC_CAPI_NETBIRD_END") -392: systemctl restart privoxy -397: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771r_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -398: echo "HTTP_PROXY_CAPI_HTTP=$code" -402:register_capi() { -403: local b proxy_url reg_out reg_rc ready n health lapi_rc capi_out capi_rc fatal envbad rc_before rc_after health_after lapi_after capi_after fatal_after env_after -405: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -406: echo "REGISTER_CAPI proxy=$proxy_url" -408: force_no_capi_stable -409: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -413: if test -f config/online_api_credentials.yaml; then -414: mkdir -p /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-"$TS" -415: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771r-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -420: wait_lapi "REGISTER_MODE" || return 13 -425: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -426: timeout 240 cscli capi register -y >/tmp/771r_register.out 2>&1 -428: timeout 240 sh -c "yes | cscli capi register" >/tmp/771r_register.out 2>&1 -441: if ! test -f config/online_api_credentials.yaml; then -445: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -446: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -448: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -455: echo "VALIDATE_CAPI" -459: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -460: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -462: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -463: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -464: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -465: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -466: printf '%s\n' "$capi_out" -467: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -474: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -476: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -477: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771r_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -478: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771r_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -KNOWN_SCRIPT=/root/771s_edge_capi_netbird_20260702T170251Z.sh SHA256=c4783c14a3a132616af5db6a065270ccd39a7690f9fd38d0ef27fe5de6bd07e5 EXECUTABLE=true -9:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -11:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -30: echo "CHECK=crowdsec-capi" -36:force_no_capi_stable() { -42: DISABLE_ONLINE_API: "true" -43: ARGS: "-no-capi" -65:wait_lapi() { -67: echo "WAIT_LAPI=$label" -70: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -72: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -73: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -74: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -149: raise SystemExit("api.server block not found") -153: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -191: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true -192: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml -204: timeout 12 ssh -n \ -209: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -221: if ssh -n -fN -M -S "$ctl" \ -231: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -232: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -233: echo "SOCKS_CAPI_HTTP=$code" -237: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -269: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -271:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -278:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -279:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -280:Restart=always -281:RestartSec=5 -287: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -291:base=/etc/homelab-crowdsec-capi-netbird-egress -299:systemctl restart homelab-crowdsec-capi-netbird-egress.service -300:systemctl restart privoxy 2>/dev/null || true -302:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -304: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -307: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -308: systemctl restart homelab-crowdsec-capi-netbird-egress.service -310: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -325: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -328: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -339:out.append("# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN") -342:out.append("# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END") -347: systemctl restart privoxy -352: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -353: echo "HTTP_PROXY_CAPI_HTTP=$code" -357:register_capi() { -359: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -360: echo "REGISTER_CAPI proxy=$proxy_url" -362: force_no_capi_stable -363: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -367: if test -f config/online_api_credentials.yaml; then -368: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-"$TS" -369: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -374: wait_lapi "REGISTER_MODE" || return 13 -379: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -380: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1 -382: timeout 240 sh -c "yes | cscli capi register" >/tmp/771s_register.out 2>&1 -395: if ! test -f config/online_api_credentials.yaml; then -399: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -400: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -402: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -409: echo "VALIDATE_CAPI" -413: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -414: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -416: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -417: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -418: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -419: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -420: printf '%s\n' "$capi_out" -421: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -428: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -430: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -431: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -432: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -433: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -434: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -435: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -437: echo "FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}" -439: test "$rc_before" = "$rc_after" && test "$health_after" = "200" && test "${lapi_after:-NA}" = "0" && test "${capi_after:-NA}" = "0" && test "$fatal_after" = "0" && test -z "$env_after" -443:echo "STEP=771S_EDGE_NETBIRD_EGRESS_CAPI" -KNOWN_SCRIPT=/root/771s_vps_identity_repair_netbird_capi.sh SHA256=16121a810320b1517291830ba128baf6c68e7b3e6f78786481dedb78a1f061b9 EXECUTABLE=false -8:PROOF="/root/evidence/771S_VPS_IDENTITY_REPAIR_NETBIRD_CAPI_${TS}_PROOF.txt" -13:EDGE_REMOTE="/tmp/771s_edge_capi_netbird_${TS}.sh" -14:EDGE_LOCAL="/root/771s_edge_capi_netbird_${TS}.sh" -31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -33:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -52: echo "CHECK=crowdsec-capi" -58:force_no_capi_stable() { -64: DISABLE_ONLINE_API: "true" -65: ARGS: "-no-capi" -87:wait_lapi() { -89: echo "WAIT_LAPI=$label" -92: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -94: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -95: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -96: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -171: raise SystemExit("api.server block not found") -175: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -213: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771s_compose.yml || true -214: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771s_compose.yml -226: timeout 12 ssh -n \ -231: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771s_capi.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" \ -243: if ssh -n -fN -M -S "$ctl" \ -253: code="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 -o /tmp/771s_capi_proxy.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -254: trace="$(curl -sk --proxy "socks5h://[PRIVATE_IP]:${port}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,5p' || true)" -255: echo "SOCKS_CAPI_HTTP=$code" -259: ssh -S "$ctl" -O exit "$user@$ip" >/dev/null 2>&1 || true -291: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -293:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -300:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -301:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -302:Restart=always -303:RestartSec=5 -309: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -313:base=/etc/homelab-crowdsec-capi-netbird-egress -321:systemctl restart homelab-crowdsec-capi-netbird-egress.service -322:systemctl restart privoxy 2>/dev/null || true -324:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -326: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -329: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -330: systemctl restart homelab-crowdsec-capi-netbird-egress.service -332: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -347: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -350: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -361:out.append("# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_BEGIN") -364:out.append("# HOMELAB_771S_CROWDSEC_CAPI_NETBIRD_END") -369: systemctl restart privoxy -374: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771s_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -375: echo "HTTP_PROXY_CAPI_HTTP=$code" -379:register_capi() { -381: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -382: echo "REGISTER_CAPI proxy=$proxy_url" -384: force_no_capi_stable -385: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -389: if test -f config/online_api_credentials.yaml; then -390: mkdir -p /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-"$TS" -391: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771s-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -396: wait_lapi "REGISTER_MODE" || return 13 -401: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -402: timeout 240 cscli capi register -y >/tmp/771s_register.out 2>&1 -404: timeout 240 sh -c "yes | cscli capi register" >/tmp/771s_register.out 2>&1 -417: if ! test -f config/online_api_credentials.yaml; then -421: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -422: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -424: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -431: echo "VALIDATE_CAPI" -435: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -436: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -438: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -439: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -440: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -441: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -442: printf '%s\n' "$capi_out" -443: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -450: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -452: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -453: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771s_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -454: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771s_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -455: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771s_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -456: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -457: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -KNOWN_SCRIPT=/root/771t_temp_hostkey_netbird_identity_then_capi.sh SHA256=0c3d628b23b67849d52112322ab2e1ee3779012c10578a0b8cece0d8ddf639da EXECUTABLE=false -8:PROOF="/root/evidence/771T_TEMP_HOSTKEY_NETBIRD_IDENTITY_THEN_CAPI_${TS}_PROOF.txt" -11:EDGE_SCRIPT_LOCAL="/root/771t_edge_capi_${TS}.sh" -12:EDGE_SCRIPT_REMOTE="/tmp/771t_edge_capi_${TS}.sh" -31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -33:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -50: echo "CHECK=crowdsec-capi" -56:force_no_capi_stable() { -62: DISABLE_ONLINE_API: "true" -63: ARGS: "-no-capi" -85:wait_lapi() { -87: echo "WAIT_LAPI=$label" -90: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -92: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -93: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -94: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -166: raise SystemExit("api.server block not found") -169: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771t_compose.yml || true -208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771t_compose.yml -217: timeout 15 ssh -n -o BatchMode=yes -o ConnectTimeout=8 -o StrictHostKeyChecking=accept-new "$TARGET_USER@$TARGET_NB" \ -218: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771t_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" >"$out" 2>&1 -236: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -238:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -245:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -246:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -D "${SOCKS_BIND}:${SOCKS_PORT}" -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -247:Restart=always -248:RestartSec=5 -254: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -258:base=/etc/homelab-crowdsec-capi-netbird-egress -266:systemctl restart homelab-crowdsec-capi-netbird-egress.service -267:systemctl restart privoxy 2>/dev/null || true -269:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -271: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -274: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -275: systemctl restart homelab-crowdsec-capi-netbird-egress.service -277: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -293: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -296: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -307:out.append("# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_BEGIN") -310:out.append("# HOMELAB_771T_CROWDSEC_CAPI_NETBIRD_END") -315: systemctl restart privoxy -320: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771t_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -321: trace="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)" -322: echo "HTTP_PROXY_CAPI_HTTP=$code" -329:register_capi() { -331: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -332: echo "REGISTER_CAPI proxy=$proxy_url" -334: force_no_capi_stable -335: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -339: if test -f config/online_api_credentials.yaml; then -340: mkdir -p /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-"$TS" -341: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771t-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -346: wait_lapi "REGISTER_MODE" || return 13 -351: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -352: timeout 240 cscli capi register -y >/tmp/771t_register.out 2>&1 -354: timeout 240 sh -c "yes | cscli capi register" >/tmp/771t_register.out 2>&1 -367: if ! test -f config/online_api_credentials.yaml; then -371: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -372: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -374: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -381: echo "VALIDATE_CAPI" -385: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -386: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -388: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -389: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -390: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -391: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -392: printf '%s\n' "$capi_out" -393: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -400: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -402: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -403: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771t_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -404: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771t_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -405: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771t_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -406: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -407: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -409: echo "FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}" -411: test "$rc_before" = "$rc_after" && test "$health_after" = "200" && test "${lapi_after:-NA}" = "0" && test "${capi_after:-NA}" = "0" && test "$fatal_after" = "0" && test -z "$env_after" -415:echo "STEP=771T_EDGE_CAPI_VIA_VERIFIED_NETBIRD_PEER" -418:systemctl restart netbird 2>/dev/null || true -KNOWN_SCRIPT=/root/771u_find_key_fix_netbird_egress_capi.sh SHA256=6b6511ec3d614793e3542777ccfcb5e8c5f09cff77ee2d57624b3ac980787bcb EXECUTABLE=false -8:PROOF="/root/evidence/771U_FIND_KEY_FIX_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt" -11:EDGE_REMOTE="/tmp/771u_edge_register_capi_${TS}.sh" -12:EDGE_LOCAL="/root/771u_edge_register_capi_${TS}.sh" -31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -33:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -52: echo "CHECK=crowdsec-capi" -58:force_no_capi_stable() { -64: DISABLE_ONLINE_API: "true" -65: ARGS: "-no-capi" -87:wait_lapi() { -89: echo "WAIT_LAPI=$label" -92: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -94: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -95: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -96: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -167: raise SystemExit("api.server block not found") -170: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -207: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771u_compose.yml || true -208: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771u_compose.yml -213: ssh-keygen -q -t ed25519 -N "" -C "homelab-crowdsec-capi-netbird-egress-edge" -f "$SSH_KEY" -227: timeout 15 ssh -n \ -234: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771u_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" >"$out" 2>&1 -253: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -255:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -262:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -263:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i "${SSH_KEY}" -D "${SOCKS_BIND}:${SOCKS_PORT}" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -264:Restart=always -265:RestartSec=5 -271: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -275:base=/etc/homelab-crowdsec-capi-netbird-egress -283:systemctl restart homelab-crowdsec-capi-netbird-egress.service -284:systemctl restart privoxy 2>/dev/null || true -286:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -288: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -291: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -292: systemctl restart homelab-crowdsec-capi-netbird-egress.service -294: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -310: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -313: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -324:out.append("# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_BEGIN") -327:out.append("# HOMELAB_771U_CROWDSEC_CAPI_NETBIRD_END") -332: systemctl restart privoxy -337: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771u_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -338: trace="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)" -339: echo "HTTP_PROXY_CAPI_HTTP=$code" -346:register_capi() { -348: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -349: echo "REGISTER_CAPI proxy=$proxy_url" -351: force_no_capi_stable -352: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -356: if test -f config/online_api_credentials.yaml; then -357: mkdir -p /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-"$TS" -358: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771u-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -363: wait_lapi "REGISTER_MODE" || return 13 -368: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -369: timeout 240 cscli capi register -y >/tmp/771u_register.out 2>&1 -371: timeout 240 sh -c "yes | cscli capi register" >/tmp/771u_register.out 2>&1 -384: if ! test -f config/online_api_credentials.yaml; then -388: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -389: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -391: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -398: echo "VALIDATE_CAPI" -402: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -403: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -405: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -406: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -407: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -408: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -409: printf '%s\n' "$capi_out" -410: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -417: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -419: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -420: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771u_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -421: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771u_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -422: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771u_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -423: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -424: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -426: echo "FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}" -428: test "$rc_before" = "$rc_after" && test "$health_after" = "200" && test "${lapi_after:-NA}" = "0" && test "${capi_after:-NA}" = "0" && test "$fatal_after" = "0" && test -z "$env_after" -432:echo "STEP=771U_EDGE_EGRESS_CAPI" -KNOWN_SCRIPT=/root/771v_deep_key_backup_netbird_capi.sh SHA256=92191ce6124981ee0468cc8f95c749c47bca5fc61f9aecaeedeef91cdd434170 EXECUTABLE=false -8:PROOF="/root/evidence/771V_DEEP_KEY_BACKUP_NETBIRD_CAPI_${TS}_PROOF.txt" -11:EDGE_LOCAL="/root/771v_edge_netbird_capi_${TS}.sh" -12:EDGE_REMOTE="/tmp/771v_edge_netbird_capi_${TS}.sh" -31:EGRESS_DIR=/etc/homelab-crowdsec-capi-netbird-egress -33:HEALTH_FILE="$HEALTH_DIR/crowdsec-capi.txt" -52: echo "CHECK=crowdsec-capi" -58:force_no_capi_stable() { -64: DISABLE_ONLINE_API: "true" -65: ARGS: "-no-capi" -87:wait_lapi() { -89: echo "WAIT_LAPI=$label" -92: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -94: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -95: fatal="$(docker logs --since 30s crowdsec 2>&1 | grep -Eic 'fatal|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed' || true)" -96: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA} FATAL_COUNT_30S=$fatal" -168: raise SystemExit("api.server block not found") -172: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -210: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|HTTP_PROXY|HTTPS_PROXY|NO_PROXY|socket-proxy|published:|target:' /tmp/771v_compose.yml || true -211: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771v_compose.yml -216: ssh-keygen -q -t ed25519 -N "" -C "homelab-crowdsec-capi-netbird-egress-edge" -f "$SSH_KEY" -230: timeout 15 ssh -n \ -237: "echo SSH_OK; hostname; curl -4 -sk --connect-timeout 8 --max-time 20 -o /tmp/771v_capi_direct.body -w 'DIRECT_CAPI_HTTP=%{http_code}\n' https://api.crowdsec.net/v3/watchers/login || true" >"$out" 2>&1 -256: cat >/etc/systemd/system/homelab-crowdsec-capi-netbird-egress.service <<'EOF' -258:Description=Homelab CrowdSec CAPI NetBird VPS SOCKS egress -265:EnvironmentFile=/etc/homelab-crowdsec-capi-netbird-egress/current.env -266:ExecStart=/bin/sh -lc 'exec /usr/bin/ssh -N -i "${SSH_KEY}" -D "${SOCKS_BIND}:${SOCKS_PORT}" -o IdentitiesOnly=yes -o BatchMode=yes -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o StrictHostKeyChecking=accept-new "${SSH_USER}@${SSH_HOST}"' -267:Restart=always -268:RestartSec=5 -274: cat >/usr/local/sbin/homelab-crowdsec-capi-egress-switch <<'EOF' -278:base=/etc/homelab-crowdsec-capi-netbird-egress -286:systemctl restart homelab-crowdsec-capi-netbird-egress.service -287:systemctl restart privoxy 2>/dev/null || true -289:systemctl --no-pager --full status homelab-crowdsec-capi-netbird-egress.service | sed -n '1,30p' -291: chmod 755 /usr/local/sbin/homelab-crowdsec-capi-egress-switch -294: systemctl enable --now homelab-crowdsec-capi-netbird-egress.service -295: systemctl restart homelab-crowdsec-capi-netbird-egress.service -297: systemctl is-active homelab-crowdsec-capi-netbird-egress.service || true -313: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "BEGIN" in line: -316: if "HOMELAB_771" in line and "CROWDSEC_CAPI" in line and "END" in line: -327:out.append("# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_BEGIN") -330:out.append("# HOMELAB_771V_CROWDSEC_CAPI_NETBIRD_END") -335: systemctl restart privoxy -340: code="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 -o /tmp/771v_http_proxy_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -341: trace="$(curl -sk --proxy "http://${b}:${HTTP_PROXY_PORT}" --connect-timeout 12 --max-time 45 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)" -342: echo "HTTP_PROXY_CAPI_HTTP=$code" -349:register_capi() { -351: proxy_url="http://${b}:${HTTP_PROXY_PORT}" -352: echo "REGISTER_CAPI proxy=$proxy_url" -354: force_no_capi_stable -355: wait_lapi "BEFORE_CAPI_REGISTER" || return 10 -359: if test -f config/online_api_credentials.yaml; then -360: mkdir -p /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-"$TS" -361: mv config/online_api_credentials.yaml /opt/stacks/crowdsec/manual-backups/771v-old-online-creds-"$TS"/online_api_credentials.yaml.before-register -366: wait_lapi "REGISTER_MODE" || return 13 -371: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -372: timeout 240 cscli capi register -y >/tmp/771v_register.out 2>&1 -374: timeout 240 sh -c "yes | cscli capi register" >/tmp/771v_register.out 2>&1 -387: if ! test -f config/online_api_credentials.yaml; then -391: stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -392: awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -394: grep -Eq '^[[:space:]]*login:' config/online_api_credentials.yaml || return 22 -401: echo "VALIDATE_CAPI" -405: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -406: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -408: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -409: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -410: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -411: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -412: printf '%s\n' "$capi_out" -413: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -420: rc_before="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -422: rc_after="$(docker inspect crowdsec --format '{{.RestartCount}}' 2>/dev/null || echo NA)" -423: health_after="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771v_health_after.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -424: lapi_after="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771v_lapi_after.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -425: capi_after="$(docker exec crowdsec sh -lc 'cscli capi status >/tmp/771v_capi_after.out 2>&1; echo CAPI_RC=$?' 2>/dev/null | awk -F= '/^CAPI_RC=/{print $2}' | tail -1 || true)" -426: fatal_after="$(docker logs --since 240s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml|proxyconnect tcp' || true)" -427: env_after="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -429: echo "FINAL_STABILITY RC_BEFORE=$rc_before RC_AFTER=$rc_after HEALTH_AFTER=$health_after LAPI_AFTER=${lapi_after:-NA} CAPI_AFTER=${capi_after:-NA} FATAL_AFTER=$fatal_after ENV_BAD_AFTER=${env_after:-NONE}" -431: test "$rc_before" = "$rc_after" && test "$health_after" = "200" && test "${lapi_after:-NA}" = "0" && test "${capi_after:-NA}" = "0" && test "$fatal_after" = "0" && test -z "$env_after" -435:echo "STEP=771V_EDGE_NETBIRD_EGRESS_CAPI" -KNOWN_SCRIPT=/root/771z_after_manual_netbird_egress_capi.sh SHA256=f198ed621fd726ed6f15c4a0dd49fad307befd01e7a58ebbda1ddc379f5b49ee EXECUTABLE=false -8:PROOF="/root/evidence/771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_${TS}_PROOF.txt" -14: echo "STEP=771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI" -17: echo "RULE=VERIFY_RELAY_MAIL_EGRESS_AND_REGISTER_CROWDSEC_CAPI" -21: ssh debian@$EDGE "sudo bash -s" <<'EDGE' -27:HEALTH=/var/lib/homelab-health/crowdsec-capi.txt -38: echo "CHECK=crowdsec-capi" -44:wait_lapi() { -46: echo "WAIT_LAPI=$label" -49: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -51: rc="$(printf '%s\n' "$out" | awk -F= '/^LAPI_RC=/{print $2}' | tail -1)" -52: echo "LAPI_TRY=$n HEALTH=$health LAPI_RC=${rc:-NA}" -59:force_no_capi() { -65: DISABLE_ONLINE_API: "true" -66: ARGS: "-no-capi" -87:enable_capi_compose() { -112: grep -nE 'DISABLE_ONLINE_API|ARGS|GODEBUG|socket-proxy|published:|target:' /tmp/771z_compose.yml || true -113: ! grep -qE 'DISABLE_ONLINE_API|ARGS:.*no-capi|-no-capi' /tmp/771z_compose.yml -180: raise SystemExit("api.server block not found") -183: " credentials_path: /etc/crowdsec/online_api_credentials.yaml", -194:echo "NETBIRD_RESTART" -195:systemctl restart netbird 2>/dev/null || true -199:netbird status 2>&1 | redact || true -202:netbird status --json >/tmp/771z_nb.json 2>/tmp/771z_nb.err || true -229:echo "CAPI_DIRECT_TEST_AFTER_MANUAL_NETBIRD" -230:capi_code="$(curl -4 -sk --http1.1 --connect-timeout 12 --max-time 45 -o /tmp/771z_capi.body -w '%{http_code}' https://api.crowdsec.net/v3/watchers/login || true)" -231:trace="$(curl -4 -sk --connect-timeout 12 --max-time 30 https://www.cloudflare.com/cdn-cgi/trace 2>/dev/null | grep -E 'ip=|colo=' | sed -n '1,6p' || true)" -232:echo "CAPI_DIRECT_HTTP=$capi_code" -237:if test "$capi_code" = "000"; then -238: force_no_capi -239: wait_lapi "CAPI_ROUTE_NOT_READY_SAFE" || true -240: write_health "REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY" "After manual NetBird setup, edge still cannot reach api.crowdsec.net; CrowdSec remains LAPI-only no-capi" -241: echo "EDGE_STATUS=REVIEW_MANUAL_NETBIRD_EGRESS_NOT_READY_CAPI_NOT_DONE" -246:echo "CAPI_ROUTE_READY_REGISTER_NOW" -248:mkdir -p "manual-backups/771z-$TS" -249:test -f config/config.yaml && cp -a config/config.yaml "manual-backups/771z-$TS/config.yaml.before" || true -250:test -f config/user.yaml && cp -a config/user.yaml "manual-backups/771z-$TS/user.yaml.before" || true -251:test -f config/online_api_credentials.yaml && mv config/online_api_credentials.yaml "manual-backups/771z-$TS/online_api_credentials.yaml.before" || true -254:enable_capi_compose || { -255: force_no_capi -256: wait_lapi "COMPOSE_FAIL_SAFE" || true -257: write_health "REVIEW_CAPI_COMPOSE_ENABLE_FAILED" "Direct CAPI route works, but compose CAPI enable failed" -262:wait_lapi "REGISTER_MODE" || exit 73 -266: if cscli capi register --help 2>&1 | grep -q -- "-y"; then -267: timeout 240 cscli capi register -y >/tmp/771z_register.out 2>&1 -269: timeout 240 sh -c "yes | cscli capi register" >/tmp/771z_register.out 2>&1 -281:if test "${reg_rc:-NA}" != "0" || ! test -f config/online_api_credentials.yaml; then -282: force_no_capi -283: wait_lapi "REGISTER_FAIL_SAFE" || true -284: write_health "REVIEW_CAPI_ROUTE_READY_BUT_REGISTER_FAILED" "Direct CAPI route works, but cscli capi register failed; restored no-capi" -285: echo "EDGE_STATUS=REVIEW_CAPI_REGISTER_FAILED_NOT_DONE" -290:stat -c 'ONLINE_CREDS path=%n mode=%a owner=%U group=%G size=%s' config/online_api_credentials.yaml || true -291:awk -F: '/^[A-Za-z0-9_ -]+:/ {gsub(/^[ \t]+|[ \t]+$/, "", $1); print $1 ": REDACTED"}' config/online_api_credentials.yaml | sed -n '1,40p' -294:enable_capi_compose || exit 75 -300: health="$(curl -sk --connect-timeout 3 --max-time 6 -o /tmp/771z_health2.html -w '%{http_code}' http://[PRIVATE_IP]:8088/health || true)" -301: lapi_rc="$(docker exec crowdsec sh -lc 'cscli lapi status >/tmp/771z_lapi2.out 2>&1; echo LAPI_RC=$?' 2>/dev/null | awk -F= '/^LAPI_RC=/{print $2}' | tail -1 || true)" -303: capi_rc="$(printf '%s\n' "$capi_out" | awk -F= '/^CAPI_RC=/{print $2}' | tail -1)" -304: fatal="$(docker logs --since 60s crowdsec 2>&1 | grep -Eic 'fatal|TLS handshake timeout|unable to run local API|failed to get docker info|lookup socket-proxy|server misbehaving|mapping value is not allowed|missing credentials field|open /etc/crowdsec/online_api_credentials.yaml' || true)" -305: envbad="$(docker inspect crowdsec --format '{{range .Config.Env}}{{println .}}{{end}}' 2>/dev/null | grep -E 'DISABLE_ONLINE_API|ARGS=.*no-capi|-no-capi' || true)" -306: echo "VALIDATE_TRY=$n HEALTH=$health LAPI_RC=${lapi_rc:-NA} CAPI_RC=${capi_rc:-NA} FATAL=$fatal ENV_BAD=${envbad:-NONE}" -307: printf '%s\n' "$capi_out" -308: if test "$health" = "200" && test "${lapi_rc:-NA}" = "0" && test "${capi_rc:-NA}" = "0" && test "$fatal" = "0" && test -z "$envbad"; then -315: write_health "OK_CAPI_REGISTERED_ENABLED_STABLE_MANUAL_NETBIRD_EGRESS" "CrowdSec CAPI registered and stable after manual NetBird egress via relay/mail" -316: echo "EDGE_STATUS=OK_CROWDSEC_CAPI_100_PERCENT_REGISTERED_ENABLED_STABLE" -321:force_no_capi -322:wait_lapi "VALIDATION_FAIL_SAFE" || true -323:write_health "REVIEW_CAPI_REGISTERED_BUT_NOT_STABLE_RESTORED_NO_CAPI" "CAPI registration happened but stability validation failed; restored no-capi" -324:echo "EDGE_STATUS=REVIEW_CAPI_NOT_STABLE_RESTORED_NO_CAPI" -331: code=$(curl -sk --connect-timeout 8 --max-time 20 --resolve "$h:443:$EDGE" -o "/tmp/771z_$h.html" -w "%{http_code}" "https://$h/" || true) -337: echo STATUS=OK_771Z_AFTER_MANUAL_NETBIRD_EGRESS_CAPI_DONE -KNOWN_771_SAFE_STATIC_END=1 -POLICY_DOCS_BEGIN=1 -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5 -1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD -9:NetBird: -14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures. -16:Current: -17:`/usr/local/sbin/pvepro-relay-healthcheck` -27:- new NetBird TCP 80/443 -37:`PASS_RELAY_HEALTHCHECK_OK` -40:enabled/active. -48:Old USA observer had been converted to Gotify-only before retirement. -50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon. -78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf` -86:- timer active -89:Rollback backup: -92:Old USA observer then: -93:- backup created -95:- service inactive -96:- 80-second freeze proved no further health-file updates -98:- old NetBird server still stopped -99:- old host NetBird client still connected -100:- Moldova peer reachable -102:Old observer backup: -103:`/root/retired-homelab-dr-observer-20260818T221046Z` -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552 -1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD -5:Old USA mail/NetBird VPS: -7:- secondary NetBird IPv4 `[PRIVATE_IP]` -10:Old NetBird server stack stopped after successful migration. -11:Host-level NetBird client left running for rollback/peer observation. -33:NetBird: -36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`. -56:- Moldova synthetic check passes -59:Important health discovery: -60:- `/api/health` 404 on exact deployed version -61:- `:9000/health` 503 in combined relay/server mode -62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy -65:Backups on new server include migration/cutover snapshots such as: -66:`/root/netbird-cutover-20260818T145807Z` -69:- upgrade NetBird -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af -1:# CRITICAL KEEP / RETIRE DECISIONS -3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof. -11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore | -12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect | -16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup | -18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first | -19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties | -20:| Moldova relay | KEEP | independent relay/external health | -21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII | -24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement | -27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active | -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/22_MOLDOVA_HEALTHCHECK_GOTIFY_2026-08-18.md SHA256=fe0f5ca63837626583d150e8c4b9ce9c795832ae4f59af25369a00fa7825fdb5 -1:# MOLDOVA HEALTHCHECK V3 / GOTIFY NOTIFIER — CURRENT RECORD -9:NetBird: -14:Old checker referenced retired Mailcow/old NetBird IP and caused false failures. -16:Current: -17:`/usr/local/sbin/pvepro-relay-healthcheck` -27:- new NetBird TCP 80/443 -37:`PASS_RELAY_HEALTHCHECK_OK` -40:enabled/active. -48:Old USA observer had been converted to Gotify-only before retirement. -50:Moldova direct public DNS for `gotify.gram1.ru` is not relied upon. -78:`/etc/systemd/system/pvepro-relay-healthcheck.service.d/20-gotify-notifier.conf` -86:- timer active -89:Rollback backup: -92:Old USA observer then: -93:- backup created -95:- service inactive -96:- 80-second freeze proved no further health-file updates -98:- old NetBird server still stopped -99:- old host NetBird client still connected -100:- Moldova peer reachable -102:Old observer backup: -103:`/root/retired-homelab-dr-observer-20260818T221046Z` -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/20_NETBIRD_USA_MIGRATION_2026-08-18.md SHA256=12fe079849346352315aac76fae82d00cbd17f88a3553270ca2c5f2749840552 -1:# NETBIRD USA MIGRATION — FINAL CURRENT RECORD -5:Old USA mail/NetBird VPS: -7:- secondary NetBird IPv4 `[PRIVATE_IP]` -10:Old NetBird server stack stopped after successful migration. -11:Host-level NetBird client left running for rollback/peer observation. -33:NetBird: -36:Compose bind changed only from old NetBird secondary public IP to new `[PRIVATE_IP]`. -56:- Moldova synthetic check passes -59:Important health discovery: -60:- `/api/health` 404 on exact deployed version -61:- `:9000/health` 503 in combined relay/server mode -62:- first rollback was triggered by incorrectly assuming this endpoint must be healthy -65:Backups on new server include migration/cutover snapshots such as: -66:`/root/netbird-cutover-20260818T145807Z` -69:- upgrade NetBird -POLICY_DOC=/root/_2/workers2-cr0108-final-of79_umj/FINAL_HANDOFF/repo/kb/private/archive/2026-08-19/docs/15_CRITICAL_KEEP_RETIRE_DECISIONS.md SHA256=ad3ea70345063e8a13608a83acb4d6a1118533eb6acab22929e0bf1ac20c06af -1:# CRITICAL KEEP / RETIRE DECISIONS -3:This is a convenience matrix distilled from the historical handbook plus current state. A RETIRE label is not authorization to delete without fresh proof. -11:| VM9130 edge-cold-standby | KEEP UNTIL DR PROOF | do not delete before timed VM130 restore | -12:| VM150 Snikket | KEEP/CLOSED | do not reopen destructive rebuild without new defect | -16:| VM180 cluster-admin | historical future RETIRE candidate | only after dependency/backup/monitoring cleanup | -18:| CT200 skladchik-mod | historical future RETIRE candidate | preserve required data/monitoring first | -19:| public edge01 | KEEP/CRITICAL | current git-read V3 and public edge duties | -20:| Moldova relay | KEEP | independent relay/external health | -21:| USA mail/NetBird | KEEP | infra mail/monitoring/no-PII | -24:| pve01 18788 | KEEP NOW | reader-v3, usage proof before retirement | -27:| Cloud.ru prepared bucket | KEEP PREPARED | real backup workload not yet active | -POLICY_DOCS_END=1 -CONTROL_UNIT_REFERENCES_BEGIN=1 -CONTROL_UNIT_REFERENCES_END=1 -DECISION=PASS_BACKUP_1123_NO_EXTERNAL_PROVIDER_CONTROL_PATH_PROVEN -NEXT_GATE=RETIRE_US_NETBIRD_TARGET_FROM_ACTIVE_BACKUPV2_POLICY_THEN_COMBINED_REPAIR -TASK_RESULT=PASS_HOMELAB_BACKUP_MOLDOVA_CONTROL_RCA -CHANGES_MADE_BY_1123=false -PRODUCT_MUTATION_BY_1123=false -VM_MUTATION_BY_1123=false -CLOUD_MUTATION_BY_1123=false -HOMELAB_RESULT_CONTRACT={"version":1,"command_id":"SUPPORT-260922-HOMELAB-BACKUP-MOLDOVA-CONTROL-RCA-1123R1","status":"OK","changes_made":false,"rollback_started":false,"rollback_restored":null} -WORKERS2_BACKUP_MOLDOVA_CONTROL_RCA_END=1 +GENERATED_AT_UTC=[PRIVATE_IP]T09:17:01Z +Cluster information +------------------- +Name: homelab +Config Version: 3 +Transport: knet +Secure auth: on +Quorum information +------------------ +Date: Tue Sep [PRIVATE_IP] 2026 +Quorum provider: corosync_votequorum +Nodes: 3 +Node ID: [PRIVATE_IP] +Ring ID: 1.130 +Quorate: Yes + +Votequorum information +---------------------- +Expected votes: 3 +Highest expected: 3 +Total votes: 3 +Quorum: 2 +Flags: Quorate + +Membership information +---------------------- + Nodeid Votes Name +[PRIVATE_IP] [PRIVATE_IP].11 (local) +[PRIVATE_IP] [PRIVATE_IP].13 +[PRIVATE_IP] [PRIVATE_IP].12 + +Membership information +---------------------- + Nodeid Votes Name + 1 1 pve01 (local) + 2 1 pve03 + 3 1 pve02 +[{"cpu":[PRIVATE_IP]676692,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/100","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"pvepro-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":202588,"vmid":100},{"cpu":0,"disk":0,"diskread":0,"diskwrite":0,"id":"qemu/101","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":0,"memhost":0,"name":"pvepro-staging-v1","netin":0,"netout":0,"node":"pve01","status":"stopped","template":0,"type":"qemu","uptime":0,"vmid":101},{"cpu":[PRIVATE_IP][PRIVATE_IP],"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/110","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"dns1","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":110},{"cpu":[PRIVATE_IP]313741,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/111","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"dns2","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":111},{"cpu":[PRIVATE_IP]242e-05,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/112","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"unbound1","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":112},{"cpu":0,"disk":[PRIVATE_IP],"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"lxc/113","maxcpu":1,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":0,"name":"unbound2","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"lxc","uptime":[PRIVATE_IP],"vmid":113},{"cpu":[PRIVATE_IP]99279,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/130","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"edge-vm","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":130},{"cpu":[PRIVATE_IP]30577,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/150","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"snikket","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":150},{"cpu":[PRIVATE_IP]520399,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/160","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"forum-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve02","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":160},{"cpu":[PRIVATE_IP]9061,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/170","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"core-apps","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":170},{"cpu":[PRIVATE_IP]17419,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/171","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"monitoring","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":171},{"cpu":[PRIVATE_IP]574775,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/190","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"homelab-ops-worker","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":190},{"cpu":[PRIVATE_IP]245615,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/210","maxcpu":2,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"newfi-prod","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve01","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":210},{"cpu":[PRIVATE_IP]556756,"disk":0,"diskread":[PRIVATE_IP],"diskwrite":[PRIVATE_IP],"id":"qemu/211","maxcpu":2,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"memhost":[PRIVATE_IP],"name":"newfi-staging","netin":[PRIVATE_IP],"netout":[PRIVATE_IP],"node":"pve03","status":"running","template":0,"type":"qemu","uptime":[PRIVATE_IP],"vmid":211},{"cpu":0,"disk":0,"diskread":0,"diskwrite":0,"id":"qemu/9130","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":0,"memhost":0,"name":"edge-cold-standby","netin":0,"netout":0,"node":"pve02","status":"stopped","template":0,"type":"qemu","uptime":0,"vmid":9130},{"cgroup-mode":2,"cpu":[PRIVATE_IP]49907,"disk":[PRIVATE_IP],"id":"node/pve03","level":"","maxcpu":8,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve03","status":"online","type":"node","uptime":[PRIVATE_IP]},{"cgroup-mode":2,"cpu":[PRIVATE_IP]9249,"disk":[PRIVATE_IP],"id":"node/pve02","level":"","maxcpu":4,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve02","status":"online","type":"node","uptime":[PRIVATE_IP]},{"cgroup-mode":2,"cpu":[PRIVATE_IP]61285,"disk":[PRIVATE_IP],"id":"node/pve01","level":"","maxcpu":24,"maxdisk":[PRIVATE_IP],"maxmem":[PRIVATE_IP],"mem":[PRIVATE_IP],"node":"pve01","status":"online","type":"node","uptime":[PRIVATE_IP]},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve03/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve03","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve02/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve02","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"images,rootdir","disk":[PRIVATE_IP],"id":"storage/pve01/local-lvm","maxdisk":[PRIVATE_IP],"node":"pve01","plugintype":"lvmthin","shared":0,"status":"available","storage":"local-lvm","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve03/local","maxdisk":[PRIVATE_IP],"node":"pve03","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve02/local","maxdisk":[PRIVATE_IP],"node":"pve02","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"content":"backup,import,iso,vztmpl","disk":[PRIVATE_IP],"id":"storage/pve01/local","maxdisk":[PRIVATE_IP],"node":"pve01","plugintype":"dir","shared":0,"status":"available","storage":"local","type":"storage"},{"id":"network/pve03/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve03","status":"ok","type":"network"},{"id":"network/pve02/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve02","status":"ok","type":"network"},{"id":"network/pve01/zone/localnetwork","network":"localnetwork","network-type":"zone","node":"pve01","status":"ok","type":"network"}] +Name Type Status Total (KiB) Used (KiB) Available (KiB) % +local dir active [PRIVATE_IP] [PRIVATE_IP] [PRIVATE_IP] 37.35% +local-lvm lvmthin active [PRIVATE_IP] [PRIVATE_IP] [PRIVATE_IP] 15.68% + UNIT LOAD ACTIVE SUB DESCRIPTION +● homelab-backup-audit.service loaded failed failed Homelab unified backup and DR audit +● netbird-peers-health.service loaded failed failed NetBird peers health check +● skladchik-reports-monitor-supervisor.service loaded failed failed Skladchik reports monitor full supervisor + +Legend: LOAD → Reflects whether the unit definition was properly loaded. + ACTIVE → The high-level unit activation state, i.e. generalization of SUB. + SUB → The low-level unit activation state, values depend on unit type. + +3 loaded units listed. +NEXT LEFT LAST PASSED UNIT ACTIVATES +Tue [PRIVATE_IP] 12:17:36 MSK 33s Tue [PRIVATE_IP] 12:16:35 MSK 26s ago homelab-router-watchdog.timer homelab-router-watchdog.service +Tue [PRIVATE_IP] 12:17:59 MSK 56s Tue [PRIVATE_IP] 12:16:59 MSK 3s ago homelab-private-vpn-hosts-health.timer homelab-private-vpn-hosts-health.service +Tue [PRIVATE_IP] 12:17:59 MSK 56s Tue [PRIVATE_IP] 12:12:59 MSK 4min 3s ago homelab-smartctl-textfile.timer homelab-smartctl-textfile.service +Tue [PRIVATE_IP] 12:18:16 MSK 1min 13s Tue [PRIVATE_IP] 12:13:16 MSK 3min 46s ago netbird-peers-health.timer netbird-peers-health.service +Tue [PRIVATE_IP] 12:21:50 MSK 4min 47s Tue [PRIVATE_IP] 12:16:32 MSK 30s ago homelab-health-metrics.timer homelab-health-metrics.service +Tue [PRIVATE_IP] 12:22:16 MSK 5min Tue [PRIVATE_IP] 12:07:16 MSK 9min ago prometheus-node-exporter-apt.timer prometheus-node-exporter-apt.service +Tue [PRIVATE_IP] 12:22:32 MSK 5min Tue [PRIVATE_IP] 12:12:32 MSK 4min 30s ago skladchik-reports-monitor-supervisor.timer skladchik-reports-monitor-supervisor.service +Tue [PRIVATE_IP] 12:23:15 MSK 6min Tue [PRIVATE_IP] 11:44:22 MSK 32min ago homelab-backup-v2.timer homelab-backup-v2.service +Tue [PRIVATE_IP] 12:28:37 MSK 11min Tue [PRIVATE_IP] 12:13:37 MSK 3min 25s ago homelab-disk-space-health.timer homelab-disk-space-health.service +Tue [PRIVATE_IP] 12:28:37 MSK 11min Tue [PRIVATE_IP] 12:13:37 MSK 3min 25s ago prometheus-node-exporter-nvme.timer prometheus-node-exporter-nvme.service +Tue [PRIVATE_IP] 12:29:22 MSK 12min Tue [PRIVATE_IP] 12:13:59 MSK 3min 3s ago homelab-alertmanager-backup-health.timer homelab-alertmanager-backup-health.service +Tue [PRIVATE_IP] 12:30:00 MSK 12min Tue [PRIVATE_IP] 12:15:15 MSK 1min 47s ago homelab-incident-journal.timer homelab-incident-journal.service +Tue [PRIVATE_IP] 12:30:10 MSK 13min Tue [PRIVATE_IP] 12:15:58 MSK 1min 4s ago homelab-forum-snuffleupagus-health.timer homelab-forum-snuffleupagus-health.service +Tue [PRIVATE_IP] 12:30:15 MSK 13min Tue [PRIVATE_IP] 12:16:32 MSK 30s ago homelab-duty-admin-v2.timer homelab-duty-admin-v2.service +Tue [PRIVATE_IP] 12:30:50 MSK 13min Tue [PRIVATE_IP] 12:16:04 MSK 57s ago homelab-external-probe-vps-health.timer homelab-external-probe-vps-health.service +Tue [PRIVATE_IP] 12:30:58 MSK 13min Tue [PRIVATE_IP] 12:15:58 MSK 1min 4s ago homelab-pve03-staging-capacity-health.timer homelab-pve03-staging-capacity-health.service +Tue [PRIVATE_IP] 12:31:26 MSK 14min Tue [PRIVATE_IP] 12:02:16 MSK 14min ago homelab-mkdocs-auto-refresh.timer homelab-mkdocs-auto-refresh.service +Tue [PRIVATE_IP] 12:35:19 MSK 18min Tue [PRIVATE_IP] 12:05:58 MSK 11min ago homelab-backup-audit.timer homelab-backup-audit.service +Tue [PRIVATE_IP] 12:44:48 MSK 27min Tue [PRIVATE_IP] 12:11:32 MSK 5min ago homelab-reference-refresh.timer homelab-reference-refresh.service +Tue [PRIVATE_IP] 13:16:26 MSK 59min Tue [PRIVATE_IP] 07:09:07 MSK 5h 7min ago homelab-evidence-root.timer homelab-evidence-root.service +Tue [PRIVATE_IP] 13:30:00 MSK 1h 12min Tue [PRIVATE_IP] 11:30:02 MSK 47min ago homelab-app-cloud-quorum-queue.timer homelab-app-cloud-quorum-queue.service +Tue [PRIVATE_IP] 14:44:55 MSK 2h 27min Tue [PRIVATE_IP] 08:42:59 MSK 3h 34min ago homelab-mailru-trash-gc.timer homelab-mailru-trash-gc.service +Tue [PRIVATE_IP] 16:35:59 MSK 4h 18min Tue [PRIVATE_IP] 10:35:59 MSK 1h 41min ago homelab-vps-identity-audit.timer homelab-vps-identity-audit.service +Tue [PRIVATE_IP] 16:47:58 MSK 4h 30min Mon [PRIVATE_IP] 16:47:58 MSK 19h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Tue [PRIVATE_IP] 17:40:23 MSK 5h 23min Mon [PRIVATE_IP] 19:10:54 MSK 17h ago apt-daily.timer apt-daily.service +Wed [PRIVATE_IP] 00:00:00 MSK 11h Tue [PRIVATE_IP] 00:00:15 MSK 12h ago dpkg-db-backup.timer dpkg-db-backup.service +Wed [PRIVATE_IP] 00:04:00 MSK 11h Tue [PRIVATE_IP] 00:14:16 MSK 12h ago homelab-docker-health.timer homelab-docker-health.service +Wed [PRIVATE_IP] 00:05:26 MSK 11h Tue [PRIVATE_IP] 00:01:16 MSK 12h ago homelab-evidence-catalog.timer homelab-evidence-catalog.service +Wed [PRIVATE_IP] 00:09:18 MSK 11h Tue [PRIVATE_IP] 00:11:58 MSK 12h ago homelab-quality-gate.timer homelab-quality-gate.service +Wed [PRIVATE_IP] 00:11:10 MSK 11h Tue [PRIVATE_IP] 00:13:45 MSK 12h ago homelab-storage-capacity.timer homelab-storage-capacity.service +Wed [PRIVATE_IP] 00:23:23 MSK 12h Tue [PRIVATE_IP] 00:17:32 MSK 11h ago logrotate.timer logrotate.service +Wed [PRIVATE_IP] 01:43:37 MSK 13h Tue [PRIVATE_IP] 01:58:53 MSK 10h ago pve-daily-update.timer pve-daily-update.service +Wed [PRIVATE_IP] 03:23:23 MSK 15h Tue [PRIVATE_IP] 03:23:32 MSK 8h ago homelab-backup-retention-gc.timer homelab-backup-retention-gc.service +Wed [PRIVATE_IP] 06:05:55 MSK 17h Tue [PRIVATE_IP] 06:01:58 MSK 6h ago apt-daily-upgrade.timer apt-daily-upgrade.service +Wed [PRIVATE_IP] 07:00:09 MSK 18h Tue [PRIVATE_IP] 07:05:52 MSK 5h 11min ago homelab-drift-check.timer homelab-drift-check.service +Wed [PRIVATE_IP] 07:37:32 MSK 19h Tue [PRIVATE_IP] 07:32:58 MSK 4h 44min ago homelab-service-registry-check.timer homelab-service-registry-check.service +Wed [PRIVATE_IP] 07:41:08 MSK 19h Tue [PRIVATE_IP] 07:55:16 MSK 4h 21min ago homelab-dependency-map-check.timer homelab-dependency-map-check.service +Wed [PRIVATE_IP] 07:45:08 MSK 19h Tue [PRIVATE_IP] 07:53:32 MSK 4h 23min ago homelab-alerting-health.timer homelab-alerting-health.service +Wed [PRIVATE_IP] 07:49:54 MSK 19h Tue [PRIVATE_IP] 07:52:16 MSK 4h 24min ago homelab-runbook-generate.timer homelab-runbook-generate.service +Wed [PRIVATE_IP] 07:54:04 MSK 19h Tue [PRIVATE_IP] 08:00:58 MSK 4h 16min ago homelab-desired-state-sync.timer homelab-desired-state-sync.service +Wed [PRIVATE_IP] 08:06:21 MSK 19h Tue [PRIVATE_IP] 08:01:32 MSK 4h 15min ago homelab-duty-admin-report.timer homelab-duty-admin-report.service +Wed [PRIVATE_IP] 08:13:48 MSK 19h Tue [PRIVATE_IP] 08:11:58 MSK 4h 5min ago homelab-overall-health.timer homelab-overall-health.service +Wed [PRIVATE_IP] 08:16:23 MSK 19h Tue [PRIVATE_IP] 08:12:58 MSK 4h 4min ago homelab-kuma-monitor-policy.timer homelab-kuma-monitor-policy.service +Wed [PRIVATE_IP] 08:18:31 MSK 20h Tue [PRIVATE_IP] 08:19:32 MSK 3h 57min ago homelab-final-readiness-gate.timer homelab-final-readiness-gate.service +Wed [PRIVATE_IP] 08:39:26 MSK 20h Tue [PRIVATE_IP] 08:28:45 MSK 3h 48min ago homelab-capacity-risk.timer homelab-capacity-risk.service +Wed [PRIVATE_IP] 08:40:06 MSK 20h Tue [PRIVATE_IP] 08:43:32 MSK 3h 33min ago homelab-secret-exposure-guard.timer homelab-secret-exposure-guard.service +Wed [PRIVATE_IP] 08:48:42 MSK 20h Tue [PRIVATE_IP] 08:51:11 MSK 3h 25min ago homelab-cluster-passport.timer homelab-cluster-passport.service +Wed [PRIVATE_IP] 08:49:21 MSK 20h Tue [PRIVATE_IP] 09:01:45 MSK 3h 15min ago homelab-golden-state-index.timer homelab-golden-state-index.service +Wed [PRIVATE_IP] 10:15:00 MSK 21h Tue [PRIVATE_IP] 10:15:00 MSK 2h 2min ago skladchik-reports-monitor-monthly-selftest-watch.timer skladchik-reports-monitor-monthly-selftest-watch.service +Wed [PRIVATE_IP] 11:04:23 MSK 22h Tue [PRIVATE_IP] 08:22:45 MSK 3h 54min ago man-db.timer man-db.service +Sun [PRIVATE_IP] 03:10:02 MSK 4 days Sun [PRIVATE_IP] 03:10:58 MSK 2 days ago xfs_scrub_all.timer xfs_scrub_all.service +Sun [PRIVATE_IP] 03:10:39 MSK 4 days Sun [PRIVATE_IP] 03:10:12 MSK 2 days ago e2scrub_all.timer e2scrub_all.service +Sun [PRIVATE_IP] 06:43:52 MSK 4 days Sun [PRIVATE_IP] 07:40:22 MSK 2 days ago homelab-rotating-boot-drill.timer homelab-rotating-boot-drill.service +Mon [PRIVATE_IP] 00:01:03 MSK 5 days Mon [PRIVATE_IP] 00:04:44 MSK 1 day 12h ago homelab-secret-sanity.timer homelab-secret-sanity.service +Mon [PRIVATE_IP] 00:15:22 MSK 5 days Mon [PRIVATE_IP] 00:09:14 MSK 1 day 12h ago fstrim.timer fstrim.service +- - - - prometheus-node-exporter-ipmitool-sensor.timer prometheus-node-exporter-ipmitool-sensor.service +- - - - prometheus-node-exporter-mellanox-hca-temp.timer prometheus-node-exporter-mellanox-hca-temp.service +- - - - prometheus-node-exporter-smartmon.timer prometheus-node-exporter-smartmon.service + +58 timers listed. +RUNTIME_MANIFEST_ID=df[PRIVATE_IP]ac9b5abd[PRIVATE_IP]b[PRIVATE_IP]d89496fb2bde[PRIVATE_IP] +EXPERIMENT_ID=5462ee[PRIVATE_IP]ebe[PRIVATE_IP]feb2ad[PRIVATE_IP]1ad87bbac0b8108 +COLLECTION_START_AT=[PRIVATE_IP]T[PRIVATE_IP]:00 +FIRST_COMPLETE_D1_CLOSE=[PRIVATE_IP]T[PRIVATE_IP]:00 +PRODUCTION_LAUNCH_ALLOWED=False +EXECUTION_AUTHORITY=False +RISK_AUTHORITY=False +STAGE_A_HEALTH=AWAITING_PRIMARY_FINALITY +FORENSIC_PREVIOUS_EPOCH_PRESERVED=YES + +## NEWFI_TASK6_AUTH_CHECKPOINT_V[PRIVATE_IP] +- Scope: historical accepted AUTH test, not a current SMTP connection test. +- Newfi approved SMTP account/sender: aleisaev@yandex.ru. +- Endpoint used by accepted test: smtp.yandex.ru:465 with certificate verification; single PLAIN initial response accepted with code 235. +- Evidence: incident ledger ### NEWFI_TASK6_YANDEX_AUTH_V2_OBSERVATION and ### NEWFI_TASK6_AUTH_PROOF_CLOSE_V1. +- No password file written, no application configuration changed, no mail sent by the accepted AUTH test. +- Persistent transport installation and application delivery are not proven by this checkpoint. Task6 is not complete. +- AUTH challenge and missing-file incidents closed; launch/session incident remains OPEN with original cause unproven. +- This update does not change VM211, VM160, routing, board state or Git. +- Other incidents and infrastructure health were not assessed. + + +## NEWFI_PRIVATE_STRUCTURE92_WRONG_MARKER_SCOPE_[PRIVATE_IP] CLOSURE +- Status: CLOSED +- RCA: NEWFI92 inspected the pve01 NEWFI90 attempt marker, which had not been finalized because the outer shell exited immediately after the guest returned RC3 following its successful rollback. The guest marker contained the true final rollback state. +- Correction: NEWFI93 required both the guest FINISHED/ROLLED_BACK record and a fresh exact demo-state readback before reconciling the outer NEWFI90 marker. NEWFI92 itself never reserved an attempt or mutated state. + + +## NEWFI_PRIVATE_NEWFI95_NESTED_TRIPLE_QUOTE_PARSE_[PRIVATE_IP] +- Status: OPEN +- Command: NEWFI95 +- Symptom: after the content-structure precheck passed, the pve03 Python wrapper failed to parse at the PHP line beginning with $root. No Portal discovery or application mutation was reached. +- RCA: an outer raw triple-single-quoted guest Python payload contained an inner raw triple-single-quoted PHP payload. The inner delimiter terminated the outer Python string, causing PHP source to be parsed as Python. +- Safety: NEWFI95 was read-only, created no attempt marker, and did not reach the intended nested guest execution. Do not replay NEWFI95. + + +## NEWFI_PRIVATE_NEWFI95_NESTED_TRIPLE_QUOTE_PARSE_[PRIVATE_IP] CLOSURE +- Status: CLOSED +- RCA: an inner triple-single-quoted PHP literal terminated the outer triple-single-quoted Python guest payload in NEWFI95. The wrapper therefore failed parsing before the intended Portal discovery executed. +- Correction: NEWFI96 removed the nested Python payload layer entirely and passed one Python program directly to VM211 through qm guest exec stdin. The read-only Portal contract completed with QGA exit 0 and the implementation worktree remained unchanged. OUTPUT_END CHAT_OUTPUT_END