v0.284.0 — a box deletes old app images (decision 53, R-736); an after_install app is held until its known login is replaced (R-741)
gates / gates (push) Successful in 27s

Image retention: after a done/undone guarded Update and at remove, an app's images older than its running
and previous one are deleted — never an image any container, installed compose or installed/previous record
names (box-wide keep set read at delete time); exact id, never forced or pruned; paused while any update runs;
a one-time sweep of catalog app images at the first start. Install hold: an after_install app is installed
behind the setup gate's door and opens when after_install succeeds or the household says it changed the login.
Tests TestImageRetention_* and TestInstallHold_* with red-proofs; parity fixture for the held card.

MinAgent: 0.131.0 (unchanged).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-30 22:29:33 +02:00
parent d48da6c7f3
commit 5a3437669f
23 changed files with 1724 additions and 23 deletions
+8
View File
@@ -1931,6 +1931,14 @@ that folder is never a dead end, and an install never runs into it silently (R-6
**v0.280.0 (R-710):** an absent record means "not run yet" only for 30 minutes after the install (an app installed
before its template gained the command is warned), and the card has "I changed it" (`POST /apps/<slug>/default-login/changed`
→ `app.yaml` `default_login`), after which the card goes.
- **The install hold (v0.284.0, R-741)** — an app with `after_install:` is installed HELD: the setup gate's forwardAuth
door stands in front of its routers (`install-hold-<app>.yml`, priority above the gate) until `after_install` succeeds
or the household says it changed the login; app.yaml `install_hold` (the gate's record shape). A stranger is refused;
the household passes. See `internal/stacks/install_hold.go`.
- **Image retention (v0.284.0, decision 53)** — after a guarded Update and at remove, an app's older images are deleted:
kept are every container's image, every installed compose's, and each installed app's running + `previous_images`.
By exact id, never forced or pruned; no pass while any update runs; a one-time sweep at the first start after the
release (marker `image-retention-v1.done` in the data dir). See `internal/stacks/image_retention.go`.
- **The setup gate (v0.280.0, decision 46)** — `.felhom.yml` `setup_gate: true` + optional `setup_done_probe: {url, field,
done}`. A FRESH install is closed to everyone but the household: the traefik file
`<stacks>/traefik/dynamic/setup-gate-<app>.yml` is written BEFORE the first start (a failed write refuses the install) and