Restores templates/{vikunja,uptime-kuma,wishlist,glance}/docker-compose.yml to exactly
their content at ff9717d379 — verified byte-identical for every image line.
catalog_since is 2026-09-21 on all four rather than the older pre-drill dates: the
catalog-since gate requires an image move to carry the day's date in EITHER direction,
and a revert is a move. The bump and its revert net to zero.
This clears the vikunja alpine:3.20 negative-control edge, which a background security
review correctly flagged as a supply-chain change. It was deliberate, it is the
documented C3-class control, no customer or demo box runs vikunja, and a deployed app
is frozen at its own pin since v0.235.0 — but the window is now closed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
vikunja 2.3.0 -> 2.6.0, uptime-kuma 2.4.0 -> 2.5.0,
wishlist v0.66.0 -> v0.67.0, glance v0.8.5 -> v0.8.6.
catalog_since set to 2026-09-21 on all four.
This is a measurement drill on the scratch guest 9202 (demo-hp) only.
REVERTED in the same session by the following REVERT commit.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This reverts commit a1f1c38. glance was abandoned as the live-test app: its template crash-loops on
a FRESH install (the image exits with "reading /app/config/glance.yml: no such file or directory"
and nothing seeds that file) — filed in felhom.eu OPEN-ITEMS.md. uptime-kuma is used instead.
catalog_since is back to 2026-07-18.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The throwaway app for the guarded-update live validation on demo-hp is installed from this older
tag, so the revert commit that follows is a real catalog tag change for Scenario A. catalog_since
moves with the image line, as the catalog rule requires; the revert restores 2026-07-18.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
BusyBox wget (+ node/python/curl one-shots, incl mealie's socket tuple) resolve
localhost -> IPv6 ::1 with no cross-family fallback; an IPv4-only-binding app
reads docker-unhealthy while serving (vaultwarden, re-run 2026-07-06). Escalates
that instance to the class. Scoped strictly to healthcheck test: lines
(diff-reviewed: no env/config/label changed; .felhom.yml already clean). New
REUSE.md convention row.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
All 51 docker-compose.yml: replaced hardcoded subdomain.${DOMAIN}
with ${SUBDOMAIN}.${DOMAIN} in Traefik labels, app env vars, and
comments.
All 51 .felhom.yml: added SUBDOMAIN deploy field (type: subdomain)
with default matching existing subdomain metadata value.
Works with felhom-controller v0.27.0 which validates and stores the
user-chosen subdomain in app.yaml. Existing deployed apps get
SUBDOMAIN auto-injected via InjectMissingFields() on next sync.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>