1
0
Files
homelab-public-context/runtime/latest.json
T
2026-09-08 08:40:38 +00:00

39 lines
73 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"schema_version": 1,
"channel": "homelab-runtime",
"command_id": "NEWFI-260908-A-STAGINGEDGE-VPS-FRONTEND-DISCOVERY6",
"status": "OK",
"rc": 0,
"host": "pve01",
"mode": "read-only",
"component": "newfi-staging-vps-frontend-access-discovery-readonly",
"started_at_utc": "2026-09-08T08:40:34Z",
"finished_at_utc": "2026-09-08T08:40:38Z",
"reference_register_checked": true,
"reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66",
"error_register_checked": true,
"error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0",
"command_sha256": "2ad58afd2cf7e1cc3a231fb3ac9b55b4f697d78841c53df32e5263b1c183c524",
"duplicate_failed_command_blocked": false,
"block_reason": null,
"execution_started": true,
"change_declared": false,
"result_contract_valid": true,
"result_contract_status": null,
"result_contract_error": null,
"command_rc": 0,
"changes_made": false,
"rollback_started": false,
"rollback_restored": null,
"mutation_outcome": "NO_MUTATION",
"sanitized": true,
"secrets_included": false,
"private_addresses_included": false,
"raw_evidence_retained_locally": true,
"raw_evidence_sha256": "284d281515727ed750fef17eede5cf72d87468c30b4ab1e2c5458a1dcc30e5b0",
"sanitized_output_sha256": "ab2cb2f4b1af09a6375abf6422ab4ce673bec87b1cb30e0c610e68776b23f81e",
"output_truncated_in_json": false,
"full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt",
"output": "VPS_FRONTEND_DISCOVERY6_BEGIN=true\nCOMMAND_ID=NEWFI-260908-A-STAGINGEDGE-VPS-FRONTEND-DISCOVERY6\nMODE=read-only\nMUTATIONS_PERFORMED=NO\nERROR_REGISTER_CHECK=OK\nERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0\nREFERENCE_CHECK=OK\nREFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66\nAUTHORITY_CHECK_SCOPE=READABILITY_ONLY_INCIDENTS_NOT_CLOSED\nRUNNER_SHA256=b248a4c32c9cc64e5747e7dce6c7fc0a23f5124a77c71ce72e27a81aceae9d2d\nRUNNER_SHA_GATE=PASS\nPRIOR_APPLY14_GATE=PASS\nPRIOR_APPLY14_HISTORY_SHA256=774ea70f504928e020983f4da32ac2d4248f158e5f6a275768ebb6c59275235a\nPRIOR_APPLY14_BLOCKER=STRONG_PUBLIC_INGRESS_COUNT_NOT_ONE:0\nOPERATIONAL_VPS_FRONTEND_REFERENCES={\"count\":1600,\"rows\":[{\"line\":2,\"path\":\"/etc/systemd/system/homelab-vps-identity-audit.timer\",\"text\":\"Description=Run Homelab VPS SSH identity audit\"},{\"line\":2,\"path\":\"/etc/systemd/system/homelab-vps-identity-audit.service\",\"text\":\"Description=Homelab VPS SSH identity audit\"},{\"line\":6,\"path\":\"/etc/systemd/system/homelab-vps-identity-audit.service\",\"text\":\"ExecStart=/usr/local/sbin/homelab-vps-identity-audit\"},{\"line\":2,\"path\":\"/etc/systemd/system/timers.target.wants/homelab-vps-identity-audit.timer\",\"text\":\"Description=Run Homelab VPS SSH identity audit\"},{\"line\":3,\"path\":\"/etc/systemd/system/netbird-vps-backup.service.d/10-superseded-noop.conf\",\"text\":\"ExecStart=/usr/local/sbin/homelab-superseded-unit-ok netbird-vps-backup.service superseded_by_current_appbackup_or_trust_proof\"},{\"line\":9,\"path\":\"/usr/local/sbin/homelab-external-probe-vps\",\"text\":\"grep -q \\\"^STATUS=OK\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":10,\"path\":\"/usr/local/sbin/homelab-external-probe-vps\",\"text\":\"grep -q \\\"^STATUS=OK\\\" /var/lib/homelab-health/netbird-vps-trust-closure.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":12,\"path\":\"/usr/local/sbin/homelab-external-probe-vps\",\"text\":\"grep -q \\\"TRUSTED_NETBIRD_IDENTITY=edge-vm\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":13,\"path\":\"/usr/local/sbin/homelab-external-probe-vps\",\"text\":\"grep -q \\\"PUBLIC_VPS_DECISION=REJECTED_HOSTKEY_MISMATCH\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":6,\"path\":\"/usr/local/sbin/homelab-vps-identity-audit\",\"text\":\"H=\\\"/var/lib/homelab-health/vps-identity-audit.txt\\\"\"},{\"line\":23,\"path\":\"/usr/local/sbin/homelab-vps-identity-audit\",\"text\":\"backup=\\\"$(find /mnt/staging/netbird-vps-backups/snapshots -maxdepth 2 -type f -name 'netbird-vps-backup.tgz' 2>/dev/null | sort | tail -n1 || true)\\\"\"},{\"line\":45,\"path\":\"/usr/local/sbin/homelab-vps-identity-audit\",\"text\":\"printf 'STATUS=%s TS=%s TYPE=vps-identity-audit VPS_IP=%s ALIAS=%s ALIAS_IP=%s SSH_TRUST=%s BACKUP_HOSTKEYS=%s KNOWN_HOSTS_UNCHANGED=YES SECRET_PRINTED=REDACTED\\\\n' \\\\\"},{\"line\":13,\"path\":\"/usr/local/sbin/homelab-external-probe-vps-health\",\"text\":\"grep -q \\\"^STATUS=OK\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":14,\"path\":\"/usr/local/sbin/homelab-external-probe-vps-health\",\"text\":\"grep -q \\\"^STATUS=OK\\\" /var/lib/homelab-health/netbird-vps-trust-closure.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":16,\"path\":\"/usr/local/sbin/homelab-external-probe-vps-health\",\"text\":\"grep -q \\\"TRUSTED_NETBIRD_IDENTITY=edge-vm\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":17,\"path\":\"/usr/local/sbin/homelab-external-probe-vps-health\",\"text\":\"grep -q \\\"PUBLIC_VPS_DECISION=REJECTED_HOSTKEY_MISMATCH\\\" /var/lib/homelab-health/netbird-vps-trust-clean-seal.txt 2>/dev/null || BAD=$((BAD+1))\"},{\"line\":29,\"path\":\"/srv/homelab-ops/KB_START_HERE.md\",\"text\":\"- Не печатать пароли, PAT, токены, TOTP, private SSH keys.\"},{\"line\":116,\"path\":\"/srv/homelab-ops/observed/current-context.json\",\"text\":\"\\\"remote\\\": \\\"https://git.gram1.ru/homelab-admin/homelab-ops.git\\\",\"},{\"line\":1,\"path\":\"/srv/homelab-ops/observed/source-snapshots/overall.txt\",\"text\":\"STATUS=WARN TS=2026-08-19T05:04:50Z TYPE=overall-health BAD=13 backup-framework.txt=FAIL drift-check.txt=WARN service-registry.txt=OK dependency-map.txt=OK golden-state.txt=OK cluster-passport.txt=WARN final-readiness.txt=WARN safe-autoheal.txt=OK kuma-monitor-policy.txt=OK backup-sla.txt=FAIL backup-coverage-matrix.txt=FAIL extended-appbackup.txt=FAIL residual-review.txt=OK forum-snuffleupagus.txt=OK incident-journal.txt=OK duty-admin-v2.txt=OK node-loss-readiness.txt=OK node-loss-runbooks.txt=OK power-loss-readiness.txt=OK power-loss-runbook.txt=OK ungated-health-backlog.txt=OK pve03-root-cleanup.txt=OK pve03-staging-retention.txt=OK pve03-staging-retention-proof.txt=OK pve03-staging-retention-cleanup.txt=OK pve03-failed-unit-cleanup.txt=OK remote-git-sops-age-readiness.txt=OK remote-git-sops-age-policy.txt=OK desired-state-remote-target-trace.txt=OK desired-state-remote-target.txt=OK desired-state.txt=OK runbooks.txt=OK alerting.txt=OK secret-exposure.txt=OK capacity-risk.txt=OK vm-local-dumps-retention.txt=FAIL vm-local-dumps-cloud.txt=FAIL vm-backup-policy.txt=FAIL vm170-vm171-full-strategy.txt=OK external-probe-vps.txt=OK netbird-vps-trust.txt=OK netbird-vps-trust-closure.txt=OK external-probe-runner-decision.txt=OK netbird-vps-trust-clean-seal.txt=OK live-tail-audit.txt=OK vm-backup.txt=OK cluster-admin-observer.txt=WARN cluster-admin-restricted-probes.txt=WARN cluster-admin-full-observer.txt=WARN cluster-admin-vm-mail-cloud-backup.txt=OK cluster-admin-webpanel-sync.txt=OK cluster-admin-webpanel.txt=OK\"},{\"line\":162,\"path\":\"/srv/homelab-ops/changes/CR-2026-0018/design.md\",\"text\":\"- не вызывается через chat wrapper, SSH forced command или remote API;\"},{\"line\":29,\"path\":\"/srv/homelab-ops/changes/CR-2026-0009/plan.json\",\"text\":\"\\\"overbroad SSH pipeline regex\\\",\"},{\"line\":157,\"path\":\"/srv/homelab-ops/errors/regression-cases.json\",\"text\":\"\\\"required_control\\\": \\\"Every active Skladchik SSH caller and its desired-state copy must be versioned, deployed and verified with StrictHostKeyChecking=yes and the canonical known_hosts file.\\\",\"},{\"line\":222,\"path\":\"/srv/homelab-ops/errors/regression-cases.json\",\"text\":\"\\\"incident\\\": \\\"A read-only diagnostic passed regular-expression metacharacters as direct SSH remote arguments, allowing the remote login shell to reinterpret them and produce syntax and command-not-found errors.\\\",\"},{\"line\":223,\"path\":\"/srv/homelab-ops/errors/regression-cases.json\",\"text\":\"\\\"required_control\\\": \\\"Remote regex, pipelines and shell metacharacters must live in versioned remote scripts transferred over stdin; direct SSH argv is limited to literal commands and paths.\\\",\"},{\"line\":234,\"path\":\"/srv/homelab-ops/errors/regression-cases.json\",\"text\":\"\\\"incident\\\": \\\"An overbroad SSH static test classified a safe local pipeline consuming SSH stdout as a forbidden remote-shell pipeline.\\\",\"},{\"line\":235,\"path\":\"/srv/homelab-ops/errors/regression-cases.json\",\"text\":\"\\\"required_control\\\": \\\"SSH safety tests must match direct remote grep or pgrep execution precisely and must not reject local post-processing pipelines.\\\",\"},{\"line\":125,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/task.json\",\"text\":\"\\\"compile\\\": \\\"NoCloud-delivered versioned guest-provision.sh; no first-boot SSH host-key trust is required\\\"\"},{\"line\":159,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/task.json\",\"text\":\"\\\"snikket_domain\\\": \\\"chat.gram1.ru\\\",\"},{\"line\":3,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/README.txt\",\"text\":\"The task carries split-DNS host configuration, public DNS for snikket_server, TURN NAT mapping, certificate permission reconciliation and recovery SSH key.\"},{\"line\":19,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/edge-readonly.py\",\"text\":\"if any(x in blob for x in ('nc.gram1.ru','chat.gram1.ru','groups.chat.gram1.ru','share.chat.gram1.ru','[PRIVATE_IP]')):\"},{\"line\":1,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/snikket.conf\",\"text\":\"SNIKKET_DOMAIN=chat.gram1.ru\"},{\"line\":8,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/guest-provision.sh\",\"text\":\"export DEBIAN_FRONTEND=noninteractive\"},{\"line\":61,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/vm150-runtime.py\",\"text\":\"DOMAINS=['chat.gram1.ru','groups.chat.gram1.ru','share.chat.gram1.ru']\"},{\"line\":710,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/vm150-runtime.py\",\"text\":\"rc,code=curl_edge('chat.gram1.ru','/.well-known/host-meta')\"},{\"line\":752,\"path\":\"/srv/homelab-ops/tasks/snikket-vm150-rebuild-v2/assets/vm150-runtime.py\",\"text\":\"obj={'schema':'snikket-vm150-seal-v2','status':'SEALED','task_id':TASK_ID,'change_id':CFG['change_id'],'source_head':source_head,'sealed_at_utc':now(),'vmid':150,'domain':'chat.gram1.ru','pre_admin_generation':pre_admin_gen,'new_generation':gen,'new_backup_restore_proven':True,'final_post_admin_backup':True,'old_generation_preserved':OLD_GEN,'mobile_av_test':'PASS','wan_5269_forwarded':False,'admin_account_created':True,'family_user_role':'LIMITED_RECOMMENDED','invite_logged':False}\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/verify.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/verify.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":34,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/verify.sh\",\"text\":\"INSTALLED_WORKER_SHA=\\\"$(ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/bin/sha256sum /usr/local/libexec/homelab-vm160-cloud-quorum-worker | awk '{print $1}')\\\"\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/apply.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/apply.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":20,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/apply.sh\",\"text\":\"ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] install -m 0755 /tmp/homelab-vm160-cloud-quorum-worker /usr/local/libexec/homelab-vm160-cloud-quorum-worker\"},{\"line\":21,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/apply.sh\",\"text\":\"ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] rm -f /tmp/homelab-vm160-cloud-quorum-worker\"},{\"line\":22,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/apply.sh\",\"text\":\"INSTALLED_WORKER_SHA=\\\"$(ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/bin/sha256sum /usr/local/libexec/homelab-vm160-cloud-quorum-worker | awk '{print $1}')\\\"\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/dry-run.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/dry-run.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/preflight.sh\",\"text\":\"pve02_probe(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/pve02-vm160-preflight-probe.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/preflight.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":11,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/preflight.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/seal.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/seal.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/prepare.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/prepare.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"pve03_versioned(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] bash -s -- \\\"$@\\\" < \\\"$HOMELAB_TASK_DIR/assets/vm160-cloud-quorum-worker.sh\\\"; }\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"pve03_installed(){ ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] /usr/local/libexec/homelab-vm160-cloud-quorum-worker \\\"$@\\\"; }\"},{\"line\":17,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] test -d /mnt/staging/vzdump/vm160-pve02-20260717T223819Z\"},{\"line\":21,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"if ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] test -x /usr/local/libexec/homelab-vm160-cloud-quorum-worker; then pve03_installed restore vm160-pve02-20260717T223819Z; else pve03_versioned restore vm160-pve02-20260717T223819Z; fi\"},{\"line\":23,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] test -s /mnt/staging/vzdump/vm160-pve02-20260717T223819Z/vzdump-qemu-160-20260717T223819Z.vma.zst\"},{\"line\":24,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"test \\\"$(ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] stat -c %s /mnt/staging/vzdump/vm160-pve02-20260717T223819Z/vzdump-qemu-160-20260717T223819Z.vma.zst)\\\" = 84995216465\"},{\"line\":25,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"test \\\"$(ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] sha256sum /mnt/staging/vzdump/vm160-pve02-20260717T223819Z/vzdump-qemu-160-20260717T223819Z.vma.zst | awk '{print $1}')\\\" = 257e10821e62e3e2f9318b238a5302a6db601dd597bfa3e0d77aba07f3b85e72\"},{\"line\":26,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"test \\\"$(ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] readlink /mnt/staging/vzdump/vm160-pve02-latest)\\\" = vm160-pve02-20260717T223819Z\"},{\"line\":29,\"path\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/rollback.sh\",\"text\":\"ssh \\\"${SSH_BASE[@]}\\\" root@[PRIVATE_IP] rm -f /usr/local/libexec/homelab-vm160-cloud-quorum-worker\"},{\"line\":23,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/verify.sh\",\"text\":\"test \\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /usr/bin/sha256sum \\\"$EDGE_SCRIPT\\\" | awk 'NR==1{print $1}')\\\" = \\\"$EXPECTED_SHA\\\"\"},{\"line\":24,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/verify.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$EXPECTED_SHA\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-verify.sh\\\")\\\"\"},{\"line\":26,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/apply.sh\",\"text\":\"ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /usr/bin/install -m 0755 -o root -g root /tmp/skladchik-reports-monitor-cookie-update-edge.cr7 \\\"$EDGE_SCRIPT\\\"\"},{\"line\":27,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/apply.sh\",\"text\":\"ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" /usr/bin/rm -f /tmp/skladchik-reports-monitor-cookie-update-edge.cr7\"},{\"line\":28,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/apply.sh\",\"text\":\"test \\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /usr/bin/sha256sum \\\"$EDGE_SCRIPT\\\" | awk 'NR==1{print $1}')\\\" = \\\"$EXPECTED_SHA\\\"\"},{\"line\":30,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/apply.sh\",\"text\":\"ssh -tt \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /usr/local/sbin/skladchik-reports-monitor-cookie-update-edge\"},{\"line\":35,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/apply.sh\",\"text\":\"if ! git -C /srv/homelab-desired-state diff --cached --quiet; then git -C /srv/homelab-desired-state commit -m 'CR-2026-0007 enforce strict Skladchik SSH and controlled reauth'; fi\"},{\"line\":32,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/dry-run.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$EDGE_STAGE\\\" \\\"$CURRENT_EDGE_SHA\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-dry-run.sh\\\")\\\"\"},{\"line\":20,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/preflight.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$CURRENT_EDGE_SHA\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-preflight.sh\\\")\\\"\"},{\"line\":16,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/seal.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$EDGE_STAGE\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-seal.sh\\\")\\\"\"},{\"line\":34,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/prepare.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$EDGE_STAGE\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-prepare.sh\\\")\\\"\"},{\"line\":18,\"path\":\"/srv/homelab-ops/tasks/skladchik-reports-monitor-controlled-reauth-v1/phases/rollback.sh\",\"text\":\"RESULT=\\\"$(ssh \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n /bin/bash -s -- \\\"$EDGE_STAGE\\\" < \\\"$HOMELAB_TASK_DIR/assets/edge-rollback.sh\\\")\\\"\"},{\"line\":21,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"authoritative and public DNS for chat.gram1.ru\\\",\"},{\"line\":22,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"EDGE-01 public service path at 185.225.35.6\\\",\"},{\"line\":36,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"Cloudflare A record chat.gram1.ru\\\",\"},{\"line\":41,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"chat.gram1.ru A record\\\",\"},{\"line\":52,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"groups.chat.gram1.ru and share.chat.gram1.ru records are unchanged\\\",\"},{\"line\":113,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"compile\\\": \\\"QGA only; no first-boot SSH dependency\\\"\"},{\"line\":116,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"host\\\": \\\"EDGE-01 185.225.35.6\\\",\"},{\"line\":128,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"chat_fqdn\\\": \\\"chat.gram1.ru\\\",\"},{\"line\":130,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/task.json\",\"text\":\"\\\"edge01_public_ip\\\": \\\"185.225.35.6\\\",\"},{\"line\":4,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/README.txt\",\"text\":\"- production traffic cutover for chat.gram1.ru from 95.84.154.183 to EDGE-01 185.225.35.6;\"},{\"line\":6,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/tools/cutover.py\",\"text\":\"CHAT = \\\"chat.gram1.ru\\\"\"},{\"line\":9,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/tools/cutover.py\",\"text\":\"EDGE = \\\"185.225.35.6\\\"\"},{\"line\":16,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/tools/cutover.py\",\"text\":\"EDGE_SSH = [\\\"ssh\\\",\\\"-o\\\",\\\"BatchMode=yes\\\",\\\"-o\\\",\\\"StrictHostKeyChecking=yes\\\",\\\"-o\\\",\\\"ConnectTimeout=8\\\",\\\"debian@[PRIVATE_IP]\\\"]\"},{\"line\":138,\"path\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/tools/cutover.py\",\"text\":\"for host in (CHAT,\\\"groups.chat.gram1.ru\\\",\\\"share.chat.gram1.ru\\\"):\"},{\"line\":120,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/task.json\",\"text\":\"\\\"host\\\": \\\"EDGE-01 185.225.35.6\\\",\"},{\"line\":137,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/task.json\",\"text\":\"\\\"edge01_public_ip\\\": \\\"185.225.35.6\\\",\"},{\"line\":24,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/tools/retire_home_forwards.py\",\"text\":\"EDGE = \\\"185.225.35.6\\\"\"},{\"line\":26,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/tools/retire_home_forwards.py\",\"text\":\"CHAT = \\\"chat.gram1.ru\\\"\"},{\"line\":30,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/tools/retire_home_forwards.py\",\"text\":\"EDGE_SSH = [\\\"ssh\\\",\\\"-o\\\",\\\"BatchMode=yes\\\",\\\"-o\\\",\\\"StrictHostKeyChecking=yes\\\",\\\"-o\\\",\\\"ConnectTimeout=8\\\",\\\"debian@[PRIVATE_IP]\\\"]\"},{\"line\":207,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/tools/retire_home_forwards.py\",\"text\":\"for host in (CHAT,\\\"groups.chat.gram1.ru\\\",\\\"share.chat.gram1.ru\\\"):\"},{\"line\":274,\"path\":\"/srv/homelab-ops/tasks/snikket-home-forward-retire-v1/tools/retire_home_forwards.py\",\"text\":\"cmd = EDGE_SSH + [\\\"sudo\\\",\\\"-n\\\",\\\"docker\\\",\\\"exec\\\",\\\"-i\\\",\\\"npmplus\\\",\\\"sh\\\",\\\"-s\\\"]\"},{\"line\":21,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"authoritative and public DNS for chat.gram1.ru and turn.gram1.ru\\\",\"},{\"line\":42,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"chat.gram1.ru is not modified\\\",\"},{\"line\":43,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"groups.chat.gram1.ru and share.chat.gram1.ru are not modified\\\",\"},{\"line\":113,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"host\\\": \\\"EDGE-01 185.225.35.6\\\",\"},{\"line\":127,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"chat_fqdn\\\": \\\"chat.gram1.ru\\\",\"},{\"line\":128,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/task.json\",\"text\":\"\\\"edge01_public_ip\\\": \\\"185.225.35.6\\\",\"},{\"line\":6,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"CHAT = \\\"chat.gram1.ru\\\"\"},{\"line\":10,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"EDGE = \\\"185.225.35.6\\\"\"},{\"line\":13,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"EDGE_SSH = [\\\"ssh\\\",\\\"-o\\\",\\\"BatchMode=yes\\\",\\\"-o\\\",\\\"StrictHostKeyChecking=yes\\\",\\\"-o\\\",\\\"ConnectTimeout=8\\\",\\\"debian@[PRIVATE_IP]\\\"]\"},{\"line\":16,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"\\\"_stun._udp.chat.gram1.ru\\\",\"},{\"line\":17,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"\\\"_stuns._tcp.chat.gram1.ru\\\",\"},{\"line\":18,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"\\\"_turn._udp.chat.gram1.ru\\\",\"},{\"line\":19,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"\\\"_turn._tcp.chat.gram1.ru\\\",\"},{\"line\":20,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"\\\"_turns._tcp.chat.gram1.ru\\\",\"},{\"line\":198,\"path\":\"/srv/homelab-ops/tasks/snikket-turn-legacy-dns-retire-v1/tools/retire_turn_dns.py\",\"text\":\"for host in (CHAT,\\\"groups.chat.gram1.ru\\\",\\\"share.chat.gram1.ru\\\"):\"},{\"line\":8,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-post-cutover-hardening-design.md\",\"text\":\"- `chat.gram1.ru` resolves to `185.225.35.6`.\"},{\"line\":9,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-post-cutover-hardening-design.md\",\"text\":\"- VM150 default route is via `[PRIVATE_IP]`; verified public egress is `185.225.35.6`.\"},{\"line\":10,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-post-cutover-hardening-design.md\",\"text\":\"- coturn advertises `185.225.35.6/[PRIVATE_IP]`.\"},{\"line\":28,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-post-cutover-hardening-design.md\",\"text\":\"Verify `chat.gram1.ru`, public Snikket services, VM150 egress and effective coturn external address remain unchanged.\"},{\"line\":7,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-edge-cutover-design.md\",\"text\":\"Move chat.gram1.ru from home IP 95.84.154.183 to EDGE-01 185.225.35.6. Persistent EDGE-01 and edge-vm inbound transit is already installed and TCP, XMPP STARTTLS, TURN TLS, UDP STUN and HTTPS canaries pass.\"},{\"line\":8,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-edge-cutover-design.md\",\"text\":\"Before cutover, EDGE-01 ingress is still restricted to source 95.84.154.183, chat.gram1.ru A is still 95.84.154.183, edge-vm table 17777 is ready, and no source rule for VM150 [PRIVATE_IP] is active.\"},{\"line\":11,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-edge-cutover-design.md\",\"text\":\"CR0080 covers only production traffic cutover: publicize the verified EDGE-01 ingress contract, change only chat.gram1.ru A to 185.225.35.6, wait for DNS convergence, activate VM150 egress through edge-vm and EDGE-01, refresh effective TURN addressing, verify, rollback and seal.\"},{\"line\":16,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-edge-cutover-design.md\",\"text\":\"EDGE-01 remains manual-operator access only. CR0080 versions the exact public-ingress contract, but the operator applies it from the established root@edge01 session; the pve01 task must not invent an automated EDGE-01 SSH path.\"},{\"line\":21,\"path\":\"/srv/homelab-ops/docs/superpowers/specs/2026-08-17-snikket-edge-cutover-design.md\",\"text\":\"Verification covers HTTPS chat/groups/share; TCP 5000,5222,3478,3479,5349,5350; XMPP STARTTLS; TURN TLS; UDP STUN and relay 60000-60199; VM150 outbound IP 185.225.35.6; DNS convergence; and no effective TURN advertisement containing 95.84.154.183.\"},{\"line\":21,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md\",\"text\":\"- Use strict SSH host verification; never `StrictHostKeyChecking=no`.\"},{\"line\":845,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md\",\"text\":\"ssh -o BatchMode=yes -o StrictHostKeyChecking=yes edgeadmin@185.225.35.6 'sudo -n true && hostname -s'\"},{\"line\":3,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-edge-cutover.md\",\"text\":\"**Goal:** finish the traffic cutover of chat.gram1.ru to EDGE-01 while preserving rollback and keeping VM150 source-policy disabled until DNS convergence.\"},{\"line\":23,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-edge-cutover.md\",\"text\":\"- apply: require explicit EDGE-01 public-ingress operator attestation; change only chat.gram1.ru A to 185.225.35.6; wait for authoritative and public convergence; only then install priority-101 source policy for [PRIVATE_IP] via table 17777 and change VM150 gateway to [PRIVATE_IP]; refresh only the Snikket server container if effective TURN addressing still shows the old origin.\"},{\"line\":24,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-edge-cutover.md\",\"text\":\"- verify: HTTPS, TCP 5000/5222/3478/3479/5349/5350, XMPP STARTTLS, TURN TLS, UDP STUN, VM150 outbound public IP 185.225.35.6, DNS convergence and effective TURN address without 95.84.154.183.\"},{\"line\":9,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-turn-legacy-dns-retirement.md\",\"text\":\"**Tech Stack:** Bash phase wrappers, Python 3, `homelab-admin`, `qm guest exec`, SSH to edge-vm, Docker/NPMplus, Cloudflare API, `dig`, `curl`, `openssl`, sockets.\"},{\"line\":15,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-turn-legacy-dns-retirement.md\",\"text\":\"- Do not modify `chat.gram1.ru`, Snikket containers, VM150 routing, edge-vm routing, EDGE-01 nftables, certificate renewal, or home-router forwards.\"},{\"line\":33,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-turn-legacy-dns-retirement.md\",\"text\":\"- Consumes: CR0080 sealed path (`chat.gram1.ru=185.225.35.6`, VM150 egress through EDGE, effective coturn external address on EDGE), NPMplus local Cloudflare credential path.\"},{\"line\":88,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-turn-legacy-dns-retirement.md\",\"text\":\"chat.gram1.ru: 185.225.35.6 at all three views\"},{\"line\":89,\"path\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-17-snikket-turn-legacy-dns-retirement.md\",\"text\":\"VM150 public egress: 185.225.35.6\"},{\"line\":209,\"path\":\"/srv/homelab-ops/tools/collect_context.py\",\"text\":\"\\\"remote\\\": \\\"https://git.gram1.ru/homelab-admin/homelab-ops.git\\\",\"},{\"line\":15,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT_PUBLIC.md\",\"text\":\"CR0083 is merged/closed. Current P0 sequence starts with Git topology preservation, then canonical post-migration state, recovery/backup refresh, VM160/forum acceptance, permanent new-USA SSH hardening, old-USA observation/retirement, and final seal.\"},{\"line\":18,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT.md\",\"text\":\"- EDGE: `edgeadmin@185.225.35.6`, key label `edge01-admin-2026`, then `sudo -i`. Do not copy the EDGE private key to pve01.\"},{\"line\":19,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT.md\",\"text\":\"- Gitea: `https://git.gram1.ru`, repo `homelab-admin/homelab-ops`.\"},{\"line\":32,\"path\":\"/srv/homelab-ops/kb/AI_CONTEXT.md\",\"text\":\"Production NetBird is new USA `46.16.34.129`, Debian 12, hostname `nb2`, NetBird `0.73.2`. Exact deployment caveat: `/api/health` = 404 and combined `:9000/health` = 503; these are not generic readiness gates for this deployment. Old USA `185.139.214.215` has Mailcow/NetBird server stopped and observer disabled, but remains in rollback window. Permanent new-USA operator SSH hardening is still P0.\"},{\"line\":28,\"path\":\"/srv/homelab-ops/kb/state/current.json\",\"text\":\"\\\"gitea_url\\\": \\\"https://git.gram1.ru\\\",\"},{\"line\":86,\"path\":\"/srv/homelab-ops/kb/state/current.json\",\"text\":\"\\\"permanent operator SSH key\\\",\"},{\"line\":6,\"path\":\"/srv/homelab-ops/kb/runbooks/02_PROXMOX.md\",\"text\":\"- SSH readiness does not mean cloud-init/apt is finished.\"},{\"line\":3,\"path\":\"/srv/homelab-ops/kb/runbooks/03_EDGE_NGINX.md\",\"text\":\"Operator path: MobaXterm → `edgeadmin@185.225.35.6` with key `edge01-admin-2026` → `sudo -i`.\"},{\"line\":7,\"path\":\"/srv/homelab-ops/kb/runbooks/04_NETBIRD_USA.md\",\"text\":\"SSH hardening sequence is strict:\"},{\"line\":7,\"path\":\"/srv/homelab-ops/kb/private/access.json\",\"text\":\"\\\"command_hint\\\": \\\"ssh root@100.100.131.41\\\",\"},{\"line\":20,\"path\":\"/srv/homelab-ops/kb/private/access.json\",\"text\":\"\\\"target\\\": \\\"185.225.35.6\\\",\"},{\"line\":22,\"path\":\"/srv/homelab-ops/kb/private/access.json\",\"text\":\"\\\"command_hint\\\": \\\"ssh edgeadmin@185.225.35.6 then sudo -i\\\",\"},{\"line\":63,\"path\":\"/srv/homelab-ops/kb/private/access.json\",\"text\":\"\\\"target\\\": \\\"https://git.gram1.ru\\\",\"},{\"line\":116,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures.json\",\"text\":\"\\\"incident\\\": \\\"ssh ... bash -s consumed stdin and disrupted enclosing command flow.\\\",\"},{\"line\":117,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures.json\",\"text\":\"\\\"prevention\\\": \\\"Use explicit script files/stdin isolation; avoid ssh bash -s inside loops that also read stdin.\\\",\"},{\"line\":378,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures.json\",\"text\":\"\\\"incident\\\": \\\"SSH became reachable before first-boot/cloud-init apt activity released package locks.\\\",\"},{\"line\":513,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures.json\",\"text\":\"\\\"incident\\\": \\\"A top-level exit can close the user’s primary SSH shell/session.\\\",\"},{\"line\":529,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures.json\",\"text\":\"\\\"OPENSSH PRIVATE KEY\\\"\"},{\"line\":68,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures_public.json\",\"text\":\"\\\"incident\\\": \\\"ssh ... bash -s consumed stdin and disrupted enclosing command flow.\\\",\"},{\"line\":69,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures_public.json\",\"text\":\"\\\"prevention\\\": \\\"Use explicit script files/stdin isolation; avoid ssh bash -s inside loops that also read stdin.\\\"\"},{\"line\":219,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures_public.json\",\"text\":\"\\\"incident\\\": \\\"SSH became reachable before first-boot/cloud-init apt activity released package locks.\\\",\"},{\"line\":297,\"path\":\"/srv/homelab-ops/kb/lessons/known_failures_public.json\",\"text\":\"\\\"incident\\\": \\\"A top-level exit can close the user’s primary SSH shell/session.\\\",\"},{\"line\":9,\"path\":\"/srv/homelab-ops/kb/current/04_P0_NEXT.md\",\"text\":\"7. New USA permanent SSH key + key-only hardening with separate-session proof.\"},{\"line\":12,\"path\":\"/srv/homelab-ops/kb/current/04_P0_NEXT.md\",\"text\":\"Do not mix unrelated changes into these gates (e.g. NetBird version upgrade/hostname change during SSH hardening).\"},{\"line\":34,\"path\":\"/srv/homelab-ops/kb/scripts/validate_kb.py\",\"text\":\"openssh_marker = '<redacted-pem>\"},{\"line\":46,\"path\":\"/srv/homelab-ops/kb/scripts/validate_kb.py\",\"text\":\"for bad in ('/etc/msmtp-postbox.secret','/etc/pvepro-relay-gotify.token','/etc/homelab-git-read/token','/var/lib/homelab-private/secrets/','begin openssh private key'):\"},{\"line\":21,\"path\":\"/srv/homelab-ops/kb/scripts/command_guard.py\",\"text\":\"add('BLOCK','REG-030-MOBAXTERM-TOP-LEVEL-EXIT','Top-level exit can close the operator SSH session.')\"},{\"line\":37,\"path\":\"/srv/homelab-ops/kb/scripts/command_guard.py\",\"text\":\"add('WARN','REG-007-SSH-STDIN-CONSUMPTION','ssh bash -s can consume stdin; isolate script input.')\"},{\"line\":33,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0080_snikket_edge_cutover.py\",\"text\":\"for needle in (\\\"185.225.35.6\\\",\\\"[PRIVATE_IP]\\\",\\\"snat to [PRIVATE_IP]\\\",\\\"60000-60199\\\",\\\"SNIKKET_PROD_INGRESS_JUMP\\\"):\"},{\"line\":33,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0081_turn_dns_retire.py\",\"text\":\"for name in (\\\"_turn._udp.turn.gram1.ru\\\",\\\"_turns._tcp.turn.gram1.ru\\\",\\\"_stun._udp.turn.gram1.ru\\\",\\\"_turn._udp.chat.gram1.ru\\\"):\"},{\"line\":69,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0013_vm160_worker_bootstrap_transition.py\",\"text\":\"actual_pos = self.apply.index('INSTALLED_WORKER_SHA=\\\"$(ssh ')\"},{\"line\":82,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0013_vm160_worker_bootstrap_transition.py\",\"text\":\"self.assertIn('INSTALLED_WORKER_SHA=\\\"$(ssh ', self.verify)\"},{\"line\":35,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0081_home_forward_retire.py\",\"text\":\"self.assertEqual(self.task[\\\"source_of_truth\\\"][\\\"edge01_public_ip\\\"], \\\"185.225.35.6\\\")\"},{\"line\":74,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0007_skladchik_reauth.py\",\"text\":\"self.assertNotIn(\\\"ssh -t -o\\\", texts)\"},{\"line\":72,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0009_skladchik_concurrency_guard.py\",\"text\":\"\\\"VALUE=$(ssh ${SSH[@]} $EDGE sudo -n /usr/bin/sha256sum /path \\\"\"},{\"line\":54,\"path\":\"/srv/homelab-ops/tests/test_cr_2026_0007_skladchik_semantic_repair.py\",\"text\":\"self.assertIn('ssh -tt \\\"${SSH[@]}\\\" \\\"$EDGE\\\" sudo -n \\\"$EDGE_SCRIPT\\\"', wrapper)\"},{\"line\":951,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"URL=https://git.gram1.ru\"},{\"line\":1899,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Avoid multiline Python directly in SSH one-liner unless base64 encoded.\"},{\"line\":1967,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"4. The only remaining access convenience item is optional: expose the cluster-admin panel via a VPN-only/internal reverse proxy route such as `cluster-admin.vpn.gram1.ru`.\"},{\"line\":2086,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Commands became too slow when they repeatedly ran `homelab-duty-admin-v2`, `appbackupctl restore-check`, `homelab-final-readiness-gate`, full `pvesh` scans, SSH to all nodes, and cloud checks.\"},{\"line\":2323,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH works as `debian@[PRIVATE_IP]`.\"},{\"line\":2445,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- pve01/pve02/pve03 SSH and Proxmox\"},{\"line\":2454,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Optional ports 80/443 on VM150/170/171 are not hard failures because services may live behind reverse proxy or not expose direct ports.\"},{\"line\":2650,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- VM180 should not have unrestricted root SSH access to pve01.\"},{\"line\":2803,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Configure operator-friendly VPN reverse proxy route: cluster-admin.vpn.gram1.ru -> [PRIVATE_IP]:8080\"},{\"line\":2817,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Do not accept public VPS 188.127.235.6 changed SSH host key without provider-console fingerprint.\"},{\"line\":2827,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"3. VM180 creation wait for QGA could be safely interrupted after VM creation; SSH was already working.\"},{\"line\":2832,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"8. `http://[PRIVATE_IP]:8080/` is not reachable from a normal browser outside LAN/VPN. Use VPN, SSH tunnel, or internal reverse proxy.\"},{\"line\":2850,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"3. сделать независимый external runner только на host с verified SSH fingerprint;\"},{\"line\":2903,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"6. Do not accept the changed public VPS SSH host key for `188.127.235.6` until independently verified from provider console.\"},{\"line\":3033,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Use ssh -n in loops/remote commands so ssh does not consume loop stdin.\"},{\"line\":3319,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- public VPS `188.127.235.6` is rejected due SSH host-key mismatch.\"},{\"line\":3331,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Use a new or repaired external host only after its provider-console SSH host fingerprint is verified.\"},{\"line\":3368,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Use SSH remote URL without embedded credentials, or HTTPS credential helper outside git config.\"},{\"line\":3411,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Do not deploy anything to public VPS 188.127.235.6 until provider-console fingerprint confirms the changed SSH host key.\"},{\"line\":3434,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"1. независимый external runner — нужен новый/починенный внешний host и verified SSH fingerprint;\"},{\"line\":4266,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- For remote loops with ssh, use `ssh -n` so ssh does not consume loop stdin.\"},{\"line\":4441,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- ssh: `ssh debian@[PRIVATE_IP]`\"},{\"line\":4448,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- ssh: `ssh debian@[PRIVATE_IP]`\"},{\"line\":4455,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- ssh: `ssh debian@[PRIVATE_IP]`\"},{\"line\":4810,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- likely frontend/cache;\"},{\"line\":5033,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- For systemd mask checks, avoid broken local `$()` expansion inside SSH strings.\"},{\"line\":5034,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Use direct remote command with single-quoted SSH body when checking systemd state.\"},{\"line\":5134,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH failure bursts;\"},{\"line\":5436,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- кто отвечает за reverse proxy;\"},{\"line\":5727,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- отдельный ssh key;\"},{\"line\":6434,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Запрещены `ssh + heredoc + python` и глубокие вложенные кавычки.\"},{\"line\":6441,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Public SSH на дачный роутер закрыт.\"},{\"line\":6442,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- WG SSH открыт.\"},{\"line\":6472,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- not authoritative: public SSH still open.\"},{\"line\":6475,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- not authoritative: direct public SSH still open.\"},{\"line\":6481,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- REVIEW snapshot: public SSH still open.\"},{\"line\":6683,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"| Core | Gitea | https://git.gram1.ru | public | Git |\"},{\"line\":6740,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Закрыли публичный SSH на дачном роутере, оставив WG SSH доступным.\"},{\"line\":6777,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- direct public dacha SSH closed, WG SSH open.\"},{\"line\":6857,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- line 1156: `### SSH and permissions`\"},{\"line\":7096,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- line 304: `## FORUM_PROD_BULK_IMPORT_PHP85_EMPTY_FRONTEND_20260701`\"},{\"line\":7244,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"| 1156 | `### SSH and permissions` |\"},{\"line\":7455,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"| 304 | `## FORUM_PROD_BULK_IMPORT_PHP85_EMPTY_FRONTEND_20260701` |\"},{\"line\":7540,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- `https://git.gram1.ru`\"},{\"line\":7573,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- `/mnt/staging/netbird-vps-backups/snapshots.`\"},{\"line\":8104,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Proxmox: ssh root@pve01, ssh root@pve02, ssh root@pve03.\"},{\"line\":8105,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Edge VM: ssh debian@[PRIVATE_IP], использовать sudo, root-login не использовать.\"},{\"line\":8106,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Nextcloud VM: ssh debian@[PRIVATE_IP].\"},{\"line\":8107,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Forum-prod: сначала ssh root@pve02, затем ssh -i [SENSITIVE_PATH] root@[PRIVATE_IP].\"},{\"line\":8279,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH port: 2222.\"},{\"line\":8280,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH security-level: private.\"},{\"line\":8285,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SFTP denied for admin in log; SSH CLI works.\"},{\"line\":8293,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- service ssh enabled.\"},{\"line\":8303,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Netcraze SSH CLI is not a normal POSIX shell.\"},{\"line\":8329,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH Server through NetBird: Disabled.\"},{\"line\":8344,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs.\"},{\"line\":8404,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.\"},{\"line\":8552,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Role: edge application host / reverse proxy / monitoring / backup automation host.\"},{\"line\":8620,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- git.gram1.ru -> [PRIVATE_IP].\"},{\"line\":8653,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- git.gram1.ru -> http://127.0.0.1:3002, cert=29, ssl_forced=1, enabled=1.\"},{\"line\":8702,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55.\"},{\"line\":8943,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots.\"},{\"line\":8944,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- NetBird VPS offhost: STATUS=OK to pve02.\"},{\"line\":8945,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded.\"},{\"line\":9006,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- https://git.gram1.ru\"},{\"line\":9062,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru.\"},{\"line\":9119,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":9131,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Reason: nested Python inside SSH lost quoting and produced SyntaxError.\"},{\"line\":9150,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":9162,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"### SSH and permissions\"},{\"line\":9182,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- PVE nodes expose SSH :22, Proxmox :8006 and node-exporter :9100.\"},{\"line\":9202,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- SSH permission correction proof: 160_PVE_ROOT_AUTHORIZED_KEYS_PERMISSIONS_FIXED.txt.\"},{\"line\":9209,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Valid closure condition: target permissions checked with stat -L are 600 for authorized_keys files and [SENSITIVE_PATH] is 700.\"},{\"line\":9305,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to 127.0.0.1:81.\"},{\"line\":9319,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"| git.gram1.ru | http://127.0.0.1:3002 | edge-vm / gitea | gitea backup/offhost/restore |\"},{\"line\":9400,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":9528,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Use 154 for Prometheus settled targets and 163 for symlink-aware SSH target permissions.\"},{\"line\":9870,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Discovery proof records DNS, HTTPS/TLS headers, reverse-proxy candidates, compose files, domain references and homepage config candidates without printing secrets.\"},{\"line\":10053,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Netcraze routerbackup SSH access is read-only for backup: show running-config works, but ACL/config commands are denied.\"},{\"line\":10093,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- New VM identity confirmed: forum-prod / forum-prod.gram1.ru, Debian 12 bookworm, SSH OK, qemu-agent OK, chrony OK.\"},{\"line\":10096,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Beget-compatible profile applied: memory_limit 256M, post/upload 1024M, max_input_vars 10000, MariaDB utf8mb4/utf8mb4_unicode_ci, innodb_buffer_pool_size 2G.\"},{\"line\":10101,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Bulk import of five forums reached DB/files/nginx/php-fpm ready state, but frontend body stayed empty under PHP 8.5.7.\"},{\"line\":10113,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Final result: all five frontend/admin HTTP 200, www redirects 301, internal_data 403, no new XenForo errors.\"},{\"line\":10119,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Applies to: SSH enter/exit points, VM prompt confirmations, snapshot confirmations, file copy confirmations, successful health checks, and other obvious next-step transitions.\"},{\"line\":10433,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"CHECK-4: команда не должна иметь вложенный ssh с несколькими уровнями кавычек.\"},{\"line\":10464,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Нельзя писать sqlite SQL вида j.type in ('object','array') внутри ssh '...'.\"},{\"line\":10465,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Для sqlite через ssh использовать SQL без одинарных кавычек: char(36), length(j.atom), двойные внешние кавычки, либо отдельный файл.\"},{\"line\":10470,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"edge-vm: ssh debian@[PRIVATE_IP], внутри использовать sudo.\"},{\"line\":10471,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"pve02/pve03: ssh root@pve02 или ssh root@pve03.\"},{\"line\":10476,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Снова был использован SQL JSON-path в одинарных кавычках внутри ssh '...'.\"},{\"line\":10526,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"27. Ошибка: Python heredoc внутри ssh сломал not_ok диагностику.\"},{\"line\":10549,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Факт: Python -c внутри ssh потерял кавычки вокруг /tmp/prom-targets-settled.json, data, activeTargets, labels, job, health.\"},{\"line\":10629,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- A portal card is openable only when DNS, reverse-proxy host mapping, and target content are all valid.\"},{\"line\":10632,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Context: attempted Netcraze router ACL apply through SSH stdin/multiline for Homepage Moscow Router monitor fix.\"},{\"line\":10638,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Context: ACL syntax read-only probe loop executed only one command because ssh consumed the loop stdin.\"},{\"line\":10640,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Fix pattern: use ssh -n or redirect SSH stdin away from the command-list loop for all future SSH-in-loop probes.\"},{\"line\":10702,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Rule: do not proceed with OS baseline until SSH failure is diagnosed; likely old known_hosts key or cloud-init/root-key issue.\"},{\"line\":10705,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Context: VM160 first SSH proof after rebuild.\"},{\"line\":10706,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Issue: command substitution $(hostname) inside nested ssh was expanded on pve02 before entering VM160.\"},{\"line\":10708,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Rule: for nested SSH identity checks, run literal hostname commands without local command substitution.\"},{\"line\":10714,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Rule: avoid nested $(...) in VM SSH proofs; use literal remote commands and clean proof.\"},{\"line\":10718,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Issue: nested SSH quoting expanded shell variables incorrectly, producing gzip checks against empty .gz and blank TAR_TOP lines.\"},{\"line\":10722,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"## FORUM_PROD_BULK_IMPORT_PHP85_EMPTY_FRONTEND_20260701\"},{\"line\":10752,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"- Rule: avoid nested SSH heredoc/Python for this task; use simpler commands, generated nginx configs, or uploaded/local script files.\"},{\"line\":11033,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"А самая критичная VM130 edge-vm находится на pve03 и держит reverse proxy, monitoring, backup automation и Docker application host. При этом pve03 — самый ограниченный по диску: local-lvm уже был самым constrained, потому что VM130 имеет 96G OS + 150G media/data, а pve03 staging доходил до 77% при WARN 80%.\"},{\"line\":11102,\"path\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md\",\"text\":\"Файл жёстко требует перед инфраструктурными командами проверять truth files, не использовать огромные paste, не использовать `ssh + heredoc + python`, валидировать скрипты и не печатать секреты. Это оставить как закон.\"},{\"line\":22,\"path\":\"/etc/pve/HOMEPAGE_BACKUP_COVERAGE_MATRIX.md\",\"text\":\"| Gitea | https://git.gram1.ru | 185 | 89 | 105 | EVIDENCE_FOUND_REVIEW |\"},{\"line\":156,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Proxmox: ssh root@pve01, ssh root@pve02, ssh root@pve03.\"},{\"line\":157,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Edge VM: ssh debian@[PRIVATE_IP], использовать sudo, root-login не использовать.\"},{\"line\":158,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Nextcloud VM: ssh debian@[PRIVATE_IP].\"},{\"line\":159,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Forum-prod: сначала ssh root@pve02, затем ssh -i [SENSITIVE_PATH] root@[PRIVATE_IP].\"},{\"line\":331,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- SSH port: 2222.\"},{\"line\":332,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- SSH security-level: private.\"},{\"line\":337,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- SFTP denied for admin in log; SSH CLI works.\"},{\"line\":345,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- service ssh enabled.\"},{\"line\":355,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Netcraze SSH CLI is not a normal POSIX shell.\"},{\"line\":381,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- SSH Server through NetBird: Disabled.\"},{\"line\":396,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- pve01 owns many backup/offhost/restore/health/security/NetBird VPS/rclone/sops/scrutiny jobs.\"},{\"line\":456,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- pve01 timers cover VPN/NetBird health, health metrics, smartctl, disk space, MkDocs refresh, VPS identity audit, storage capacity, quality gate, evidence catalog, backup freshness, docker health, Filebrowser backup/offhost/restore, NPMplus/Kuma backup, NetBird VPS backup/offhost, Authentik/Gitea/Vaultwarden backup, SOPS secret coverage, mail cloud upload/restore, Immich/Memos/Paperless backup/offhost/restore, auto backup, edge-vm vzdump, secret sanity.\"},{\"line\":604,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Role: edge application host / reverse proxy / monitoring / backup automation host.\"},{\"line\":672,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- git.gram1.ru -> [PRIVATE_IP].\"},{\"line\":705,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- git.gram1.ru -> http://127.0.0.1:3002, cert=29, ssl_forced=1, enabled=1.\"},{\"line\":754,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- cert=29: git.gram1.ru, expires 2026-09-13 17:36:55.\"},{\"line\":995,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- NetBird VPS backup: STATUS=OK, snapshot under /mnt/staging/netbird-vps-backups/snapshots.\"},{\"line\":996,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- NetBird VPS offhost: STATUS=OK to pve02.\"},{\"line\":997,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- NetBird VPS restore validation: STATUS=OK, archive SHA256 recorded.\"},{\"line\":1058,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- https://git.gram1.ru\"},{\"line\":1114,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- external canary checks include nc.gram1.ru, git.gram1.ru, auth.gram1.ru, backup.gram1.ru.\"},{\"line\":1171,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":1183,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Reason: nested Python inside SSH lost quoting and produced SyntaxError.\"},{\"line\":1202,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":1214,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"### SSH and permissions\"},{\"line\":1234,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- PVE nodes expose SSH :22, Proxmox :8006 and node-exporter :9100.\"},{\"line\":1254,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- SSH permission correction proof: 160_PVE_ROOT_AUTHORIZED_KEYS_PERMISSIONS_FIXED.txt.\"},{\"line\":1261,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Valid closure condition: target permissions checked with stat -L are 600 for authorized_keys files and [SENSITIVE_PATH] is 700.\"},{\"line\":1357,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Reverse proxy: NPMplus on edge-vm, container npmplus, host networking, admin bound to 127.0.0.1:81.\"},{\"line\":1371,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"| git.gram1.ru | http://127.0.0.1:3002 | edge-vm / gitea | gitea backup/offhost/restore |\"},{\"line\":1452,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Do not use exit 1 in interactive SSH sessions.\"},{\"line\":1580,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Use 154 for Prometheus settled targets and 163 for symlink-aware SSH target permissions.\"},{\"line\":1922,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Discovery proof records DNS, HTTPS/TLS headers, reverse-proxy candidates, compose files, domain references and homepage config candidates without printing secrets.\"},{\"line\":2105,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Netcraze routerbackup SSH access is read-only for backup: show running-config works, but ACL/config commands are denied.\"},{\"line\":2145,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- New VM identity confirmed: forum-prod / forum-prod.gram1.ru, Debian 12 bookworm, SSH OK, qemu-agent OK, chrony OK.\"},{\"line\":2148,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Beget-compatible profile applied: memory_limit 256M, post/upload 1024M, max_input_vars 10000, MariaDB utf8mb4/utf8mb4_unicode_ci, innodb_buffer_pool_size 2G.\"},{\"line\":2153,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Bulk import of five forums reached DB/files/nginx/php-fpm ready state, but frontend body stayed empty under PHP 8.5.7.\"},{\"line\":2165,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Final result: all five frontend/admin HTTP 200, www redirects 301, internal_data 403, no new XenForo errors.\"},{\"line\":2171,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Applies to: SSH enter/exit points, VM prompt confirmations, snapshot confirmations, file copy confirmations, successful health checks, and other obvious next-step transitions.\"},{\"line\":2515,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Recommended future path: establish VPN/NetBird/WireGuard or reverse-proxy/private management endpoint first; then issue DNS-01 certificate on a trusted node and deploy cert/key to the router only over that private path.\"},{\"line\":2531,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Public SSH 194.33.48.131:22 closed.\"},{\"line\":2539,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Public SSH remains closed.\"},{\"line\":2546,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Public SSH closed.\"},{\"line\":2558,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Supersedes failed/partial proof 669 because direct SSH was open during that run.\"},{\"line\":2564,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Direct dacha public SSH is closed; WG SSH remains open.\"},{\"line\":2596,\"path\":\"/etc/pve/31_HOMELAB_REFERENCE.md\",\"text\":\"- Direct public SSH to dacha router is closed.\"},{\"line\":2597,\"...<truncated>\nSYSTEMD_VPS_NETBIRD_UNITS={\"count\":9,\"units\":[{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/homelab-external-probe-vps-health.service\",\"Description=Homelab external probe VPS strategy health\",\"After=network-online.target\",\"ExecStart=/usr/local/sbin/homelab-external-probe-vps-health\"],\"rc\":0,\"unit\":\"homelab-external-probe-vps-health.service\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/homelab-external-probe-vps-health.timer\",\"Description=Homelab external probe VPS strategy health timer\"],\"rc\":0,\"unit\":\"homelab-external-probe-vps-health.timer\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/homelab-vps-identity-audit.service\",\"Description=Homelab VPS SSH identity audit\",\"ExecStart=/usr/local/sbin/homelab-vps-identity-audit\"],\"rc\":0,\"unit\":\"homelab-vps-identity-audit.service\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/homelab-vps-identity-audit.timer\",\"Description=Run Homelab VPS SSH identity audit\"],\"rc\":0,\"unit\":\"homelab-vps-identity-audit.timer\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/netbird-peers-health.service\",\"Description=NetBird peers health check\",\"After=network-online.target\",\"ExecStart=/root/netbird-peers-health.sh\"],\"rc\":0,\"unit\":\"netbird-peers-health.service\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/netbird-peers-health.timer\",\"Description=Run NetBird peers health check\"],\"rc\":0,\"unit\":\"netbird-peers-health.timer\"},{\"err\":\"\",\"lines\":[\"# /etc/systemd/system/netbird.service\",\"Description=NetBird mesh network client\",\"ConditionFileIsExecutable=/usr/bin/netbird\",\"After=network.target syslog.target\",\"ExecStart=/usr/bin/netbird \\\"service\\\" \\\"run\\\" \\\"--log-level\\\" \\\"info\\\" \\\"--daemon-addr\\\" \\\"unix:///var/run/netbird.sock\\\" \\\"--log-file\\\" \\\"/var/log/netbird/client.log\\\"\",\"StandardOutput=file:/var/log/netbird/netbird.out\",\"StandardError=file:/var/log/netbird/netbird.err\",\"EnvironmentFile=-/etc/sysconfig/netbird\",\"Environment=SYSTEMD_UNIT=netbird\"],\"rc\":0,\"unit\":\"netbird.service\"},{\"err\":\"\",\"lines\":[\"# /usr/lib/systemd/system/pveproxy.service\",\"Description=PVE API Proxy Server\",\"ConditionPathExists=/usr/bin/pveproxy\",\"Wants=pve-cluster.service\",\"Wants=pvedaemon.service\",\"Wants=ssh.service\",\"Wants=pve-storage.target\",\"After=pve-storage.target\",\"After=pve-cluster.service\",\"After=pvedaemon.service\",\"After=ssh.service\",\"ExecStartPre=-/usr/bin/pvecm updatecerts --silent\",\"ExecStart=/usr/bin/pveproxy start\",\"ExecStartPost=-sh -c '[ ! -e /var/log/pveam.log ] && /usr/bin/pveupdate'\",\"ExecStop=/usr/bin/pveproxy stop\",\"ExecReload=/usr/bin/pveproxy restart\",\"PIDFile=/run/pveproxy/pveproxy.pid\"],\"rc\":0,\"unit\":\"pveproxy.service\"},{\"err\":\"\",\"lines\":[\"# /usr/lib/systemd/system/spiceproxy.service\",\"Description=PVE SPICE Proxy Server\",\"ConditionPathExists=/usr/bin/spiceproxy\",\"Wants=pveproxy.service\",\"After=pveproxy.service\",\"ExecStart=/usr/bin/spiceproxy start\",\"ExecStop=/usr/bin/spiceproxy stop\",\"ExecReload=/usr/bin/spiceproxy restart\",\"PIDFile=/run/pveproxy/spiceproxy.pid\"],\"rc\":0,\"unit\":\"spiceproxy.service\"}]}\nSSH_METADATA={\"config\":[{\"line\":21,\"path\":\"/etc/ssh/ssh_config\",\"text\":\"Host *\"}],\"key_metadata\":[{\"mode\":\"0o600\",\"path\":\"[SENSITIVE_PATH] Host git.gram1.ru found: line 72 \",{\"algorithm\":\"ssh-ed25519\",\"line_sha256\":\"956d4c61a41d7547b9c63dbbf4f31730f0579f638a5bcdab9b299154bc17913a\"}],\"query\":\"git.gram1.ru\",\"rc\":0},{\"err\":\"\",\"matches\":[],\"query\":\"chat.gram1.ru\",\"rc\":1},{\"err\":\"\",\"matches\":[],\"query\":\"newfi-staging.gram1.ru\",\"rc\":1}]}\nPUBLIC_FRONTEND_SSH_KEYSCAN=[{\"err\":\"\",\"host\":\"185.225.35.6\",\"keys\":[{\"algorithm\":\"ecdsa-sha2-nistp256\",\"line_sha256\":\"ac034f62bb300d5803fb554720d8e893f60de04d2d7b4e4173927a22898844a0\"},{\"algorithm\":\"ssh-rsa\",\"line_sha256\":\"d50e3d759085b7fed47aabfda87e5b8898baaa901558b2ceb86669818bb31367\"},{\"algorithm\":\"ssh-ed25519\",\"line_sha256\":\"7958f5c47286d25debbcdf39d333b2ae99c27a851b09a89e750e40e5f2646d75\"}],\"rc\":0},{\"err\":\"\",\"host\":\"git.gram1.ru\",\"keys\":[{\"algorithm\":\"ssh-rsa\",\"line_sha256\":\"008c80ae05353cedff97a531fbca0f4e626dfbe16822ed82f9868495e887a6e2\"},{\"algorithm\":\"ecdsa-sha2-nistp256\",\"line_sha256\":\"8ef2fdb8c060387ce82f66221713faeef4c7d27895d2dbd92bc87aa375b94172\"},{\"algorithm\":\"ssh-ed25519\",\"line_sha256\":\"e13c7f631cc347a1c52f5816326189542f8d3a1ca6d31ad596aa422aa9e9ac3e\"}],\"rc\":0},{\"err\":\"\",\"host\":\"chat.gram1.ru\",\"keys\":[{\"algorithm\":\"ssh-rsa\",\"line_sha256\":\"15a9ce01047aa6d86b0a7f323187062c126d2f7f8c3d5b7cdf47b89f96f94f7a\"},{\"algorithm\":\"ecdsa-sha2-nistp256\",\"line_sha256\":\"db8a2e358b3d2b62ad43991f34fdc76ee85a43ea39efaf9bb2420a89ee42fdb4\"},{\"algorithm\":\"ssh-ed25519\",\"line_sha256\":\"d5f95e577619b811e15cb286ce4661f3835450b79e138717f7283ffbb4eabc63\"}],\"rc\":0},{\"err\":\"getaddrinfo newfi-staging.gram1.ru: Name or service not known\\ngetaddrinfo newfi-staging.gram1.ru: Name or service not known\\ngetaddrinfo newfi-staging.gram1.ru: Name or service not known\\n\",\"host\":\"newfi-staging.gram1.ru\",\"keys\":[],\"rc\":1}]\nEXPLICIT_SSH_CANDIDATES=[{\"host\":\"[PRIVATE_IP]\",\"source\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/verify.sh:9\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/srv/homelab-ops/tasks/cluster-cloud-quorum-vm160-canary-v1/phases/preflight.sh:9\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/srv/homelab-ops/tasks/snikket-edge-cutover-v1/tools/cutover.py:16\",\"user\":\"debian\"},{\"host\":\"185.225.35.6\",\"source\":\"/srv/homelab-ops/docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md:845\",\"user\":\"edgeadmin\"},{\"host\":\"100.100.131.41\",\"source\":\"/srv/homelab-ops/kb/private/access.json:7\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:2323\",\"user\":\"debian\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:4448\",\"user\":\"debian\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:4455\",\"user\":\"debian\"},{\"host\":\"pve01\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:8104\",\"user\":\"root\"},{\"host\":\"pve02\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:8104\",\"user\":\"root\"},{\"host\":\"pve03.\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:8104\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP].\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:8106\",\"user\":\"debian\"},{\"host\":\"[PRIVATE_IP].\",\"source\":\"/etc/pve/HOMELAB_FULL_HANDOFF_HISTORICAL_2026-07-09.md:8107\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:3109\",\"user\":\"edgeadmin\"},{\"host\":\"pve03\",\"source\":\"/etc/pve/HOMELAB_ASSISTANT_ERROR_REGISTER.md:3267\",\"user\":\"root\"},{\"host\":\"[PRIVATE_IP]\",\"source\":\"/root/post-reboot-pve01-check.sh:32\",\"user\":\"debian\"}]\nTRUSTED_FRONTEND_SSH_READONLY_ATTEMPTS=[]\nFINAL_DECISION=NO_TRUSTED_BEGET_FRONTEND_SSH_PATH_VERIFIED\nVPS_FRONTEND_DISCOVERY6_END=true\n"
}