hydranode auth state (server_url + token) lives in exactly one place: ~/.hydranode/body.yaml. When running as SYSTEM on Windows that is C:\Windows\System32\config\systemprofile\.hydranode\body.yaml — a path that is routinely touched by Windows updates, AV cleanups, profile resets, and sfc /scannow. If the file is gone, hydranode falls back to enroll-polling mode forever, the body never heartbeats, and from the cluster's perspective the body is offline with no remote-recovery path.
Today (2026-05-11) on cosmic-pretzel-98: .hydranode\ directory under systemprofile was simply absent. Only C:\hydranode\\enroll.yaml and the binaries remained. Required physical access to recover (operator at the venue had to write a body.yaml by hand from a token I pulled out of the cluster's nodes.yaml via SSH). Manual recovery worked but is the kind of operation that should never need an operator on site.
Defense in depth, not a single new location:
~/.hydranode/body.yaml and a fallback (next to the binary at C:\hydranode\body.yaml on Windows / /etc/hydranode/body.yaml on Linux). Optionally also the Windows registry as a tertiary backup.POST /api/v1/nodes/{id}/reissue-enroll-token that mints a one-shot enrollment token tied to the existing node id, so hydranode reinstall --node-id <id> --enroll-token <one-shot> rebuilds locally without creating a duplicate node record.Steps 1+2 close the operational gap (single-point-of-failure becomes triple-point-of-failure with auto-repair). Step 3 is for the catastrophic case and replaces the SSH-into-cluster + hand-write-body.yaml dance.
body.yaml is now written to two locations and read with fallback:
~/.hydranode/body.yaml (existing, SYSTEM profile on Windows)C:\hydranode\body.yaml (Windows), /etc/hydranode/body.yaml (Linux/macOS) — outside any profile dirOn every hydranode startup: read primary; if missing, read backup, restore the primary from the backup, log [config] primary ... missing, restoring from backup .... If primary is read successfully, mirror it to the backup so they never drift. New helpers in pkg/provider/... — GetBackupConfigPath, loadBodyConfigWithFallback, mirrorIfDifferent. Install path writes both locations up front; uninstall paths already clean both.
v1.10.26 follow-up: opened the log file before loadBodyConfig so the recovery diagnostic actually lands in hydranode.log instead of stderr (which the Windows SYSTEM scheduled task discards).
Verified on cosmic-pretzel-98 (the body that hit the original failure):
Remove-Item C:\Windows\System32\config\systemprofile\.hydranode\body.yaml (Test-Path = False after).schtasks /run /tn HydraNode to restart.[config] primary ... missing, restoring from backup C:\hydranode\body.yaml, primary recreated with correct content, heartbeat succeeded at 20:02:50. Total recovery time: 2 seconds.online throughout — no operator file-writing needed.Before: SYSTEM-profile wipe required SSH-into-cluster + hand-writing body.yaml on the body. After: hydranode self-heals within 2 seconds of the next startup. The catastrophic both-gone case is still manual SSH recovery (acceptable, much rarer now).