25c30ba625
Enabling Megosztás on a fresh box pulled felhom-samba from the registry with zero feedback — minutes of silent nothing. Observed live, twice. Cause: this script carried its own hand-maintained array of three image tags, with a comment telling the reader to keep it in sync with the controller's internal/infra constants. It drifted the moment a fourth stack was added. felhom-samba was never added here, so the golden baked 3 of 4. The fix is structural rather than a fourth copy of the list: it now comes from the controller image the bake just pulled (--print-infra-images, backed by infra.Images(), which derives from the pins themselves). The golden bakes exactly what THAT controller version will request, so the two cannot disagree. Ordering fix this exposed: docker logout ran immediately after the controller pull, but felhom-samba is on the same private registry, so the infra loop would have 401'd. Logout moved after the loop, plus a hard assertion that no credential remains in the guest before it is archived. Pre-0.147.0 controllers have no such flag; the bake falls back to the historical 3-image list and says so loudly — the fallback IS the drift-prone thing being removed, so it must never pass silently. No agent version bump: build tooling only. Effective at the next golden build; the current golden is not rebuilt for this. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Nn3VgQk9iwEGgyx6QJ2NvE