v0.279.0: after_install (decision 45), known default logins on the page, Part D empty-backup alarm, night chain (R-705), R-706
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,30 @@
|
||||
## v0.279.0 — no app goes live with a login a stranger knows (after_install); an empty backup of a running app is an alarm; the night's chain on a button; R-706 (2026-09-28)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged; Part D rides the existing operator-only
|
||||
`backup_run_failures` digest). New strings: `app_info.known_login`, `backups_apps.hollow_local`,
|
||||
`backups_apps.hollow_offsite`, `debug.night_chain` (hu + en). Evidence: `felhom.eu/documentation/audits/logins-nvme-2026-09-28/`.
|
||||
|
||||
- **`after_install:` (`09` §3 decision 45).** A template may declare ONE command the box runs once in the app's own
|
||||
container after a FRESH install (the deploy-done hook, ok=true) — to replace a known default login with a generated
|
||||
`type: password` field, shown on the app page as the first password. `env:` names the deploy values filled into
|
||||
`${NAME}` (an undeclared or empty one refuses — never an empty password); `success:` is a marker the output must
|
||||
carry (claper's CLI exits 0 on an error). Retried while the app boots (6 × 20 s), recorded in `app.yaml`
|
||||
(`after_install: {at, ok, detail}`), never logged expanded. Never on a restore or a kept-data load (R-694). The
|
||||
deploy-done hook is now set on EVERY box (it was inside `if notifier != nil`, so a box with no hub would never run it).
|
||||
- **The page says when a default login is in effect** (`defaultLoginInEffect`): the install dialog before the install
|
||||
when nothing will replace it, the app page while it is in effect ("This app starts with a known, shared password: %s.
|
||||
Change it right after the install."); the default-login card is HIDDEN once after_install replaced it.
|
||||
- **Part D — a running app whose newest copy holds no data is an alarm.** At the end of the dump leg (the local unit)
|
||||
and in the off-site loop (the pushed unit): an installed app that RUNS and has volumes, whose copy lists no dump and no
|
||||
tar → the operator digest once per app per tier per day, and a sentence on the backup page until a later check finds
|
||||
data. A held app that is stopped is not flagged. Measured before: yesterday's demo-hp nextcloud had a WARN line only.
|
||||
- **R-705 (controller half):** debug action `POST /api/debug/backup/night-chain` — dump → Tier 2 → off-site → update leg,
|
||||
one at a time, refused while a backup/restore op, a guarded update or another chain runs. The update leg gets its
|
||||
normal length from its own start (`RunUpdateLegNow`; by day the night's W+5h has passed).
|
||||
- **R-706:** a removal "with its backups" also deletes the app's off-site verification copy.
|
||||
- Tests: `TestAfterInstall_*` (stacks + main.go wiring), `TestKnownLogin_*`, `TestPartD_*` (backup + page),
|
||||
`TestR705_*` (web + stacks), `TestR706_*`. Red-proofs RP7–RP15, each seen failing on an assertion.
|
||||
|
||||
## v0.278.0 — a hold left by an earlier install no longer holds the new one (R-704) (2026-09-28)
|
||||
|
||||
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged). New strings: none. Evidence:
|
||||
|
||||
Reference in New Issue
Block a user