docs: R-168 is CLOSED — the "CI is still owed" sentence was stale (R-229 part 2)
gates / gates (push) Successful in 0s

Corrected in all four instruction files across all four repos. Found while confirming this
session own push by run ID, which is precisely the check that catches it.

In felhom-agent/CLAUDE.md the sentence contradicted the same file release section, which
already said R-168 mails the failure -- a contradiction inside one instruction file, the exact
class the R-229 work exists to find.

REPORT.md deliberately NOT overwritten in the sibling repos: a one-line docs correction must not
destroy the record of their last real implementation.
This commit is contained in:
2026-08-06 11:03:02 +02:00
parent ee2c810201
commit 459766cb16
2 changed files with 15 additions and 1 deletions
+13
View File
@@ -1,5 +1,18 @@
# Changelog # Changelog
## docs — the "CI is still owed" claim was stale; corrected (2026-08-06, R-229 part 2) — no version bump
**One sentence, no code.** This file asserted that continuous integration was still owed
(`felhom.eu` `OPEN-ITEMS.md` R-168). **R-168 was CLOSED on 2026-08-02** — a Gitea Actions runner
re-runs each repo's gate entry point on every push and emails the operator on failure. Found while
confirming this session's own push by run ID, which is the check that caught it.
The same stale sentence was in four instruction files across all four repos and is corrected in all
four. In `felhom-agent/CLAUDE.md` it **contradicted the same file's release section**, which already
said R-168 mails the failure — a contradiction inside one instruction file, which is the exact class
the R-229 work exists to find.
### papra — the volume is mounted where the app actually writes (2026-08-03, R-156, last leg) ### papra — the volume is mounted where the app actually writes (2026-08-03, R-156, last leg)
**The third and last of the three apps that kept their data where backups never looked.** papra **The third and last of the three apps that kept their data where backups never looked.** papra
+2 -1
View File
@@ -45,7 +45,8 @@ deployed `app.yaml` (customer secrets) is never overwritten. Full deploy details
runtime and take minutes per app, and a push that pulls images and starts containers gets bypassed runtime and take minutes per app, and a push that pulls images and starts containers gets bypassed
within a week, after which the bypass is the habit. They stay deliberate periodic runs. The hook is within a week, after which the bypass is the habit. They stay deliberate periodic runs. The hook is
per-clone (`git config core.hooksPath .githooks`) and `git push --no-verify` bypasses it, which is per-clone (`git config core.hooksPath .githooks`) and `git push --no-verify` bypasses it, which is
why R-161's automatic half is still owed — it is now tracked as `felhom.eu` `OPEN-ITEMS.md` R-168. why gate 1 alone cannot be the whole story — CI re-runs the entry point on every push and **emails
on failure** (`felhom.eu` `OPEN-ITEMS.md` R-168, CLOSED 2026-08-02), which is what notices a bypass.
- **Never `:latest` or untagged images in templates** — pin a concrete version tag; an app deployed - **Never `:latest` or untagged images in templates** — pin a concrete version tag; an app deployed
anywhere in the fleet is pinned to the digest it is currently running (a pin must never cause a anywhere in the fleet is pinned to the digest it is currently running (a pin must never cause a
version jump). Digest pins (`@sha256:`) also count. Gate: `python scripts/check-image-pins.py` version jump). Digest pins (`@sha256:`) also count. Gate: `python scripts/check-image-pins.py`