mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-28 14:20:55 +00:00
ac43506e6e
The Settings > Infrastructure installer mints generic host install tokens, but install.sh auto-detects Proxmox and the agent presents type pve/pbs at /api/auto-register. The bootstrap grant required an exact install_type match, so every generic install on a Proxmox node was denied source creation and the denial was a single buried journal warn. Four-part fix (#1644): - server: extend the one-shot bootstrap grant to host-issued install tokens presenting a canonical Proxmox type. Typed tokens stay pinned, the grant keeps its settings-write mint requirement, first-hostname binding, serialized completion, and single consumption across types. - agent: a canRegister=false denial now logs at error level, returns a setup error, and records the operator-facing reason in a proxmox-<type>-registration-blocked state marker. - installer: report the Proxmox registration outcome in install output by reading the registered/blocked markers, and poll the server lookup for a bounded retry window before warning that registration was not confirmed (readyz flips before the first report cycle). - setup script: the auto-register transport now captures the HTTP status alongside the body (no -f), making the invalid-setup-token branch reachable via 401/403 instead of a dead server-string grep, and operator guidance names Settings -> Infrastructure instead of the retired Nodes page (also updated in docs/PBS.md and the pinned assertions in contract, setup-script, and repoctl docs tests). Regression proof: internal/api/issue1644_host_install_token_proxmox_test.go plus new install.sh proofs for the retry window and blocked-marker surfacing, and the updated hostagent blocked-registration test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>