1
0
Files
homelab-public-context/runtime/latest.json
T

39 lines
11 KiB
JSON

{
"schema_version": 1,
"channel": "homelab-runtime",
"command_id": "SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1",
"status": "OK",
"rc": 0,
"host": "pve01",
"mode": "read-only",
"component": "homelab-backup-git-push-route-rca",
"started_at_utc": "2026-09-21T02:17:42Z",
"finished_at_utc": "2026-09-21T02:17:45Z",
"reference_register_checked": true,
"reference_sha256": "5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66",
"error_register_checked": true,
"error_register_sha256": "3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0",
"command_sha256": "af88af9350b0bf23b8c37a94b0c520545170e33e839524b750f1d74c7761139a",
"duplicate_failed_command_blocked": false,
"block_reason": null,
"execution_started": true,
"change_declared": false,
"result_contract_valid": true,
"result_contract_status": null,
"result_contract_error": null,
"command_rc": 0,
"changes_made": false,
"rollback_started": false,
"rollback_restored": null,
"mutation_outcome": "NO_MUTATION",
"sanitized": true,
"secrets_included": false,
"private_addresses_included": false,
"raw_evidence_retained_locally": true,
"raw_evidence_sha256": "bde5b53dae7c17e77083db11c8da3df556a47ee2b18b4127063fbf2b28ced1f8",
"sanitized_output_sha256": "bde5b53dae7c17e77083db11c8da3df556a47ee2b18b4127063fbf2b28ced1f8",
"output_truncated_in_json": false,
"full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt",
"output": "WORKERS2_BACKUP_GIT_PUSH_ROUTE_RCA_BEGIN=1\nCOMMAND_ID=SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1\nMODE=read-only\nCOMPONENT=homelab-backup-git-push-route-rca\nHOST=pve01\nUID=0\nMUTATION_BOUNDARY=READ_ONLY_GIT_CONFIG_AND_NETWORK_DRY_RUN_ONLY_NO_FETCH_NO_CHECKOUT_NO_RESET_NO_COMMIT_NO_PUSH_UPDATE_NO_PRODUCTION_NO_SERVICE_ACTION_NO_BACKUP_NO_RESTORE_NO_RETENTION_NO_DELETE_NO_MAIL\nWORKTREE_BRANCH=cr-2026-1005-backup-v2-health-alerting-remediation\nWORKTREE_HEAD=46c6f9aaf8fa93ce9f0cee686f948704c1a61336\nWORKTREE_HEAD_EXPECTED=true\nWORKTREE_CLEAN=true\nWORKTREE_STATUS_LINES=[]\nLIVE_POLICY_META={\"baseline_match\":true,\"exists\":true,\"expected_baseline\":\"ea6526bec7d7591bef876799cecddff4849631a936edc9f593b47211fbad715c\",\"sha256\":\"ea6526bec7d7591bef876799cecddff4849631a936edc9f593b47211fbad715c\"}\nLIVE_HELPER_META={\"baseline_match\":true,\"exists\":true,\"expected_baseline\":\"6b7ec1ab3ee1c540a9113b5620c3b4b5a50de6536f3a069d31b2e1243f23bafa\",\"sha256\":\"6b7ec1ab3ee1c540a9113b5620c3b4b5a50de6536f3a069d31b2e1243f23bafa\"}\nORIGIN_FETCH_URL_META={\"fragment_present\":false,\"host\":\"git.gram1.ru\",\"kind\":\"url\",\"path\":\"/homelab-admin/homelab-ops.git\",\"port\":null,\"present\":true,\"query_present\":false,\"safe_display\":\"https://git.gram1.ru/homelab-admin/homelab-ops.git\",\"scheme\":\"https\",\"sha256\":\"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9\",\"userinfo_present\":false}\nORIGIN_PUSH_URL_META={\"kind\":\"sentinel\",\"present\":true,\"sha256\":\"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12\",\"value\":\"DISABLED\"}\nORIGIN_FETCH_URL_SOURCE={\"rc\":0,\"rows\":[{\"origin\":\"file:/srv/homelab-ops/.git/config\",\"scope\":\"local\",\"value_meta\":{\"fragment_present\":false,\"host\":\"git.gram1.ru\",\"kind\":\"url\",\"path\":\"/homelab-admin/homelab-ops.git\",\"port\":null,\"present\":true,\"query_present\":false,\"safe_display\":\"https://git.gram1.ru/homelab-admin/homelab-ops.git\",\"scheme\":\"https\",\"sha256\":\"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9\",\"userinfo_present\":false}}],\"stderr_sha256\":null}\nORIGIN_PUSH_URL_SOURCE={\"rc\":0,\"rows\":[{\"origin\":\"file:/srv/homelab-ops/.git/config\",\"scope\":\"local\",\"value_meta\":{\"kind\":\"sentinel\",\"present\":true,\"sha256\":\"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12\",\"value\":\"DISABLED\"}}],\"stderr_sha256\":null}\nMAIN_ORIGIN_FETCH_URL_META={\"fragment_present\":false,\"host\":\"git.gram1.ru\",\"kind\":\"url\",\"path\":\"/homelab-admin/homelab-ops.git\",\"port\":null,\"present\":true,\"query_present\":false,\"safe_display\":\"https://git.gram1.ru/homelab-admin/homelab-ops.git\",\"scheme\":\"https\",\"sha256\":\"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9\",\"userinfo_present\":false}\nMAIN_ORIGIN_PUSH_URL_META={\"kind\":\"sentinel\",\"present\":true,\"sha256\":\"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12\",\"value\":\"DISABLED\"}\nREMOTE_METADATA=[{\"fetch\":{\"fragment_present\":false,\"host\":\"git.gram1.ru\",\"kind\":\"url\",\"path\":\"/homelab-admin/homelab-ops.git\",\"port\":null,\"present\":true,\"query_present\":false,\"safe_display\":\"https://git.gram1.ru/homelab-admin/homelab-ops.git\",\"scheme\":\"https\",\"sha256\":\"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9\",\"userinfo_present\":false},\"name\":\"origin\",\"push\":{\"kind\":\"sentinel\",\"present\":true,\"sha256\":\"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12\",\"value\":\"DISABLED\"}}]\nGIT_CONFIG_ENV_OVERLAY=[]\nEXPLICIT_FETCH_URL_LS_REMOTE={\"combined_sha256\":\"7b8ab49b5592ffea89971a6a8059abaf434142cd964f9d26c957c2d75e8f20e9\",\"lines\":[\"326622a4864fa9b5f43b69981733236bb42c4d7b\\trefs/heads/main\"],\"rc\":0}\nEXPLICIT_MAIN_SHA=326622a4864fa9b5f43b69981733236bb42c4d7b\nREMOTE_TARGET_BRANCH_SHA=null\nREMOTE_TARGET_BRANCH_ABSENT=true\nEXPLICIT_FETCH_URL_PUSH_DRY_RUN={\"combined_sha256\":\"7a93936ba141ba96f5779a108732095ee5de42822d60f23391d4797743894652\",\"lines\":[\"To <GIT_URL_REDACTED>\",\"*\\tHEAD:refs/heads/cr-2026-1005-backup-v2-health-alerting-remediation\\t[new branch]\",\"Done\"],\"rc\":0}\nLOCAL_GIT_PUSH_HELPER_PATHS=[]\nCANONICAL_PUSH_PATTERN_LINES=[\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:13:- CR `origin` fetch points to Gitea while `origin` push is deliberately `<GIT_URL_REDACTED>`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:17:1. Freshly verify source HEAD/clean state, reference SHA, read/write credentials, remote branch absence, Gitea fetch URL, and `origin` push URL `<GIT_URL_REDACTED>`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:40:- source `origin` fetch still points to Gitea and push remains `<GIT_URL_REDACTED>`;\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:28:- Boundary: safe-run KB/auth/check-only succeeded. Phase B created local commit `710dc3036d9a2d3fcfba687559253f28b298bf8b` and failed only at `git push`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:34:## CMD-1403 \\u2014 SOURCE_AUDIT_FIX / SYMBOLIC ORIGIN PUSH TARGET `<GIT_URL_REDACTED>`\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:36:- Symptom: `CR0086_RECEIPT|cmd_id=1403|status=ERROR|rc=1`; Phase B state recorded `GIT_PUSH_RC_128` with diagnostic `fatal: '<GIT_URL_REDACTED>' does not appear to be a git repository`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:38:- Root cause: v2 verified remote access with the explicit Gitea repository URL but executed `git push origin`. The CR worktree intentionally separates `origin` fetch and push destinations: fetch resolves to Gitea while push resolves to `<GIT_URL_REDACTED>`. The preflight never audited `git remote get-url --push origin`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:39:- Invalid assumption: a valid fetch URL, valid write token, and successful explicit `ls-remote` do not imply that symbolic remote `origin` uses the same URL for push. Git supports a separate `remote.<name>.pushurl`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:42:- Prevention: `remote.origin.pushurl=<GIT_URL_REDACTED>` is now a required safety invariant. Source publication must never change or bypass that setting from the CR worktree. A temporary isolated publisher clone imports the local commit, publishes through the explicit Gitea URL with the separated write credential and an absent-ref `--force-with-lease`, verifies the exact remote SHA, and is destroyed. All network readback and compensation use the explicit repository URL rather than symbolic `origin`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:67:CMD-1400 proved that the default root Git credential must remain read-only. The v1 remediation correctly installed a `read:repository` credential for `git.gram1.ru`, allowing `homelab-safe-run` to perform its mandatory authenticated `ls-remote` and shallow clone. The same credential cannot be used for `git push`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:80:CMD-1403 proved that the CR worktree's Git remote has intentionally different fetch and push behavior. `origin` fetch resolves to `<GIT_URL_REDACTED>`, while `origin` push resolves to `<GIT_URL_REDACTED>`. This is a safety feature, not a broken remote.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:88:- after publication, the remote ref must equal the exact local commit SHA and the source worktree must still report the original Gitea fetch URL plus push URL `<GIT_URL_REDACTED>`;\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Pre_Command_Contract_20260823.md:69:- `git remote get-url --push origin` \\u2192 `<GIT_URL_REDACTED>`.\",\"HEAD:docs/operations/workers2/2026-08-23/Workers2_Pre_Command_Contract_20260823.md:71:`<GIT_URL_REDACTED>` is an invariant to preserve, not a value to replace. A source publisher must use a disposable isolated repository and the explicit audited Gitea URL. No source command may infer push routing from the fetch URL, and no final readback may use symbolic `origin` for a network assertion.\",\"HEAD:docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md:23:- No blind `git fetch`, `git pull`, `git push`, reset, checkout, or canonical dirty-tree cleanup.\"]\nCANONICAL_PUSH_PATTERN_COUNT=15\nRCA_DECISION=ORIGIN_PUSHURL_DISABLED_EXPLICIT_FETCH_URL_DRY_RUN_PUSH_CAPABLE\nNO_MUTATION=true\nNO_GIT_FETCH=true\nNO_GIT_COMMIT=true\nNO_GIT_PUSH_UPDATE=true\nNETWORK_OPERATION=LS_REMOTE_PLUS_PUSH_DRY_RUN_ONLY\nNO_PRODUCTION_MUTATION=true\nNO_SERVICE_ACTION=true\nNO_BACKUP_STARTED=true\nNO_RESTORE_STARTED=true\nNO_RETENTION_STARTED=true\nNO_DELETE=true\nNO_MAIL_SENT=true\nRCA_DURATION_SEC=2.74\nTASK_RESULT=PASS_HOMELAB_BACKUP_GIT_PUSH_ROUTE_RCA_READONLY\nHOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1\",\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"OK\",\"version\":1}\nWORKERS2_BACKUP_GIT_PUSH_ROUTE_RCA_END=1\n"
}