controller v0.269.0: whole restore from the second drive; crash loops stopped; exact image digests; steps judged by their own .felhom.yml (decisions 26-28, R-661 R-666 R-667 R-668 R-664 R-665 R-662, 09 6.4 part 6)
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 12:18:39 +02:00
parent 7c3b3a9694
commit 3c6b49b31c
141 changed files with 3401 additions and 237 deletions
+12
View File
@@ -704,6 +704,18 @@ unit restore both refuse it (R-538) — with what it holds. With none, the sente
app raises no `app_start_failed` (R-660). A removed app leaves no `applied-compose.yml` / `applied-meta/`
(R-651).
**The second drive brings a file app back whole (v0.269.0, decision 26).** For an app with drive files, the
second drive's „Teljes visszaállítás" merges the files (never deletes, never overwrites a newer live file, keeps
a replaced older one beside as `.felhom-<ts>`) and then restores the unit from the mirror.
**A crash loop is stopped (v0.269.0, decision 28).** ≥ 6 container restarts in 10 min (from `RestartCount`) or
≥ 20 OOM kills in 30 min → the box stops the app, holds it (`unhealthy_stop`), shows Start, and sends
`app_stopped_unhealthy`. Start gives one more try; a repeat within 24 h says support is informed.
**Exact images (v0.269.0, `09` §6.4 part 6).** The compose that runs pins `tag@sha256` from the ladder entry that
tested it; pins stay plain; a floating tag reads Behind only for a newer TESTED digest. An update judges the new
version by its own `.felhom.yml` (the step's, or the catalog's). A stranded app's Remove keeps the data.
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
state the containers are in at that moment; whether the app works is the health probe's to say.