Puts the catalog pin back where 5ff36d0 had it. The box is deliberately left running 2.5.0 for the
R-524 half of the measurement -- a box AHEAD of the catalog must read "Naprakesz"/"Up to date" and
its Update must be refused 409, not offered as a downgrade.
catalog_since stays 2026-09-21, NOT restored to 2026-07-18: the catalog-since gate requires
since >= the commit day of any commit that moves an image: line, and a revert is an image move.
Restoring the old date would fail the gate. So this file does not return byte-for-byte to 5ff36d0 --
the image: line does, the date does not, and that is the gate's rule, not a leftover.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
A temporary image move so a live box can be walked through the update arc on demo-hp LXC 9202
(audit update-arc-2026-09-21): the badge going to "Frissites elerheto - ma", a power cut mid-pull
(R-520), then the revert that leaves the box AHEAD of the catalog (R-524).
2.5.0 is the next REAL released upstream tag: 2.4.1 and 2.4.2 do not exist on Docker Hub
(docker manifest inspect, all three checked). catalog_since moves to today as the catalog-since
gate requires of any commit that moves an image: line.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This reverts commit 6ce3f65, reverted EARLY — as soon as the update under test had advanced its pin,
which is the last moment the catalog value mattered to Scenario F. Flagged by the commit security
review (supply-chain: a catalog push is a deploy, and any fresh uptime-kuma install in that window
would have received an image that exits at once). Measured exposure: demo-hp's throwaway was the only
uptime-kuma install on either demo box. catalog_since is back to its original value.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Scenario F of the guarded-update live validation, the same way the 2026-09-01 spike did it: the new
"version" is an image that starts and exits immediately, so the app never becomes healthy and must be
HELD — and then restored from its named copy. catalog_since moves with the image line; the revert
restores it.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Scenario E of the guarded-update live validation: the catalog names a tag that does not resolve, so
the update's pull must fail and the pin must be PUT BACK with the app untouched. catalog_since moves
with the image line, as the catalog rule requires; the revert restores it.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This reverts commit 01c631d — and is itself the real catalog tag change (2.3.2 -> 2.4.0) that
Scenario A of the slice-4 live validation updates the deployed throwaway across. catalog_since is
back to its original value.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The throwaway app for the guarded-update live validation on demo-hp is installed from this older
tag, so the revert that follows is a real catalog tag change for Scenario A (2.3.2 -> 2.4.0).
catalog_since moves with the image line, as the catalog rule requires; the revert restores it.
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
House style is a specific upstream tag. ':2' is a floating major that silently
moves under customers on every pull -- the same class of problem as ':latest',
just narrower. Pinned to the current 2.x release.
Campaign 7 catalog sweep.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nn3VgQk9iwEGgyx6QJ2NvE
The override pointed at a v1-era node /app/extra/healthcheck.mjs that does not
exist in louislam/uptime-kuma:2, so the container was permanently unhealthy and
Traefik withheld the route → the app URL 404'd despite the app running. Point at
the correct binary (extra/healthcheck, WORKDIR /app) and use the image's timing
(180s start_period) to avoid transient unhealthy→404 on first boot.
All 51 docker-compose.yml: replaced hardcoded subdomain.${DOMAIN}
with ${SUBDOMAIN}.${DOMAIN} in Traefik labels, app env vars, and
comments.
All 51 .felhom.yml: added SUBDOMAIN deploy field (type: subdomain)
with default matching existing subdomain metadata value.
Works with felhom-controller v0.27.0 which validates and stores the
user-chosen subdomain in app.yaml. Existing deployed apps get
SUBDOMAIN auto-injected via InjectMissingFields() on next sync.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>