NEW-APP-CHECKLIST.md: the reviewer's draft reviewed - 60 rows in 10 groups, each with how/why and a since date; 7 rows added, 16 sharpened, 9 wrong claims fixed. onboarding/_TEMPLATE.md (one line per id), onboarding/wger.md (the pilot, exempt app, 11 open rows each a register row), onboarding/EXISTING-APPS-GAPS.md (read only, from scripts/onboarding_gaps.py). Gate onboarding (scripts/check-onboarding.py) in --fast: a template directory not among the 53 published before 2026-10-01 needs a complete record; decoys in test_gate_decoys.py (16 cases, 5 gate mutants seen red). CLAUDE.md, REUSE.md 5, README point to it. No template changed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
6.1 KiB
Onboarding record —
app: opened: YYYY-MM-DD template_at:
0.1 | open | not started: Open-source licence 0.2 | open | not started: Upstream is alive: a release in the last 6 months, issues answered 0.3 | open | not started: An official image with version tags (not latest only), amd64 (+ arm64 if pi_compatible) 0.4 | open | not started: Telemetry / phone-home 0.5 | open | not started: Needs the internet at runtime (claim tokens, first-start downloads)? 0.6 | open | not started: Needs ports other than HTTP(S)? The tunnel carries HTTP only 0.7 | open | not started: Phone / desktop apps: which login route do they call, and does it work through the … 0.8 | open | not started: What a household gets from it, in one sentence (Hungarian) 0.9 | open | not started: The app does not call ITSELF at its public name (server-side), or the bench override … 1.1 | open | not started: Every image pinned to a concrete tag that resolves 1.2 | open | not started: Database engine and major = what the app's own upstream compose runs 1.3 | open | not started: MariaDB sidecar: MARIADB_AUTO_UPGRADE=1 1.4 | open | not started: The app migrates its own database at start, or the switch that makes it do so is set 1.5 | open | not started: The app runs its production server, not a development server 1.6 | open | not started: Every key and secret the app READS is set or generated 1.7 | open | not started: Every start-time switch in the image's entrypoint is read and decided (migrations, … 1.8 | open | not started: Debug / development mode is OFF on the public origin 1.9 | open | not started: A secret whose loss destroys data or locks people out (it encrypts stored data, or … 2.1 | open | not started: Every path the app writes is mounted 2.2 | open | not started: Where each path lives: named volume (NVMe) / ${HDD_PATH}/appdata / ${USERDATA_PATH} 2.3 | open | not started: Backup class for every HDD path (backup: in .felhom.yml) and what the tier-1 unit holds 2.4 | open | not started: File owner / uid fits the box (PUID/PGID where the image wants them) 2.5 | open | not started: A backup and a restore through the product, data read back 2.6 | open | not started: "Remove with data" and "remove, keep data" both do what they say 2.7 | open | not started: Off-site size for a typical household 2.8 | open | not started: A file the household uploads opens again through the front door 3.1 | open | not started: First-admin class (FIRST-ADMIN.md 1–6), measured, and the household can make its first … 3.2 | open | not started: Known default login → after_install with a generated password (and a generated name, … 3.3 | open | not started: Open first-run screen → setup_gate (+ a probe that flips, measured before and after) 3.4 | open | not started: Open sign-up after the setup → signup_block / after_setup 3.5 | open | not started: The install window: a stranger reaches nothing before the password is replaced 3.6 | open | not started: Lock-out: N wrong passwords by a stranger for the public name 3.7 | open | not started: The household can change its password and add family members 3.8 | open | not started: Secrets pass to commands as arguments, never inside program code 3.9 | open | not started: Sign in the way each client does, through traefik over https: the browser form (with … 4.1 | open | not started: Compose healthcheck of the family the IMAGE has (inspected, one tool per run), … 4.2 | open | not started: The controller probe dials what the compose healthcheck dials 4.3 | open | not started: Healthy within start_period on a cold first start (incl. one-time imports), with no … 4.4 | open | not started: Negative control: a broken app reads unhealthy 4.5 | open | not started: The probe-named container is the stack name 5.1 | open | not started: First start from birth, swap OFF: peak anon, oom_kill = 0 5.2 | open | not started: 10-minute soak under the household's heaviest ordinary act: peak anon < 80 % of the … 5.3 | open | not started: mem_limit in .felhom.yml = the sum of the compose limits, and the header comment says … 5.4 | open | not started: Node/Java apps: does the heap size itself from the limit? 5.5 | open | not started: Pi-compatible (yes/no) and the disk the images pull 6.1 | open | not started: An upgrade fixture: seed + read-back through the app's own front door, negative control 6.2 | open | not started: A first ladder step proven on bench + 9202 (--write-ladder), or "manual only" with the … 6.3 | open | not started: The undo works on a real failure (one forced-fail case) 6.4 | open | not started: files_may_change understood (which files change at start) 6.5 | open | not started: Tag shape is stable upstream (no v dropped, no flavour prefix) and whether the … 7.1 | open | not started: Sends mail? → smtp_mapping + ${VAR:-} compose lines 8.1 | open | not started: Hungarian + English, informal „te", no „kérjük" 8.2 | open | not started: app_info: tagline, use_cases, first_steps, default_creds (if any), add_people 8.3 | open | not started: Logo + screenshots on felhom.eu by slug 8.4 | open | not started: README tables, FIRST-ADMIN row, category, catalog_since 8.5 | open | not started: The website's app count still holds 9.1 | open | not started: python3 scripts/catalog_gates.py 9.2 | open | not started: A fresh install on 9202 from the drill catalog, as a household and as a stranger, … 9.3 | open | not started: Every item above done or n/a-with-reason 9.4 | open | not started: Published to the live catalog in ONE commit with its record