An IMAGE change, pushed to prove that a pinned app does NOT receive it — the whole
point of slice 3. bentopdf is deployed on demo-hp only and is file-based with no
database and no volume, so no data anywhere can be touched. The revert follows in
the same session.
A NON-image template change, pushed to prove that a pinned app still receives
template fixes on the normal 15-minute cycle. No image pin is touched. The revert
commit follows in the same session.
Phase 2 of SPIKE-app-update-2026-09-01: measure live whether the 15-minute
catalog sync rewrites a DEPLOYED app's docker-compose.yml on demo-hp while its
running container keeps the old image (R-438).
bentopdf is deployed on demo-hp ONLY (demo-felhom runs opengist alone; Peti's
box is down with no access route), it is file-based with no database and no
volume, so the change cannot touch customer data anywhere.
This commit is reverted as soon as the measurement is taken.
bentopdf :latest -> v2.8.6; calibre-web :latest -> v4.0.6 (== running digest on
demo 9201, c31a738b - pin is a no-op); papra :latest -> 26.6.1-rootless (latest
was the rootless variant); recipe-importer :latest -> v0.9.11 (tag pre-existed,
digest-equal, no retag needed); termix :latest -> 2.5.0.
All five pins digest-identical to what :latest resolved to on 2026-07-12.
New gate scripts/check-image-pins.py (catches floating tags AND untagged refs;
red-proofed both shapes). Standing rule in CLAUDE.md + REUSE.md row.
BusyBox wget (+ node/python/curl one-shots, incl mealie's socket tuple) resolve
localhost -> IPv6 ::1 with no cross-family fallback; an IPv4-only-binding app
reads docker-unhealthy while serving (vaultwarden, re-run 2026-07-06). Escalates
that instance to the class. Scoped strictly to healthcheck test: lines
(diff-reviewed: no env/config/label changed; .felhom.yml already clean). New
REUSE.md convention row.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
All 51 docker-compose.yml: replaced hardcoded subdomain.${DOMAIN}
with ${SUBDOMAIN}.${DOMAIN} in Traefik labels, app env vars, and
comments.
All 51 .felhom.yml: added SUBDOMAIN deploy field (type: subdomain)
with default matching existing subdomain metadata value.
Works with felhom-controller v0.27.0 which validates and stores the
user-chosen subdomain in app.yaml. Existing deployed apps get
SUBDOMAIN auto-injected via InjectMissingFields() on next sync.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>