Files
Felis/docs/changes/2026-06-27-felis-cli-break-glass-setup.md
T
flyemoji 096d59716e docs(changes): backfill detail docs for pre-ledger functional commits
Retroactively author 15 grouped detail docs covering the backend
functional (feat/fix) commits made before the change ledger was
established (fad48ff), closing the ledger's detail-doc axis for the
pre-convention history. Each doc groups a feature's constituent commits,
lists their SHAs with subjects, and carries a backfill note stating it
was reconstructed from git history on 2026-07-07 and not independently
re-verified (current tree green at 9911b8c).

Add a Detail docs section to INDEX.md linking every detail doc (the 6
existing + 15 backfill) to the commit(s) it covers, so a doc is findable
from the index without a column on the auto-generated ledger table. Catch
the table up with the missing 9911b8c row.

Scope: backend (Go/Java/K8s) only, per the ledger's stated convention
that frontend/panel commits are the collaborator's UI work; non-functional
commits (docs/style/chore/refactor) keep their table row without a
dedicated detail doc.
2026-07-07 20:55:51 +09:00

2.4 KiB
Raw Blame History

felis CLI: break-glass recovery console + first-run setup (ledger backfill)

  • Type: feature + fix — retroactive ledger entry
  • Date: 2026-06-27 – 2026-06-30
  • Area: cmd/felis (break-glass/setup TUI, apply, migrate), internal/api (audit, owner store), deploy/
  • Commits:
    • e108a37 feat(cli): break-glass emergency console TUI — root-only (euid==0), provisions/resets the Owner directly against Postgres, enables local login, prints a durable one-time-password summary
    • 2d0bbb0 feat(cli): attribute break-glass recovery to the SysAdmin who runs it — bootstrap / recovery (bcrypt) / root-override, each audited with an honest verified flag and payload
    • a94b001 feat(deploy): break-glass Operator account provisioning
    • eb5875a feat(felis): Operator break-glass op behind an operation menu
    • f5d00f3 feat(cli): felis apply for direct CRD creation
    • 9c46632 feat(cli): felis setup first-run console (shared runConsoleTUI model, reclaim protection, cfsetup idempotency, [auth].admin_hostname respect)
    • 7d91373 fix(migrate): honor -config placed after the up verb (flag.Parse stops at the first non-flag token)
  • Tasks: #27 (B1 login→change-pw→TUI reset)

What it did

Built the local-root recovery and first-run surface that bypasses web Zero Trust by design. felis breakGlass mints or resets the Owner when the web login is unreachable; 2d0bbb0 makes it accountable by recording which SysAdmin broke the glass across three audited modes. felis setup is the non-emergency first-run twin sharing the same console model. felis apply writes a MinecraftServer CRD directly, and 7d91373 fixes the migrate flag parse so a configured DB path after up is honored.

Why

An operator with root on the node and a kubeconfig must always be able to recover the platform — that is break-glass's whole job, so it never refuses. Attribution (2d0bbb0) closes the gap that root is machine authority, not a human identity: the root gate is necessary but not sufficient for the audit trail.

Backfill note. Reconstructed 2026-07-07 from the commit history. The core logic was covered by Go unit tests over a fake owner store at each commit (auth match/non-match, the three audit modes, headless TUI drive). The bubbletea TUI glue is untested by house convention. Not independently re-verified for this doc; current tree green at 9911b8c.