<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Farrow</title>
    <link>https://farrow.pgsty.com/</link>
    <description>Recent content on Farrow</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    
    
    
      <lastBuildDate>Tue, 25 Aug 2026 00:00:00 +0800</lastBuildDate>
    
    
      <atom:link href="https://farrow.pgsty.com/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>RC6 development candidate: owner-scoped Tier-1 delivery</title>
        <link>https://farrow.pgsty.com/blog/release/rc6-owner-scoped-20260825/</link>
        <pubDate>Tue, 25 Aug 2026 00:00:00 +0800</pubDate>
        
        <guid>https://farrow.pgsty.com/blog/release/rc6-owner-scoped-20260825/</guid>
        <description>&lt;div class=&#34;td-callout td-callout--caution&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-circle-xmark&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Caution&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;Pre-Farrow historical record. It preserves the predecessor candidate&amp;rsquo;s exact&#xA;identity and does not establish support for current Farrow bytes or paths.&#xA;See &lt;a href=&#34;https://farrow.pgsty.com/docs/about/status/&#34;&gt;current status&lt;/a&gt;.&lt;/p&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&lt;p&gt;Piglet &lt;code&gt;1.0.0-rc.6&lt;/code&gt; is the owner-scoped local development candidate for the&#xA;single native-QEMU path. It closes the requested Quick and exact four-node&#xA;&lt;code&gt;full&lt;/code&gt; scenarios on both Tier-1 hosts and adds durable privileged-network&#xA;transactions. It is deliberately not a public release.&lt;/p&gt;&#xA;&lt;div class=&#34;td-callout td-callout--warning&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-triangle-exclamation&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Warning&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;No Homebrew operation, public tag, remote push, GitHub Release, package&#xA;repository, production signature, attestation, or support commitment was&#xA;created. The hashes below identify retained local artifacts; this site does&#xA;not provide them as downloads.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Development snapshot: the Go 1.27 product surface</title>
        <link>https://farrow.pgsty.com/blog/release/development-snapshot-20260824/</link>
        <pubDate>Mon, 24 Aug 2026 00:00:00 +0800</pubDate>
        
        <guid>https://farrow.pgsty.com/blog/release/development-snapshot-20260824/</guid>
        <description>&lt;div class=&#34;td-callout td-callout--caution&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-circle-xmark&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Caution&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;Pre-Farrow historical record. Names, commands, paths, hashes, and claims on&#xA;this page describe the predecessor snapshot only. Use the current&#xA;&lt;a href=&#34;https://farrow.pgsty.com/docs/about/status/&#34;&gt;Farrow status&lt;/a&gt; and guides for present behavior.&lt;/p&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&lt;p&gt;Piglet&amp;rsquo;s 2026-08-24 source snapshot has moved well beyond an initial QEMU&#xA;spike. It now presents one coherent local-VM product: zero-configuration Quick,&#xA;fixed-address private labs, 13 Piglet-owned profiles, an audited Pigsty&#xA;inventory boundary, explicit persistence/state migration, diagnostics, and a&#xA;reproducible release toolchain.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Configuration</title>
        <link>https://farrow.pgsty.com/docs/reference/configuration/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/reference/configuration/</guid>
        <description>&lt;h2 id=&#34;discovery&#34;&gt;Discovery&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Configuration lookup order is explicit &lt;code&gt;-f&lt;/code&gt;, then &lt;code&gt;farrow.yml&lt;/code&gt;,&#xA;&lt;code&gt;farrow.yaml&lt;/code&gt;, &lt;code&gt;pigsty.yml&lt;/code&gt;, and &lt;code&gt;pigsty.yaml&lt;/code&gt; in the current directory. Every&#xA;name uses the same Pigsty-compatible YAML Inventory format.&lt;/p&gt;&#xA;&lt;p&gt;The retired top-level &lt;code&gt;version:&lt;/code&gt;/&lt;code&gt;nodes:&lt;/code&gt; format is rejected with migration&#xA;guidance.&lt;/p&gt;&#xA;&lt;p&gt;For &lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, &lt;code&gt;reload&lt;/code&gt;, and &lt;code&gt;recreate&lt;/code&gt;, absence of a file falls back to&#xA;the applied spec when a deployment exists. &lt;code&gt;validate&lt;/code&gt; has no fallback. A&#xA;configuration must be a regular non-symlink file no larger than 4 MiB.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Design</title>
        <link>https://farrow.pgsty.com/docs/about/design/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/about/design/</guid>
        <description>&lt;h2 id=&#34;one-useful-abstraction&#34;&gt;One useful abstraction&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Farrow boots one Pigsty Inventory as one local QEMU deployment. It deliberately&#xA;has no project marker, project registry, lease model, provider layer, or&#xA;second configuration format.&lt;/p&gt;&#xA;&lt;p&gt;State lives under &lt;code&gt;~/.farrow&lt;/code&gt; for one Unix user. The product assumes one active&#xA;Pigsty deployment per computer; this is not a root-enforced cross-user&#xA;singleton.&lt;/p&gt;&#xA;&lt;h2 id=&#34;node-level-convergence&#34;&gt;Node-level convergence&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Farrow extracts only the documented VM and Pigsty-native fields, computes&#xA;per-node hashes, and keeps applied state plus process identity. Additions are&#xA;incremental. Changes require an&#xA;explicit per-node recreate. &lt;code&gt;up&lt;/code&gt; also starts selected existing stopped nodes;&#xA;already-running peers remain untouched. Absence never authorizes deletion.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Installation</title>
        <link>https://farrow.pgsty.com/docs/start/installation/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/start/installation/</guid>
        <description>&lt;h2 id=&#34;supported-path-today&#34;&gt;Supported path today&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Build from the current checkout:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-5caa8b5d-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;5&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-5caa8b5d-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;cd&lt;/span&gt; /path/to/farrow&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make build&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;export&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;PATH&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;$PWD&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;/bin:&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;$PATH&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow version&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow doctor&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;There is no published v1 package yet. Do not substitute an unofficial binary&#xA;for the matching &lt;code&gt;farrow&lt;/code&gt; and &lt;code&gt;farrow-hosts-helper&lt;/code&gt; build.&lt;/p&gt;&#xA;&lt;p&gt;The source build requires Go 1.27.x. macOS also needs an existing Homebrew&#xA;installation; Farrow can install QEMU through Homebrew but never bootstraps&#xA;Homebrew itself. The current compiled image repository is the development host&#xA;&lt;code&gt;https://m0/farrow&lt;/code&gt;; use &lt;code&gt;FARROW_REPO&lt;/code&gt; or &lt;code&gt;--repo&lt;/code&gt; when another reachable mirror&#xA;is required.&lt;/p&gt;</description>
      </item>
    <item>
        <title>CLI</title>
        <link>https://farrow.pgsty.com/docs/reference/cli/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/reference/cli/</guid>
        <description>&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-9455d335-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;text&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-9455d335-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow [--json|--yaml] [--verbose] &amp;lt;command&amp;gt; [flags] [node...]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;The installed binary is the authoritative reference for its own version. Every&#xA;visible command includes its operational boundary and copyable examples:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-9455d335-fence-1&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;3&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-9455d335-fence-1-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow --help&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow setup --help&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow image pull --help&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;In text mode, bare &lt;code&gt;farrow&lt;/code&gt; and namespaces such as &lt;code&gt;farrow image&lt;/code&gt; display&#xA;contextual help and exit successfully. In JSON/YAML mode a bare namespace is a&#xA;structured usage error; explicit &lt;code&gt;--help&lt;/code&gt; always renders human help.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Status</title>
        <link>https://farrow.pgsty.com/docs/about/status/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/about/status/</guid>
        <description>&lt;p&gt;Farrow is pre-1.0. Source tests, dated native replays, packages, release, CI,&#xA;and the public site are separate gates.&lt;/p&gt;&#xA;&lt;h2 id=&#34;last-recorded-native-replay--2026-08-27&#34;&gt;Last recorded native replay — 2026-08-27&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;This matrix belongs to the exact checkpoint exercised that day. Later source&#xA;or documentation edits do not inherit native proof without another replay.&lt;/p&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Host&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Path&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Result&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;macOS 26.6.2 arm64&lt;/td&gt;&#xA;      &lt;td&gt;HVF, QEMU 11.1, socket_vmnet&lt;/td&gt;&#xA;      &lt;td&gt;one node and additive four nodes passed&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Ubuntu 26.04 amd64 (&lt;code&gt;mx&lt;/code&gt;)&lt;/td&gt;&#xA;      &lt;td&gt;KVM, QEMU 10.2.1, NetworkManager&lt;/td&gt;&#xA;      &lt;td&gt;setup, one node, additive four nodes, and uninstall passed&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;Both hosts passed fixed IP, SSH readiness, default CPU/memory/root/data disk,&#xA;cloud-init, stop/start, cross-directory commands, unchanged control-node boot&#xA;ID during scale-out, control-to-peer SSH, ignored unconsumed Pigsty changes,&#xA;absence-never-destroys, and explicit destroy.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Tutorial</title>
        <link>https://farrow.pgsty.com/docs/start/tutorial/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/start/tutorial/</guid>
        <description>&lt;h2 id=&#34;1-create-the-lab&#34;&gt;1. Create the lab&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-0d9c382d-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;6&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-0d9c382d-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;mkdir -p ~/lab&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;cd&lt;/span&gt; ~/lab&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;export&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;FARROW_REPO&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;https://m0/farrow   &lt;span class=&#34;c1&#34;&gt;# replace outside the development network&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow setup --dry-run&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow setup --yes&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow up&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;With no existing file, setup writes &lt;code&gt;farrow.yml&lt;/code&gt; for one node:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-0d9c382d-fence-1&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;yaml&#34; data-td-line-count=&#34;7&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-0d9c382d-fence-1-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-yaml&#34; data-lang=&#34;yaml&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nt&#34;&gt;all&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;  &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;vars&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;    &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;admin_ip&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;m&#34;&gt;10.10.10.10&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;  &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;children&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;    &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;nodes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;      &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;hosts&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;w&#34;&gt;        &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;10.10.10.10&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;{&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;nodename&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;l&#34;&gt;meta }&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;&lt;code&gt;up&lt;/code&gt; downloads and verifies the image, creates the disks and cloud-init seed,&#xA;starts QEMU, and waits for the guest readiness record.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Engineering</title>
        <link>https://farrow.pgsty.com/docs/about/engineering/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/about/engineering/</guid>
        <description>&lt;h2 id=&#34;repository-boundary&#34;&gt;Repository boundary&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The Farrow source repository contains code, tests, build/package definitions,&#xA;legal notices, and a short landing README. This site is the authoritative home&#xA;for user, design, operator, and release documentation. Raw review transcripts,&#xA;historical scratch inventories, demo directories, generated binaries, and&#xA;release output trees are not source inputs and must not be committed.&lt;/p&gt;&#xA;&lt;p&gt;Generated output is disposable:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;bin/&lt;/code&gt; — development builds;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;dist/&lt;/code&gt; and &lt;code&gt;.goreleaser-*&lt;/code&gt; — release/snapshot staging;&lt;/li&gt;&#xA;&lt;li&gt;root &lt;code&gt;farrow&lt;/code&gt;, &lt;code&gt;farrow-hosts-helper&lt;/code&gt;, and &lt;code&gt;catalogsign&lt;/code&gt; binaries;&lt;/li&gt;&#xA;&lt;li&gt;Hugo &lt;code&gt;public/&lt;/code&gt; and &lt;code&gt;resources/&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;build-and-source-gates&#34;&gt;Build and source gates&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-179a7674-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;9&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-179a7674-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make build&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make &lt;span class=&#34;nb&#34;&gt;test&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make race&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make vet&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make staticcheck&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make vuln&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make cross-check&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make image-pipeline-test&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;make license-check&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;&lt;code&gt;make check&lt;/code&gt; combines these gates. A source gate is not native VM evidence;&#xA;macOS HVF, Linux KVM/networking, package consumption, release publication, and&#xA;the public render remain separate gates.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Images</title>
        <link>https://farrow.pgsty.com/docs/reference/images/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/reference/images/</guid>
        <description>&lt;p&gt;Farrow uses a signed static-file Catalog plus immutable qcow2 artifacts. A&#xA;Catalog update does not require a new Farrow binary, but the binary decides&#xA;which signing keys and image safety rules are trusted.&lt;/p&gt;&#xA;&lt;div class=&#34;td-callout td-callout--warning&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-triangle-exclamation&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Warning&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;EL7 is &lt;code&gt;deprecated&lt;/code&gt;; every other built-in image is currently &lt;code&gt;testing&lt;/code&gt;, not&#xA;&lt;code&gt;supported&lt;/code&gt;. The warning printed by &lt;code&gt;up&lt;/code&gt; is intentional: a successful pull&#xA;is an integrity result, not a production-support promise.&lt;/p&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&lt;h2 id=&#34;aliases-and-pull-order&#34;&gt;Aliases and pull order&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The embedded Catalog contains 9 families and 17 artifacts: &lt;code&gt;el7&lt;/code&gt; is&#xA;amd64-only; &lt;code&gt;el8&lt;/code&gt;, &lt;code&gt;el9&lt;/code&gt;, &lt;code&gt;el10&lt;/code&gt;, &lt;code&gt;d12&lt;/code&gt;, &lt;code&gt;d13&lt;/code&gt;, &lt;code&gt;u22&lt;/code&gt;, &lt;code&gt;u24&lt;/code&gt;, and &lt;code&gt;u26&lt;/code&gt;&#xA;have amd64 and arm64 artifacts. &lt;code&gt;u24&lt;/code&gt; is the VM default.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Operations</title>
        <link>https://farrow.pgsty.com/docs/start/operations/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/start/operations/</guid>
        <description>&lt;h2 id=&#34;inspect-and-access&#34;&gt;Inspect and access&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-ab9c2dd3-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;5&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-ab9c2dd3-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow status&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow ssh meta&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow &lt;span class=&#34;nb&#34;&gt;exec&lt;/span&gt; node-1 -- hostname&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow logs meta --source serial&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow ss                         &lt;span class=&#34;c1&#34;&gt;# install SSH aliases; then: ssh meta&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Applied state is under &lt;code&gt;~/.farrow&lt;/code&gt;; these commands work from any directory.&#xA;Status includes the persisted Guest architecture and accelerator, so TCG is&#xA;never an invisible fallback.&#xA;&lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, &lt;code&gt;reload&lt;/code&gt;, and &lt;code&gt;recreate&lt;/code&gt; prefer &lt;code&gt;-f&lt;/code&gt;, then a discovered&#xA;Inventory, then the applied spec when no file exists. &lt;code&gt;validate&lt;/code&gt; always needs&#xA;a file.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Image Pipeline</title>
        <link>https://farrow.pgsty.com/docs/reference/image-pipeline/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/reference/image-pipeline/</guid>
        <description>&lt;p&gt;&lt;code&gt;packaging/image-pipeline/&lt;/code&gt; accepts one already-downloaded immutable qcow2 and&#xA;an independently obtained SHA-256. It never downloads, uploads, touches Farrow&#xA;runtime/network state, reads signing keys, or marks an image &lt;code&gt;supported&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;modes&#34;&gt;Modes&#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;validate&lt;/code&gt;: copy/re-hash, force qcow2 inspection, validate the single backing&#xA;chain, run &lt;code&gt;qemu-img check&lt;/code&gt;, and emit an explicitly unpublishable evidence&#xA;bundle. Guest credentials are not changed.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;offline&lt;/code&gt;: additionally use libguestfs &lt;code&gt;virt-customize --no-network&lt;/code&gt; and&#xA;&lt;code&gt;virt-cat&lt;/code&gt; on the staged copy. It rejects unrelated UID/GID 88 occupants,&#xA;normalizes the locked &lt;code&gt;dba&lt;/code&gt;/&lt;code&gt;admin&lt;/code&gt; identity, disables password/root SSH,&#xA;removes keys/history/host identity/cloud-init cache, restores targeted SELinux&#xA;labels, and reads back a deterministic marker.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-01b05ff9-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;14&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-01b05ff9-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SOURCE_DATE_EPOCH&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;m&#34;&gt;1787486400&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;./packaging/image-pipeline/build.sh &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --mode validate &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --source /absolute/source.qcow2 &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --expected-sha256 &amp;lt;digest&amp;gt; &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --output /absolute/new/evidence-directory &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --name u24 --release 20260801.0.0 --arch amd64 &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --source-user ubuntu --boot uefi &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --source-uri https://immutable.example/source.qcow2 &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --artifact-url &lt;span class=&#34;s1&#34;&gt;&amp;#39;https://images.example/u24/{sha256}.qcow2&amp;#39;&lt;/span&gt; &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --license NOASSERTION &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --source-date-epoch &lt;span class=&#34;s2&#34;&gt;&amp;#34;&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;$SOURCE_DATE_EPOCH&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;&lt;/span&gt; &lt;span class=&#34;se&#34;&gt;\&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  --manifest-version &lt;span class=&#34;m&#34;&gt;2026082801&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Source/output paths must be absolute; source is canonical, regular,&#xA;non-symlinked, stable while copied, and at most 16 GiB. Output must not exist.&#xA;The builder uses an exclusive adjacent lock, mode-0700 staging, and one final&#xA;rename. Failure removes only its guarded staging directory.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Troubleshooting</title>
        <link>https://farrow.pgsty.com/docs/start/troubleshooting/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://farrow.pgsty.com/docs/start/troubleshooting/</guid>
        <description>&lt;p&gt;Start read-only:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-651a117f-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;3&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-651a117f-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow doctor --json&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow network status --json&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;farrow status --json&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;no-configuration-found&#34;&gt;No configuration found&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;For the first deployment, run &lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, or &lt;code&gt;validate&lt;/code&gt; beside&#xA;&lt;code&gt;farrow.yml&lt;/code&gt;/&lt;code&gt;pigsty.yml&lt;/code&gt;, or pass &lt;code&gt;-f /path/to/file&lt;/code&gt;. Once state exists,&#xA;&lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, &lt;code&gt;reload&lt;/code&gt;, and &lt;code&gt;recreate&lt;/code&gt; can fall back to its applied spec.&#xA;Status, start, stop, SSH, and destroy always use applied state. If &lt;code&gt;status&lt;/code&gt;&#xA;prints the same message, the selected &lt;code&gt;FARROW_HOME&lt;/code&gt; has no applied state.&lt;/p&gt;</description>
      </item>
    
  </channel>
</rss>
