Skip to content

feat(ansible): install Koncreet host hardening with an Ubuntu 26.04 patch - #28

Merged
undeemed merged 7 commits into
mainfrom
fm/cf-koncreet-u26-k4
Oct 1, 2026
Merged

undeemed merged 7 commits into
mainfrom
fm/cf-koncreet-u26-k4

Conversation

@undeemed

@undeemed undeemed commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Intent

"https://github.com/jimididit/koncreet add this as well for new machine"

"wtf? can we make a ubuntu 26 version then"

"dont need upstream pr, just make a fork"

Context for reading those asks: Koncreet (jimididit/koncreet, MIT, plain Bash, latest release v0.2.4) is a first-hour hardening toolkit for a fresh Linux VPS: a baseline (sudo user, SSH keys, sysctl, swap, journald, timezone/NTP), a ufw default-deny firewall, fail2ban, unattended security updates, and an SSH hardening module that turns off password and root login only once a sudo user with keys already exists. Its OS gate (lib/os.sh) refuses everything except Debian 12/13 and Ubuntu 22.04/24.04. This host and Code-Factory's current target are Ubuntu 26.04 LTS ("resolute"), so upstream Koncreet refuses to run there; the second ask is to make it work on 26.04. Code-Factory does no firewall or SSH hardening today; its docs say UFW and sshd stay manual (ansible/tasks/tailscale.yml). The operator's standing model is that tools track the latest upstream release, with his own changes layered on top separately. The third ask replaces an upstream pull request with a fork of jimididit/koncreet that carries the Ubuntu 26.04 change.

What Changed

  • Adds an optional Koncreet install (ansible/tasks/koncreet.yml, imported from site.yml). It runs on hosts with start_services: true and not in the container image. scripts/install_tools.py resolves the latest jimididit/koncreet release, verified against its GitHub SHA-256 digest. Any lookup, digest or download failure skips Koncreet with a warning and the rest of the apply continues. Apply installs it as root under /usr/local/lib/code-factory/koncreet/<version>-<patch hash>, links /usr/local/bin/koncreet, and renders /etc/koncreet.conf from the new koncreet.conf.j2. The config never makes the factory user a sudo user. Apply never runs Koncreet. The hand-run steps and lockout recovery are in docs/security.md.
  • Adds patches/koncreet/ubuntu-26.04.patch, layered on each release. It adds 26.04 to the OS gate and doctor, and falls back to loginctl for the SSH client address because 26.04 has no utmp. The task prints whether the patch applied, was skipped because the release already supports 26.04, or was skipped because it no longer applies.
  • install_tools.py now rejects release tags that are not plain versions (e.g. v1;id) for every tool, and preflight.yml warns about optional tools that were skipped. Docs (docs/security.md, dependencies.md, architecture.md, CONTRIBUTING.md) are updated. New tests cover the Koncreet resolution and skip paths, config rendering per tailscale profile and apply user, and the digest-failure and --check behavior of the playbook tasks. CI installs fakeroot so those tests run unprivileged.

Risk Assessment

✅ Low: Koncreet is installed but never run by apply, and every failure (lookup, digest, download, patch, link) is rescued with a warning, so apply continues. The version regex, the digest-gated root-owned install and the factory-user guard in the config template all hold on the paths I traced. I found no source-backed defect or intent contradiction.

Testing

The koncreet files (koncreet.yml, the template, the patch, preflight.yml, the container config) are byte-identical to d72af44, which the earlier rounds validated. Only base-merge changes landed after it, so the reused evidence still matches the tree. This run I drove the real playbook against the real v0.2.4 release. The fakeroot sandbox could not write /usr/local/bin and was rescued at the link step, so I use it only as evidence for patch-applied, digest-mismatch skip and 404 skip, and I relabeled that file with a scope note. Install, link, config render and idempotence are shown by the mount-namespace run at real paths and by a fresh 24.04 container, both with rescued=0. A mismatch skips koncreet, installs and links nothing, writes no config, and the next task still runs. A correct digest then installs it. A second apply keeps an edit made to the rendered config. The config rules for tailscale on or off, the factory user and root hold. Patched koncreet passes the OS gate on 26.04 and upstream does not, and the fork diff is byte-identical to the shipped patch. The 20 targeted tests pass. Three scenarios are marked untested because the payload does not establish a live result for them: the optional-lookup failure scenario (resolver run only against injected faults in pytest; the live 403 run is from an earlier round), the worker-image exclusion scenario (not rebuilt; rests on a passing test and earlier-round evidence), and the digest-test and CI scenario (workflow not run; YAML parsed and mutation proof from an earlier round). There is no UI surface, so no screenshots.

  • Live validation: ✅ go - 7 of 10 scenarios driven live against the product
Scenario Result Live Evidence
Operator installs the real v0.2.4 release on Ubuntu 26.04: it installs root-owned, the 26.04 patch is applied, /usr/local/bin/koncreet is linked, and koncreet doctor says 'OS ubuntu 26.04 supported' ✅ pass live live-round4-real-paths-mountns-overlay.txt section B (rescued=0, link and doctor output). The fakeroot file shows only that the patch applied.
Unpatched upstream v0.2.4 on the same 26.04 host fails the OS gate, so the patch is needed ✅ pass live live-round4-fakeroot-patch-digest-404-only.txt section 2c; host-26.04-patched-vs-unpatched.txt from an earlier round. Upstream lib/os.sh has 0 matches for '26.04'.
Fork request: undeemed/koncreet has an ubuntu-26.04 branch whose diff against main is byte-identical to the shipped patches/koncreet/ubuntu-26.04.patch ✅ pass live git ls-remote showed refs/heads/ubuntu-26.04. cmp of the compare diff against the patch printed BYTE-IDENTICAL (68 lines).
Adversarial: publisher digest does not match the tarball. Apply warns 'koncreet skipped, apply continues', installs and links nothing, writes no config, and the later task still runs ✅ pass live live-round4-real-paths-mountns-overlay.txt section A (rescued=1, no link, no /etc/koncreet.conf). live-round4-24.04-container-head-koncreet.txt (mismatch, later task ran). live-round4-fakeroot-patch-d…
Adversarial: tarball URL returns 404. Apply skips koncreet with a warning and the later task still runs ✅ pass live live-round4-fakeroot-patch-digest-404-only.txt section 5
Recovery and idempotence: after a mismatch the correct digest installs. A second apply skips all six install tasks, and an edit appended to the rendered /etc/koncreet.conf survives (force: false) ✅ pass live live-round4-real-paths-mountns-overlay.txt sections B and C: the template task ran with rescued=0 and '# operator edit' was preserved. The fakeroot run is not used here, because its template task neve…
Config rules: tailscale on gives firewall_ports=41641/udp and off gives none. Apply as the factory user or root comments out user= and pubkey_file= and says why. ssh is not in the module list. The ope… ✅ pass live live-round4-real-paths-mountns-overlay.txt sections B (dry-run plan), D, E, F. The 4-way parametrized pytest also passed.
Optional lookup: a release with no SHA-256 or no asset, an unsafe tag, or a failed or 403 lookup is skipped with a warning and the resolver exits 0, so apply is not blocked ⏸️ untested no The prior payload did not establish a live result. In this run the real resolver CLI was exercised only against injected faults through pytest (test_koncreet_release_* and test_koncreet_lookup_failure…
Container worker image excludes koncreet: it is resolved only when start_services is true ⏸️ untested no The prior payload did not establish a live result. The worker image was not rebuilt in this run, per the user's instructions, so the exclusion was never observed in a running image. It rests on pytest…
Digest test is not vacuous and CI installs fakeroot: the test passes with fakeroot present, and its skip reason is the checksum failure at 'Fetch the koncreet tarball' ⏸️ untested no The prior payload did not establish a live result. The CI workflow was not run in this run. Only its YAML was parsed (fakeroot install is step 5, pytest is step 6) and the local pytest run showed 20 p…
Evidence: Targeted koncreet pytest at HEAD (20 passed, 0 skipped)
....................                                                     [100%]
20 passed, 85 deselected in 14.75s
Evidence: Mount-namespace run at real paths on 26.04: mismatch skip, recovery, link, doctor, dry-run, idempotence, config variants
uid=0 os=26.04
\### A. mismatch first (real paths): nothing linked, no conf
fatal: [localhost]: FAILED! => {"changed": false, "checksum_dest": null, "checksum_src": "8e6b51c5ef93cf3f11089d4c32eb0704d79d9d27", "dest": "/usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a.tar.gz", "elapsed": 0, "msg": "The checksum for /root/.ansible/tmp/ansible-tmp-1790851475.5507374-20193-217194390741575/tmpv35htpi_ did not match 0000000000000000000000000000000000000000000000000000000000000000; it was 3ac13e2925414c49dd8697e4b77c863ed91f173dadb226031ada0c97042fa3a3.", "src": "/root/.ansible/tmp/ansible-tmp-1790851475.5507374-20193-217194390741575/tmpv35htpi_", "url": "https://github.com/jimididit/koncreet/releases/download/v0.2.4/koncreet.tar.gz"}
    "msg": "WARNING: koncreet skipped, apply continues. Fetch the koncreet tarball: The checksum for /root/.ansible/tmp/ansible-tmp-1790851475.5507374-20193-217194390741575/tmpv35htpi_ did not match 0000000000000000000000000000000000000000000000000000000000000000; it was 3ac13e2925414c49dd8697e4b77c863ed91f173dadb226031ada0c97042fa3a3."
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=0    rescued=1    ignored=0   
ls: cannot access '/usr/local/bin/koncreet': No such file or directory
ls: cannot access '/etc/koncreet.conf': No such file or directory
\### B. recovery: correct digest installs, links, renders conf (operator, tailscale on)
    "msg": "koncreet 0.2.4: patch applied: Ubuntu 26.04 support layered on this release"
localhost                  : ok=12   changed=7    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0   
-rw-r--r-- 1 root root 1189 Oct  1 10:44 /etc/koncreet.conf
lrwxrwxrwx 1 root root   73 Oct  1 10:44 /usr/local/bin/koncreet -> /usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a/koncreet/koncreet
drwxr-xr-x 3 root root  80 Oct  1 10:44 /usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a/
drwxr-xr-x 2 root root 160 Oct  1 10:44 /usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a/koncreet/lib
patch applied: Ubuntu 26.04 support layered on this release
--- doctor via /usr/local/bin/koncreet

> koncreet doctor
  version        0.2.4
  [OK] OS ubuntu 26.04 supported
  [OK] running as root (apply ready)
  [OK] apt-get available
--- rendered /etc/koncreet.conf (operator, tailscale on)
modules=baseline,firewall,fail2ban,updates
user=operator
pubkey_file=~/.ssh/authorized_keys
firewall_ports=41641/udp
firewall_public=false
fail2ban_services=ssh
auto_reboot=false
--- dry-run feeding rendered conf to real koncreet
  · Loaded config /etc/koncreet.conf

Change plan
───────────
  - Create/ensure sudo user 'operator' and install SSH keys
  - Install pubkey from file ~/.ssh/authorized_keys
  - Write cloud-safer sysctl drop-in /etc/sysctl.d/99-koncreet.conf
  - Ensure swapfile if none active (cap 2G)
  - Cap journald SystemMaxUse=200M
  - Install logrotate for /var/log/koncreet.log
  - Install MOTD note (update-motd.d)
  - Ensure time sync (systemd-timesyncd or chrony)
  - Install ufw if needed
  - Default deny incoming / allow outgoing
  - Allow SSH on 22/tcp
  - Open custom ports: 41641/udp
  - Enable ufw (snapshot rules for undo)
  - Install fail2ban
  - Write /etc/fail2ban/jail.d/99-koncreet.conf (backend=systemd, banaction=ufw if ufw active)
  - Enable jails for: ssh
  - Enable and restart fail2ban; verify sshd jail is running
  - Install unattended-upgrades
  - Enable APT::Periodic daily refresh + unattended-upgrade
  - Write distro-correct origins policy for ubuntu
  - Automatic-Reboot=false at 04:00
\### C. second apply: install skipped, conf preserved
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
localhost                  : ok=6    changed=1    unreachable=0    failed=0    skipped=6    rescued=0    ignored=0   
# operator edit
\### D. factory user + tailscale off -> conf withholds sudo user and tailscale rules (fresh conf)
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=6    rescued=0    ignored=0   
modules=baseline,firewall,fail2ban,updates
# Apply ran as coder, the factory account that runs the agents and
# user=<operator login>
# pubkey_file=/home/<operator login>/.ssh/authorized_keys
# The tailscale profile is off, so no Tailscale port or interface is opened.
\### E. root + tailscale on
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=6    rescued=0    ignored=0   
# Apply ran as root, so the operator account is unknown. Set both before use:
# user=<operator login>
# pubkey_file=/home/<operator login>/.ssh/authorized_keys
firewall_ports=41641/udp
\### F. operator + tailscale off
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
skipping: [localhost]
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=6    rescued=0    ignored=0   
modules=baseline,firewall,fail2ban,updates
user=operator
pubkey_file=~/.ssh/authorized_keys
# The tailscale profile is off, so no Tailscale port or interface is opened.
Evidence: Ubuntu 24.04 container at HEAD: mismatch skip, then install, link and doctor
container: Ubuntu 24.04
ansible-playbook [core 2.16.3]
\### mismatch
[WARNING]: No inventory was parsed, only implicit localhost is available
    "msg": "WARNING: koncreet skipped, apply continues. Fetch the koncreet tarball: The checksum for /usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a.tar.gz did not match 0000000000000000000000000000000000000000000000000000
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=0    rescued=1    ignored=0   
ls: cannot access '/usr/local/bin/koncreet': No such file or directory
ls: cannot access '/etc/koncreet.conf': No such file or directory
later: yes
\### good
[WARNING]: No inventory was parsed, only implicit localhost is available
    "msg": "koncreet 0.2.4: patch applied: Ubuntu 26.04 support layered on this release"
localhost                  : ok=12   changed=7    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0   
lrwxrwxrwx 1 root root 73 Oct  1 10:46 /usr/local/bin/koncreet -> /usr/local/lib/code-factory/koncreet/0.2.4-701cb5befe1a/koncreet/koncreet

> koncreet doctor
  version        0.2.4
  [OK] OS ubuntu 24.04 supported
patch applied: Ubuntu 26.04 support layered on this release
Evidence: Fakeroot run, scoped to patch-applied, digest-mismatch skip and 404 skip only (not an install or idempotence proof; scope note inside)
## SCOPE NOTE: this fakeroot run proves ONLY: real v0.2.4 tarball verified and extracted, 26.04 patch applied (section 2/2b), digest-mismatch skip (section 4) and 404 skip (section 5).
## It does NOT prove install-complete, link, config render, or idempotence: sections 2 and 3 were rescued at 'Link koncreet into /usr/local/bin' (hard-coded path, fakeroot cannot write it), so the template task never ran and the '# operator edit' line in section 3 is only a seeded file.
## Install, link, render and idempotence evidence: live-round4-real-paths-mountns-overlay.txt (sections B, C) and live-round4-24.04-container-head-koncreet.txt.

\### 2. clean install, real tarball + digest
TASK [Hash the Ubuntu 26.04 koncreet patch] ************************************
TASK [Name the koncreet release directory] *************************************
TASK [Stat the installed koncreet release] *************************************
TASK [Create the koncreet release directory] ***********************************
TASK [Fetch the koncreet tarball] **********************************************
TASK [Extract koncreet] ********************************************************
TASK [Remove the koncreet tarball] *********************************************
TASK [Layer the Ubuntu 26.04 patch on the release] *****************************
TASK [Report the koncreet release and patch outcome] ***************************
    "msg": "koncreet 0.2.4: patch applied: Ubuntu 26.04 support layered on this release"
TASK [Link koncreet into /usr/local/bin] ***************************************
93             msg: "koncreet {{ factory_latest.koncreet.version }}: {{ factory_koncreet_outcome.stdout }}"
fatal: [localhost]: FAILED! => {"changed": false, "msg": "Error while linking: [Errno 13] Permission denied: b'/tmp/kc-live/a/prefix/0.2.4-701cb5befe1a/koncreet/koncreet' -> b'/usr/local/bin/koncreet'", "path": "/usr/local/bin/koncreet"}
TASK [Skip koncreet] ***********************************************************
    "msg": "WARNING: koncreet skipped, apply continues. Link koncreet into /usr/local/bin: Error while linking: [Errno 13] Permission denied: b'/tmp/kc-live/a/prefix/0.2.4-701cb5befe1a/koncreet/koncreet' -> b'/usr/local/bin/koncreet'"
PLAY RECAP *********************************************************************
localhost                  : ok=11   changed=6    unreachable=0    failed=0    skipped=0    rescued=1    ignored=0   
--- state
total 0
drwxr-xr-x 3 ubuntu ubuntu 60 Oct  1 10:43 .
drwxrwxr-x 3 ubuntu ubuntu 60 Oct  1 10:43 ..
drwxr-xr-x 3 ubuntu ubuntu 80 Oct  1 10:43 0.2.4-701cb5befe1a
koncreet
patch-outcome
patch applied: Ubuntu 26.04 support layered on this release
ls: cannot access '/tmp/kc-live/a/prefix/*.tar.gz': No such file or directory
--- 2b. doctor via installed (patched) koncreet on this 26.04 host

> koncreet doctor
  version        0.2.4
  [OK] OS ubuntu 26.04 supported
--- 2c. unpatched upstream tarball on same host

> koncreet doctor
  version        0.2.4
\### 3. second apply is a no-op for install and keeps the config
TASK [Hash the Ubuntu 26.04 koncreet patch] ************************************
TASK [Name the koncreet release directory] *************************************
TASK [Stat the installed koncreet release] *************************************
TASK [Create the koncreet release directory] ***********************************
skipping: [localhost]
TASK [Fetch the koncreet tarball] **********************************************
skipping: [localhost]
TASK [Extract koncreet] ********************************************************
skipping: [localhost]
TASK [Remove the koncreet tarball] *********************************************
skipping: [localhost]
TASK [Layer the Ubuntu 26.04 patch on the release] *****************************
skipping: [localhost]
TASK [Report the koncreet release and patch outcome] ***************************
skipping: [localhost]
TASK [Link koncreet into /usr/local/bin] ***************************************
93             msg: "koncreet {{ factory_latest.koncreet.version }}: {{ factory_koncreet_outcome.stdout }}"
fatal: [localhost]: FAILED! => {"changed": false, "msg": "Error while linking: [Errno 13] Permission denied: b'/tmp/kc-live/a/prefix/0.2.4-701cb5befe1a/koncreet/koncreet' -> b'/usr/local/bin/koncreet'", "path": "/usr/local/bin/koncreet"}
TASK [Skip koncreet] ***********************************************************
    "msg": "WARNING: koncreet skipped, apply continues. Link koncreet into /usr/local/bin: Error while linking: [Errno 13] Permission denied: b'/tmp/kc-live/a/prefix/0.2.4-701cb5befe1a/koncreet/koncreet' -> b'/usr/local/bin/koncreet'"
PLAY RECAP *********************************************************************
localhost                  : ok=5    changed=1    unreachable=0    failed=0    skipped=6    rescued=1    ignored=0   
# operator edit
\### 4. digest mismatch skips with warning, apply continues, nothing installed
TASK [Hash the Ubuntu 26.04 koncreet patch] ************************************
TASK [Name the koncreet release directory] *************************************
TASK [Stat the installed koncreet release] *************************************
TASK [Create the koncreet release directory] ***********************************
TASK [Fetch the koncreet tarball] **********************************************
fatal: [localhost]: FAILED! => {"changed": false, "checksum_dest": null, "checksum_src": "8e6b51c5ef93cf3f11089d4c32eb0704d79d9d27", "dest": "/tmp/kc-live/b/prefix/0.2.4-701cb5befe1a.tar.gz", "elapsed": 0, "msg": "The checksum for ~/.ansible/tmp/ansible-tmp-1790851409.8314385-5505-148773923169137/tmphpeby5x2 did not match 0000000000000000000000000000000000000000000000000000000000000000; it was 3ac13e2925414c49dd8697e4b77c863ed91f173dadb226031ada0c97042fa3a3.", "src": "~/.ansible/tmp/ansible-tmp-1790851409.8314385-5505-148773923169137/tmphpeby5x2", "url": "https://github.com/jimididit/koncreet/releases/download/v0.2.4/koncreet.tar.gz"}
TASK [Skip koncreet] ***********************************************************
    "msg": "WARNING: koncreet skipped, apply continues. Fetch the koncreet tarball: The checksum for ~/.ansible/tmp/ansible-tmp-1790851409.8314385-5505-148773923169137/tmphpeby5x2 did not match 0000000000000000000000000000000000000000000000000000000000000000; it was 3ac13e2925414c49dd8697e4b77c863ed91f173dadb226031ada0c97042fa3a3."
PLAY RECAP *********************************************************************
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=0    rescued=1    ignored=0   
/tmp/kc-live/b:
prefix

/tmp/kc-live/b/prefix:
0.2.4-701cb5befe1a
later task ran: yes
\### 5. tarball 404 skips
TASK [Hash the Ubuntu 26.04 koncreet patch] ************************************
TASK [Name the koncreet release directory] *************************************
TASK [Stat the installed koncreet release] *************************************
TASK [Create the koncreet release directory] ***********************************
TASK [Fetch the koncreet tarball] **********************************************
fatal: [localhost]: FAILED! => {"changed": false, "dest": "/tmp/kc-live/c/prefix/0.2.4-701cb5befe1a.tar.gz", "elapsed": 0, "msg": "Request failed", "response": "HTTP Error 404: Not Found", "status_code": 404, "url": "https://github.com/jimididit/koncreet/releases/download/v0.2.4/nope.tar.gz"}
TASK [Skip koncreet] ***********************************************************
    "msg": "WARNING: koncreet skipped, apply continues. Fetch the koncreet tarball: Request failed"
PLAY RECAP *********************************************************************
localhost                  : ok=6    changed=2    unreachable=0    failed=0    skipped=0    rescued=1    ignored=0   
later task ran: yes
0.2.4-701cb5befe1a
Evidence: Fork branch diff byte-identical to shipped patch (earlier round)
GET https://github.com/undeemed/koncreet/compare/main...ubuntu-26.04.diff -> 68 lines, files:
diff --git a/lib/doctor.sh b/lib/doctor.sh
diff --git a/lib/os.sh b/lib/os.sh
diff --git a/lib/sshd.sh b/lib/sshd.sh
diff fork-compare.diff patches/koncreet/ubuntu-26.04.patch: BYTE-IDENTICAL
701cb5befe1a327c101bb59f9efa67585f37087b946e2931dee61b0ec9c76a63  /tmp/fork-compare.diff
701cb5befe1a327c101bb59f9efa67585f37087b946e2931dee61b0ec9c76a63  patches/koncreet/ubuntu-26.04.patch
- Outcome: 🔧 1 issue found → auto-fixed → no changes applied ✅ across 4 runs (1h13m11s)

Pipeline

Updates from git push no-mistakes

... (3 earlier update rounds omitted to keep the PR body within GitHub's 65536-char limit; full history is in the run log.)

🔧 **Review** - 3 issues found → auto-fixed (2) ✅

🔧 Fix applied.
4 warnings still open:

  • ⚠️ ansible/group_vars/all.yml:189 - &#39;koncreet&#39; is added to factory_installer_also unconditionally, with no profile gate or opt-out. Resolution happens in preflight and fails hard: verified() raises if the release has no SHA-256 digest or the asset is renamed or missing, and fetch() raises on a 404 or rate limit. Concrete sequence: upstream publishes a release without koncreet.tar.gz, or GitHub rate-limits the lookup. resolve_latest raises, preflight aborts, and the whole ./factory apply stops for every profile (tailscale, agents and the rest). The tool is optional and is never run by apply, and the author made the patch step non-fatal on purpose, so the resolution and download steps contradict that goal. The unconditional install also reaches the Docker image build, which runs the same playbook, where a ufw/sshd hardening toolkit cannot be used. The intent was Koncreet 'for new machine'. A profile gate, or a soft-fail that skips Koncreet with a warning, would fix this. Both change behavior, so this needs the author's decision.
  • ⚠️ ansible/templates/koncreet.conf.j2:1 - Simplification: the intent asks for Koncreet to be added to the new-machine setup and for Ubuntu 26.04 support. No requirement asks for a rendered /etc/koncreet.conf. Rendering it adds policy the user never specified: a module list that leaves out ssh, firewall_ports=41641/udp opened even when the Tailscale profile is off, and making the account that ran apply the sudo user via ansible_user_id/ansible_user_dir. It also adds a branch for apply-as-root and the factory_koncreet_config variable. The template comment says 'Not factory.user', but nothing guards ansible_user_id == factory_cfg.user, which factory_become_target treats as a supported mode. The narrower form is to install only the release (upstream already ships share/koncreet.conf.example in the tarball) and let the operator copy and edit it. The remedy is removal of the template task (ansible/tasks/koncreet.yml:96), factory_koncreet_config (ansible/group_vars/all.yml:366) and the matching docs/security.md text.
  • ⚠️ ansible/templates/koncreet.conf.j2:1 - Still open after the fix round, which only changed the version handling. No intent requirement asks for a rendered /etc/koncreet.conf. The intent asks to add Koncreet to the new-machine setup and to make it work on Ubuntu 26.04. The template adds policy nobody asked for: a modules list without ssh, and firewall_ports=41641/udp opened even when the tailscale profile is off. It also makes the account that ran apply (ansible_user_id/ansible_user_dir, lines 17-19) the sudo user, and adds a root branch (lines 20-24). The key names match upstream's lib/config.sh, so this is not a correctness bug. A concrete defect sits inside the component. The comment at line 15 says 'Not factory.user ... must not gain sudo through this file', but nothing guards ansible_user_id == factory_cfg.user. factory_become_target (ansible/group_vars/all.yml:113) treats that case as supported. Running ./factory apply as the agent account renders user=&lt;agent&gt;, and the operator then follows the docs and makes the agent a sudo user. The smallest honest remedy is to remove the component, not to add the guard. Narrower form: install only the release, since upstream ships share/koncreet.conf.example in the tarball, and let the operator copy and edit it. Removal covers the template task (ansible/tasks/koncreet.yml:96-104), factory_koncreet_config (ansible/group_vars/all.yml:366), the template file, and the /etc/koncreet.conf text and -c /etc/koncreet.conf commands in docs/security.md (Host hardening section) and docs/dependencies.md.
  • ⚠️ ansible/group_vars/all.yml:190 - Still open. &#39;koncreet&#39; is added to factory_installer_also for every profile, with no gate or opt-out. Resolution happens in preflight (ansible/tasks/preflight.yml:93-98), before any other work. verified() raises when the release lists no SHA-256 or no koncreet.tar.gz asset. fetch() raises on a 404 or on rate limiting. Concrete sequence: GitHub rate-limits the lookup, or upstream publishes a release without the asset. resolve_latest raises and preflight aborts the whole ./factory apply for every profile, including hosts that never use the hardening tool. Koncreet is never run by apply. The same unconditional install reaches the Docker image build (the Dockerfile runs the same playbook), where a ufw/sshd toolkit has no use. The intent says to add it 'for new machine', so installing on every host may be intended. Whether an upstream Koncreet failure should block provisioning is a product decision. Options are a profile gate, or a soft-fail that skips Koncreet with a warning. Either option changes behavior, so the remedy needs the author's authorization. The same unconditional-resolution path is also visible at ansible/site.yml:112-115, where the import has no when:.

🔧 Fix applied.
✅ Re-checked - no issues remain.

✅ No issues found.

🔧 **Test** - 1 issue found → auto-fixed → no changes applied ✅
  • ⚠️ tests/test_configuration.py:664 - test_a_koncreet_tarball_that_fails_its_digest_is_skipped_and_apply_continues passed for the wrong reason when run unprivileged. koncreet.yml creates root-owned directories, and with ansible_become=False and no root the chown failed first. The skip warning read Create the koncreet release directory: chown failed, so the download was never checked. A correct digest gave the same skipped outcome (digest-test-vacuity.txt). I changed tests/test_configuration.py so _run_koncreet_tasks wraps the run in fakeroot when not root. The digest test also asserts the skip reason is Fetch the koncreet tarball: The checksum for .... With the get_url checksum line removed, the fixed test fails. With it restored, it passes (digest-test-mutation.txt). The --check planning test needs no root, so the fakeroot requirement applies only to runs that chown, and the planning test still runs when fakeroot is missing (digest-test-fakeroot-presence.txt). Product code is unchanged. One point needs a decision. .github/workflows/ci.yml runs uv run pytest as a non-root user on ubuntu-24.04 and has no step that installs fakeroot. CI therefore runs the digest test only if the runner image already has fakeroot. Otherwise the test skips, which shows only as s unless -rs is passed, and CI stays green with no digest coverage. I could not check the runner image from here. Options: add a fakeroot install step to ci.yml, or make the test fail instead of skip when CI is set. I did not change the workflow.
  • Live validation: ✅ go - 14 of 17 scenarios driven live against the product
Scenario Result Live Evidence
Latest koncreet resolves from the real GitHub API with its published SHA-256 under the full factory tool selection ✅ pass live resolve-live.txt: v0.2.4, sha256 3ac13e29…, exit 0
Rate limit, missing digest, missing asset or unsafe tag on koncreet's release lookup skips koncreet with a warning, exits 0, and other tools still resolve ✅ pass live resolve-live.txt and preflight-live.txt: all four faults print 'skipping optional koncreet', exit 0, and bun/herdr/node/uv still resolve. The faults were injected into the koncreet GitHub call only, v…
A non-optional tool lookup failure still hard-fails, so only koncreet is optional ✅ pass live Offline --also obscura --resolve failed with exit 1. The first rate-limited site.yml run also aborted with 'cannot resolve the latest gh release (HTTP 403)'.
Full apply path installs koncreet as released plus the 26.04 patch and links it (site.yml --tags always,koncreet) ✅ pass live site-koncreet-live.txt (S1): failed=0, link and conf present, patch-outcome 'patch applied'. Run as root in a bwrap user namespace with /usr/local redirected, plus a tar --no-same-owner shim for the u…
Re-applying the same release is a no-op for koncreet ✅ pass live koncreet-install-real.txt run 2: fetch, extract and patch skipped; link and conf ok; only the unrelated 'later' task changed
Digest mismatch on the real release tarball is skipped with a checksum warning; nothing installed or linked, no config rendered, later tasks still run, apply exits 0 ✅ pass live koncreet-failure-scenarios.txt (A): the warning shows 'checksum ... did not match', no link, no patch-outcome, no tarball, no conf, later task ran. Run as root in a bwrap user namespace and under fake…
404 asset URL skips koncreet and apply continues ✅ pass live koncreet-failure-scenarios.txt (B): 'WARNING: koncreet skipped ... Request failed', later task ran, exit 0
Rate-limit or missing-digest in the real preflight makes site.yml skip koncreet rather than abort ✅ pass live site-koncreet-live.txt (S2, S3): failed=0, the koncreet imports are skipped, the preflight prints the warning, and no link or conf is created
Container worker config (start_services=false) never resolves or installs koncreet, even when GitHub is faulted ✅ pass live preflight-live.txt P4 and site-koncreet-live.txt S4: no koncreet lookup and no skip warning (the same fault warns on the host config); tasks skipped. The Docker image build itself was not run; this dr…
Plan mode (--check) installs nothing and warns of nothing ✅ pass live koncreet-failure-scenarios.txt (E): nothing created, no WARNING in the output
Ubuntu 26.04 works: patched doctor and dry-run apply pass the OS gate on this host; unpatched upstream refuses ✅ pass live koncreet-doctor-patched.txt: '[OK] OS ubuntu 26.04 supported'. koncreet-dryrun-patched.txt: full change plan. koncreet-doctor-unpatched.txt: '[FAIL] OS ubuntu 26.04 not supported', and dry-run apply e…
The patch layers correctly across upstream states: applied, release already supports 26.04, no longer applies (installed as released) ✅ pass live koncreet-failure-scenarios.txt (C, D2) and the real-tarball run: each case reports its outcome and still installs and links. The C and D2 fixtures were built by modifying lib/os.sh in the real tarball…
Rendered /etc/koncreet.conf: 41641/udp and the tailscale0 hint appear only with the tailscale profile; the factory user or root never becomes the sudo user (user= and pubkey_file= stay commented, with… ✅ pass live koncreet-conf-matrix.txt (F1-F4), rendered through the real template task. The tailscale0 rule is only a comment hint because koncreet's firewall_ports takes ports, not interfaces.
The ubuntu-26.04 branch of the undeemed/koncreet fork exists and carries the same change as patches/koncreet/ubuntu-26.04.patch ✅ pass live fork-compare.txt: repo, branch and compare diff all return HTTP 200; the change lines are identical
SSH client IP fallback on 26.04, where who -m prints nothing: patched koncreet_ssh_client_ip asks logind; junk or missing input yields no IP ⏸️ untested no The prior payload did not establish a live result. It recorded live=false because the real patched and unpatched lib/sshd.sh functions were sourced with stubbed loginctl and who commands, not a re…
Koncreet's firewall does not reset existing ufw rules, so the tailscale0 allow survives the manual apply ⏸️ untested no A real koncreet apply would install ufw and change the operator's host firewall, and the workspace boundary forbids system-state changes outside the worktree. The sandbox cannot drive it either: it…
Digest unit test actually exercises the digest check (mutation: remove verification and the test must fail) ⏸️ untested no The prior payload did not establish a live result. It recorded live=false because this is a pytest mutation check (digest-test-vacuity.txt, digest-test-mutation.txt), not a run against the real runnin…
  • .venv/bin/pytest -k koncreet tests/test_install_tools.py tests/test_configuration.py (20 passed before my test change; 8 koncreet config tests passed after)
  • .venv/bin/pytest -k &#34;digest or planning&#34; tests/test_configuration.py with fakeroot on PATH (2 passed) and with it hidden (digest test skips with a reason, planning test passes)
  • install_tools.py --resolve --tools herdr,node,bun,uv --also koncreet against the real GitHub API: resolved v0.2.4 with the published SHA-256
  • The same resolve with faults injected into the koncreet GitHub call only (403 rate limit, no digest, no asset, unsafe tag): each skipped koncreet with a warning and exited 0. Offline obscura still hard-fails.
  • Real ansible/tasks/koncreet.yml with the real v0.2.4 tarball, real digest and real patch, run as root in a bwrap user namespace with /usr/local redirected: installed, linked, patch applied, config rendered. A second run was a no-op for the koncreet tasks.
  • Installed patched koncreet doctor and --dry-run apply -c &lt;rendered conf&gt; on this Ubuntu 26.04 host, compared with unpatched upstream, which refuses with Unsupported OS: ubuntu 26.04 (exit 2)
  • Patched koncreet_ssh_client_ip sourced from the real library with stubbed loginctl and who (stubs, not live): the logind fallback works when who is empty; junk and empty inputs return no IP
  • Failure scenarios through the real tasks: wrong digest on the real tarball, 404 asset URL, --check plan mode, a release that already supports 26.04, a release the patch no longer applies to
  • Rendered /etc/koncreet.conf matrix: tailscale on/off, apply user equal to the factory user, root, and re-apply not overwriting an operator edit
  • Real site.yml --tags always,koncreet: the host config installed koncreet; rate-limit and no-digest faults skipped it with failed=0; the container config never looked it up
  • Compared the undeemed/koncreet ubuntu-26.04 fork branch with patches/koncreet/ubuntu-26.04.patch (identical change lines)
  • Mutation check (pytest, not live): removed the get_url checksum line, the fixed digest test failed, then restored it and the test passed
  • Read ansible/tasks/koncreet.yml and the upstream tree for any ufw reset (code reading only, not driven)

🔧 Fix applied.
3 issues (1 error, 2 warnings) still open:

  • ⚠️ The Test agent did not finish within its invocation budget. Reported: agent run tests timed out after 30m0s: agent last produced output 157ms ago (2314 observed); agent reported: pi parse events: context deadline exceeded. The cut does not clear the findings reported alongside it. Re-running the same request costs another full budget, so no further attempt is made automatically. If this repository's targeted tests or evidence gathering routinely approach the default 30m0s, raise test_agent_timeout in global config. Respond with fix to spend another budget: a repair turn runs only for selected findings other than this budget cut, then validation re-runs. Or abort and retry after raising the budget.
  • 🚨 Approval is refused: the run worktree at ~/.no-mistakes/worktrees/5a80d6e36b53/01M3V8HZDS2XJ51RCQ6HFTMFPR holds work no Test turn validated, and the steps after Test would commit and publish it. It holds commits 58f2d11..d72af44, recorded locally as the run head and not pushed (inspect with git -C ~/.no-mistakes/worktrees/5a80d6e36b53/01M3V8HZDS2XJ51RCQ6HFTMFPR log -p 58f2d119db1f974b6ab24c39f48554cf72fe8bb7..d72af44269fad06a7e835dc8750dc46db4d0cdd9). Respond with fix to validate it, or abort.
  • ⚠️ tests/test_configuration.py:664 - test_a_koncreet_tarball_that_fails_its_digest_is_skipped_and_apply_continues passed for the wrong reason when run unprivileged. koncreet.yml creates root-owned directories, and with ansible_become=False and no root the chown failed first. The skip warning read Create the koncreet release directory: chown failed, so the download was never checked. A correct digest gave the same skipped outcome (digest-test-vacuity.txt). I changed tests/test_configuration.py so _run_koncreet_tasks wraps the run in fakeroot when not root. The digest test also asserts the skip reason is Fetch the koncreet tarball: The checksum for .... With the get_url checksum line removed, the fixed test fails. With it restored, it passes (digest-test-mutation.txt). The --check planning test needs no root, so the fakeroot requirement applies only to runs that chown, and the planning test still runs when fakeroot is missing (digest-test-fakeroot-presence.txt). Product code is unchanged. One point needs a decision. .github/workflows/ci.yml runs uv run pytest as a non-root user on ubuntu-24.04 and has no step that installs fakeroot. CI therefore runs the digest test only if the runner image already has fakeroot. Otherwise the test skips, which shows only as s unless -rs is passed, and CI stays green with no digest coverage. I could not check the runner image from here. Options: add a fakeroot install step to ci.yml, or make the test fail instead of skip when CI is set. I did not change the workflow.
  • Live validation: ✅ go - 14 of 17 scenarios driven live against the product
Scenario Result Live Evidence
Latest koncreet resolves from the real GitHub API with its published SHA-256 under the full factory tool selection ✅ pass live resolve-live.txt: v0.2.4, sha256 3ac13e29…, exit 0
Rate limit, missing digest, missing asset or unsafe tag on koncreet's release lookup skips koncreet with a warning, exits 0, and other tools still resolve ✅ pass live resolve-live.txt and preflight-live.txt: all four faults print 'skipping optional koncreet', exit 0, and bun/herdr/node/uv still resolve. The faults were injected into the koncreet GitHub call only, v…
A non-optional tool lookup failure still hard-fails, so only koncreet is optional ✅ pass live Offline --also obscura --resolve failed with exit 1. The first rate-limited site.yml run also aborted with 'cannot resolve the latest gh release (HTTP 403)'.
Full apply path installs koncreet as released plus the 26.04 patch and links it (site.yml --tags always,koncreet) ✅ pass live site-koncreet-live.txt (S1): failed=0, link and conf present, patch-outcome 'patch applied'. Run as root in a bwrap user namespace with /usr/local redirected, plus a tar --no-same-owner shim for the u…
Re-applying the same release is a no-op for koncreet ✅ pass live koncreet-install-real.txt run 2: fetch, extract and patch skipped; link and conf ok; only the unrelated 'later' task changed
Digest mismatch on the real release tarball is skipped with a checksum warning; nothing installed or linked, no config rendered, later tasks still run, apply exits 0 ✅ pass live koncreet-failure-scenarios.txt (A): the warning shows 'checksum ... did not match', no link, no patch-outcome, no tarball, no conf, later task ran. Run as root in a bwrap user namespace and under fake…
404 asset URL skips koncreet and apply continues ✅ pass live koncreet-failure-scenarios.txt (B): 'WARNING: koncreet skipped ... Request failed', later task ran, exit 0
Rate-limit or missing-digest in the real preflight makes site.yml skip koncreet rather than abort ✅ pass live site-koncreet-live.txt (S2, S3): failed=0, the koncreet imports are skipped, the preflight prints the warning, and no link or conf is created
Container worker config (start_services=false) never resolves or installs koncreet, even when GitHub is faulted ✅ pass live preflight-live.txt P4 and site-koncreet-live.txt S4: no koncreet lookup and no skip warning (the same fault warns on the host config); tasks skipped. The Docker image build itself was not run; this dr…
Plan mode (--check) installs nothing and warns of nothing ✅ pass live koncreet-failure-scenarios.txt (E): nothing created, no WARNING in the output
Ubuntu 26.04 works: patched doctor and dry-run apply pass the OS gate on this host; unpatched upstream refuses ✅ pass live koncreet-doctor-patched.txt: '[OK] OS ubuntu 26.04 supported'. koncreet-dryrun-patched.txt: full change plan. koncreet-doctor-unpatched.txt: '[FAIL] OS ubuntu 26.04 not supported', and dry-run apply e…
The patch layers correctly across upstream states: applied, release already supports 26.04, no longer applies (installed as released) ✅ pass live koncreet-failure-scenarios.txt (C, D2) and the real-tarball run: each case reports its outcome and still installs and links. The C and D2 fixtures were built by modifying lib/os.sh in the real tarball…
Rendered /etc/koncreet.conf: 41641/udp and the tailscale0 hint appear only with the tailscale profile; the factory user or root never becomes the sudo user (user= and pubkey_file= stay commented, with… ✅ pass live koncreet-conf-matrix.txt (F1-F4), rendered through the real template task. The tailscale0 rule is only a comment hint because koncreet's firewall_ports takes ports, not interfaces.
The ubuntu-26.04 branch of the undeemed/koncreet fork exists and carries the same change as patches/koncreet/ubuntu-26.04.patch ✅ pass live fork-compare.txt: repo, branch and compare diff all return HTTP 200; the change lines are identical
SSH client IP fallback on 26.04, where who -m prints nothing: patched koncreet_ssh_client_ip asks logind; junk or missing input yields no IP ⏸️ untested no The prior payload did not establish a live result. It recorded live=false because the real patched and unpatched lib/sshd.sh functions were sourced with stubbed loginctl and who commands, not a re…
Koncreet's firewall does not reset existing ufw rules, so the tailscale0 allow survives the manual apply ⏸️ untested no A real koncreet apply would install ufw and change the operator's host firewall, and the workspace boundary forbids system-state changes outside the worktree. The sandbox cannot drive it either: it…
Digest unit test actually exercises the digest check (mutation: remove verification and the test must fail) ⏸️ untested no The prior payload did not establish a live result. It recorded live=false because this is a pytest mutation check (digest-test-vacuity.txt, digest-test-mutation.txt), not a run against the real runnin…
  • .venv/bin/pytest -k koncreet tests/test_install_tools.py tests/test_configuration.py (20 passed before my test change; 8 koncreet config tests passed after)
  • .venv/bin/pytest -k &#34;digest or planning&#34; tests/test_configuration.py with fakeroot on PATH (2 passed) and with it hidden (digest test skips with a reason, planning test passes)
  • install_tools.py --resolve --tools herdr,node,bun,uv --also koncreet against the real GitHub API: resolved v0.2.4 with the published SHA-256
  • The same resolve with faults injected into the koncreet GitHub call only (403 rate limit, no digest, no asset, unsafe tag): each skipped koncreet with a warning and exited 0. Offline obscura still hard-fails.
  • Real ansible/tasks/koncreet.yml with the real v0.2.4 tarball, real digest and real patch, run as root in a bwrap user namespace with /usr/local redirected: installed, linked, patch applied, config rendered. A second run was a no-op for the koncreet tasks.
  • Installed patched koncreet doctor and --dry-run apply -c &lt;rendered conf&gt; on this Ubuntu 26.04 host, compared with unpatched upstream, which refuses with Unsupported OS: ubuntu 26.04 (exit 2)
  • Patched koncreet_ssh_client_ip sourced from the real library with stubbed loginctl and who (stubs, not live): the logind fallback works when who is empty; junk and empty inputs return no IP
  • Failure scenarios through the real tasks: wrong digest on the real tarball, 404 asset URL, --check plan mode, a release that already supports 26.04, a release the patch no longer applies to
  • Rendered /etc/koncreet.conf matrix: tailscale on/off, apply user equal to the factory user, root, and re-apply not overwriting an operator edit
  • Real site.yml --tags always,koncreet: the host config installed koncreet; rate-limit and no-digest faults skipped it with failed=0; the container config never looked it up
  • Compared the undeemed/koncreet ubuntu-26.04 fork branch with patches/koncreet/ubuntu-26.04.patch (identical change lines)
  • Mutation check (pytest, not live): removed the get_url checksum line, the fixed digest test failed, then restored it and the test passed
  • Read ansible/tasks/koncreet.yml and the upstream tree for any ufw reset (code reading only, not driven)

🔧 No changes applied.
✅ Re-checked - no issues remain.

  • Live validation: ✅ go - 8 of 10 scenarios driven live against the product
Scenario Result Live Evidence
Operator applies on a fresh Ubuntu 26.04 host: Koncreet installs root-owned with the 26.04 patch and koncreet doctor reports OS ubuntu 26.04 supported ✅ pass live live-scenarioA-clean-install-via-preflight.txt; host-26.04-patched-vs-unpatched.txt (unpatched fails the OS gate, patched passes)
Operator applies on a fresh Ubuntu 24.04 host: Koncreet installs, the 26.04 patch layers on without regressing the supported OS, and doctor reports ubuntu 24.04 supported ✅ pass live live-24.04-container-koncreet-apply.txt
Adversarial: the publisher digest does not match the tarball (24.04 and 26.04): Koncreet is skipped with a warning, apply exits 0, nothing is linked or configured, and the next correct-digest apply in… ✅ pass live live-24.04-container-digest-mismatch-and-recovery.txt (rescued=1, failed=0, rc=0; no file, link or /etc/koncreet.conf afterwards); live-scenarioC-digest-mismatch-skips-then-recovers.txt and live-diges…
Adversarial: the Koncreet release lookup returns HTTP 403 (rate limit): apply warns and continues with rc=0, both when an earlier release is installed and on a fresh host ✅ pass live live-lookup-403-skips-real-rc.txt
Resolver faults for optional koncreet (403, 404, no published SHA-256, renamed asset, unsafe release tag) are skipped with a warning and install_tools --resolve exits 0, while a mandatory tool's 403… ✅ pass live live-resolver-koncreet-faults.txt (real CLI run). Supporting only: pytest tests/test_install_tools.py -k koncreet, 12 passed
Container worker image config (start_services=false) never resolves or installs Koncreet ✅ pass live live-scenarioE-container-and-plan.txt; live-gate-start-services-both-configs.txt
Rendered /etc/koncreet.conf follows the tailscale profile and never makes factory.user a sudo user: operator account gets user and pubkey_file, factory user and root leave them commented with an expla… ✅ pass live live-scenarioD-apply-as-operator-and-factory-user.txt (26.04: operator and factory user); live-24.04-container-koncreet-apply.txt (root, tailscale off); live-rendered-configs-fed-to-koncreet-dry-run.t…
Fork requirement: the patch Code Factory applies is byte-identical to the fork branch ubuntu-26.04 of the Koncreet repo ✅ pass live fork-ls-remote.txt; fork-compare-diff-byte-identical.txt
CI installs fakeroot before the pytest step so the digest test neither skips nor fails in CI ⏸️ untested no Only a real GitHub Actions run on the ubuntu-24.04 runner can exercise this step, and no Actions runner or credentials are reachable from this sandbox. The remote CI run on the PR will exercise it. Lo…
Full koncreet apply including the fail2ban restart on a systemd-booted host ⏸️ untested no Not a pass. The recorded sandbox ran without systemd as PID 1 ("System has not been booted with systemd"). This change only installs Koncreet and never runs it, and the 26.04 patch touches only the OS…
  • uv run pytest tests/test_configuration.py tests/test_install_tools.py -k koncreet -rs -v (20 passed, 0 skipped): supporting evidence only, not live
  • New live drive: disposable Ubuntu 24.04.5 container (kc-systemd:24.04 image), ansible-core 2.16.3 from noble apt, repo = git archive of HEAD d72af44. ansible-playbook ansible/site.yml --tags koncreet against a stand-in GitHub release API serving the real v0.2.4 tarball and its real sha256. Then koncreet doctor and the rendered /etc/koncreet.conf
  • New live adversarial drive in the same 24.04 container: the stand-in published an all-zero sha256 (second stand-in on port 8100). Checked the skip warning, rc, and that nothing was left installed, linked or configured. Then repeated with the correct digest
  • Reused recorded live 26.04 container runs from earlier in this round: scenarioA, C, D, E, live-lookup-403-skips-real-rc, live-digest-skip-wrapper-playbook, live-gate-start-services-both-configs, live-resolver-koncreet-faults, host-26.04-patched-vs-unpatched. Before reuse I compared that sandbox's /repo against the worktree by md5 for koncreet.yml, install_tools.py, group_vars/all.yml, koncreet.conf.j2, the 26.04 patch, site.yml and preflight.yml: identical. I did not diff the whole tree
  • fork-ls-remote.txt and fork-compare-diff-byte-identical.txt (read-only GitHub queries); ci-fakeroot-step.txt (parsed ci.yml, supporting only)

✅ No issues found.

  • Live validation: ✅ go - 7 of 10 scenarios driven live against the product
Scenario Result Live Evidence
Operator installs the real v0.2.4 release on Ubuntu 26.04: it installs root-owned, the 26.04 patch is applied, /usr/local/bin/koncreet is linked, and koncreet doctor says 'OS ubuntu 26.04 supported' ✅ pass live live-round4-real-paths-mountns-overlay.txt section B (rescued=0, link and doctor output). The fakeroot file shows only that the patch applied.
Unpatched upstream v0.2.4 on the same 26.04 host fails the OS gate, so the patch is needed ✅ pass live live-round4-fakeroot-patch-digest-404-only.txt section 2c; host-26.04-patched-vs-unpatched.txt from an earlier round. Upstream lib/os.sh has 0 matches for '26.04'.
Fork request: undeemed/koncreet has an ubuntu-26.04 branch whose diff against main is byte-identical to the shipped patches/koncreet/ubuntu-26.04.patch ✅ pass live git ls-remote showed refs/heads/ubuntu-26.04. cmp of the compare diff against the patch printed BYTE-IDENTICAL (68 lines).
Adversarial: publisher digest does not match the tarball. Apply warns 'koncreet skipped, apply continues', installs and links nothing, writes no config, and the later task still runs ✅ pass live live-round4-real-paths-mountns-overlay.txt section A (rescued=1, no link, no /etc/koncreet.conf). live-round4-24.04-container-head-koncreet.txt (mismatch, later task ran). live-round4-fakeroot-patch-d…
Adversarial: tarball URL returns 404. Apply skips koncreet with a warning and the later task still runs ✅ pass live live-round4-fakeroot-patch-digest-404-only.txt section 5
Recovery and idempotence: after a mismatch the correct digest installs. A second apply skips all six install tasks, and an edit appended to the rendered /etc/koncreet.conf survives (force: false) ✅ pass live live-round4-real-paths-mountns-overlay.txt sections B and C: the template task ran with rescued=0 and '# operator edit' was preserved. The fakeroot run is not used here, because its template task neve…
Config rules: tailscale on gives firewall_ports=41641/udp and off gives none. Apply as the factory user or root comments out user= and pubkey_file= and says why. ssh is not in the module list. The ope… ✅ pass live live-round4-real-paths-mountns-overlay.txt sections B (dry-run plan), D, E, F. The 4-way parametrized pytest also passed.
Optional lookup: a release with no SHA-256 or no asset, an unsafe tag, or a failed or 403 lookup is skipped with a warning and the resolver exits 0, so apply is not blocked ⏸️ untested no The prior payload did not establish a live result. In this run the real resolver CLI was exercised only against injected faults through pytest (test_koncreet_release_* and test_koncreet_lookup_failure…
Container worker image excludes koncreet: it is resolved only when start_services is true ⏸️ untested no The prior payload did not establish a live result. The worker image was not rebuilt in this run, per the user's instructions, so the exclusion was never observed in a running image. It rests on pytest…
Digest test is not vacuous and CI installs fakeroot: the test passes with fakeroot present, and its skip reason is the checksum failure at 'Fetch the koncreet tarball' ⏸️ untested no The prior payload did not establish a live result. The CI workflow was not run in this run. Only its YAML was parsed (fakeroot install is step 5, pytest is step 6) and the local pytest run showed 20 p…
  • uv run pytest tests/test_configuration.py tests/test_install_tools.py -k koncreet -q -rs: 20 passed, 0 skipped (fakeroot present)
  • git diff d72af442 HEAD limited to koncreet.yml, koncreet.conf.j2, patches/koncreet, preflight.yml and containers/factory.container.yml: 0 lines
  • git diff d72af442 HEAD on group_vars/all.yml, site.yml, install_tools.py and the tests: only base-merge changes (omp pattern-kill, no-mistakes pi agent). Nothing about koncreet changed except one shared test assertion that no longer lists no-mistakes.
  • python3 scripts/install_tools.py --home &lt;tmp&gt; --also koncreet --resolve against the live GitHub API: koncreet 0.2.4 with its release-asset SHA-256
  • tasks/koncreet.yml under fakeroot with a temp prefix, real v0.2.4 tarball and real digest: patch applied, digest-mismatch skip, 404 skip. Scope is limited to those three, because install and link were rescued here (hard-coded /usr/local/bin).
  • sudo unshare -m with overlays on /etc and /usr/local (upper dirs in /tmp), real paths and real root: digest-mismatch skip, then correct-digest install, link, config render, koncreet doctor, koncreet --dry-run apply -c /etc/koncreet.conf, second-apply idempotence (rescued=0 in all five runs), and the factory-user, root and tailscale-off config variants. The host was checked afterwards and has no /usr/local/bin/koncreet, /etc/koncreet.conf or /usr/local/lib/code-factory.
  • Unpatched upstream v0.2.4 doctor on the same 26.04 host, compared with the patched one
  • Fresh ubuntu:24.04 container at HEAD: digest-mismatch skip, then correct-digest install, link and doctor
  • git ls-remote of undeemed/koncreet, then cmp of the fork's compare/main...ubuntu-26.04.diff against patches/koncreet/ubuntu-26.04.patch
  • Parsed .github/workflows/ci.yml (job config-and-python): fakeroot install is step 5, pytest is step 6
✅ **Document** - passed

✅ No issues found.

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

✅ No issues found.

…ered on

Every apply resolves the latest jimididit/koncreet release, verifies
koncreet.tar.gz against the GitHub release-asset digest, extracts it as
root into /usr/local/lib/code-factory/koncreet/<version>-<patch hash>/
and links /usr/local/bin/koncreet. Nothing runs it.

patches/koncreet/ubuntu-26.04.patch opens the OS gate and doctor for
Ubuntu 26.04 and restores the last SSH client IP fallback there (26.04
keeps no utmp, so who -m prints nothing; ask logind instead). The same
change is the ubuntu-26.04 branch of undeemed/koncreet. Apply layers the
patch on each new release and reports applied, skipped because upstream
already supports 26.04, or skipped because it no longer applies; the
patch never fails the apply.

/etc/koncreet.conf is rendered once for the fleet: the operator account
as the sudo user with its own authorized_keys, SSH kept open, 41641/udp
for Tailscale. docs/security.md has the one-time manual run, the
tailscale0 ufw rule, and upstream's lockout recovery.
A root-run apply now leaves user= and pubkey_file= commented for the
operator to fill in, and the template says why the operator login, not
factory.user, is the sudo user.
@undeemed
undeemed force-pushed the fm/cf-koncreet-u26-k4 branch from 2c3c15e to b3d31fe Compare October 1, 2026 10:53
@undeemed
undeemed merged commit 61979ea into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant