docs(v0.222.0): REPORT, CONTEXT decisions, README state table + the ordering
gates / gates (push) Successful in 11s

REPORT.md overwritten with the full run: baselines and the hub's four numbers,
the four red-proofs with the mutation and observed text for each, the five
IsDownState consumers walked and named, the live walk in full with the old and
new heartbeat lines quoted side by side, and the halt.

CONTEXT records the decision - a dead supervised member is asked about before a
failing healthcheck, because they are different questions and the second was
answering the first - plus the fence that IsDownState did not move, the trap
that three existing subtests pinned the defect, and R-386.

README gains the `degraded` row, which the state table never had, and a note
that the ORDER is load-bearing. Points at the new alarm-ladder architecture doc.
This commit is contained in:
2026-08-23 07:58:09 +02:00
parent 5da11c4480
commit 14137efac5
3 changed files with 320 additions and 80 deletions
+10 -1
View File
@@ -702,10 +702,19 @@ When app templates are updated (e.g., a new `APP_KEY` secret is added to `.felho
| Running + starting | Orange | "Indulas..." | Healthcheck not yet passed |
| Deploying | Orange | "Telepítés..." | Compose up in progress (image pull, container creation) |
| Running + unhealthy | Yellow | "Nem egeszseges" | Docker or controller-side healthcheck failing |
| **Degraded** | Red | "Leallitva" (counts with stopped) | **A SUPERVISED member of a multi-container app is dead** — e.g. the app's database — while other members are still up. Counts as DOWN: raises the dead-app banner and `app_start_failed` (R-51, R-384) |
| Stopped/exited | Red | "Leallitva" | All containers stopped |
| Restarting | Yellow | "Ujrainditas..." | Restart loop |
| Restarting | Yellow | "Ujrainditas..." | Restart loop; becomes down only after 5 minutes sustained (crash loop) |
| Not deployed | Gray | "Nincs telepitve" | Compose file exists, not deployed |
**The order these are decided in is load-bearing (v0.222.0, R-384).** `degraded` is evaluated
**before** `unhealthy`/`starting`/`restarting`. An app whose database dies drags its own front end
`unhealthy` seconds later — so if `unhealthy` were decided first (as it was until v0.222.0), the
symptom would mask the fault and the app would be silently down. A down member whose restart policy
is `no`/`on-failure` is a finished one-shot init/migrate container and stays benign. The full ladder,
including which states deliberately do NOT alarm and why, is documented in
`felhom.eu/documentation/architecture/08-alarm-ladder.md`.
**Route-unpublished indicator (F5, v0.61.0).** Traefik's Docker provider only publishes a route to a
container that is healthy (or has no healthcheck), so an `unhealthy`/`restarting` deployed app returns a
hard **404** at its URL even though the container is running. The `routeUnpublished` template helper