controller v0.271.0: automatic app updates — the update leg after the off-site copy, the backup gate waits, the switch (09 6.4 part 7; R-680, R-678, R-643)
gates / gates (push) Successful in 24s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-24 22:07:24 +02:00
parent 1495ca43fb
commit 9cf13a3add
33 changed files with 1672 additions and 14 deletions
+16
View File
@@ -724,6 +724,22 @@ finished at the next start: what it started is removed (volumes kept), `app_depl
apps page says the install was interrupted until the next install (R-681). The recovery unit keeps the pinned
version's `.felhom.yml`, and a restore makes it the applied record (R-669).
**Automatic updates (v0.271.0, `09` §6.4 part 7, decisions 11–15, 20).** Each night, after the off-site leg
(chained in the `offbox-backup` job on every path — configured or not, ok, failed, panicked; a box without an
off-site target runs it at W+105m), the box presses the SAME guarded Update a person presses: one app at a time,
ONE tested step per app per night, only a `proven` ladder entry; never a step marked `needs_person`; a
`files_may_change` step only when a fresh WHOLE copy exists (`backup.FreshWholeCopy`, the hold's truth table);
never an app older than the ladder, held, current, ahead or unorderable; never the step that was undone or held
before while the catalog's ladder is unchanged (`app.yaml` `failed_update_step`, R-680 — a person can still press
it). A passing refusal (`busy`…) is retried once. No step starts at or after W+5h, and the full-system backup's
gate waits for the leg until W+5h (then only for a step in flight, at most to W+5h30m). The controller's own
self-update waits for the whole leg. Switch: settings page „Alkalmazások automatikus frissítése" /
"Automatic app updates", `settings.json` `app_update.unattended`, **absent = ON**. A successful automatic step
sends no mail; the app page says „Automatikus frissítés %s-kor — sikeres." (`app.yaml` `last_auto_update`).
One summary line per night (`[update-leg] update leg (after-offsite): done=… undone=… held=… failed=…
skipped=… [skipped: app=reason, …]`) in the log and in the hub report's `update_leg`. After `done`/`undone` the
app's steps-left and badge are fresh at once (R-678). `stacks.update_window` is removed (it was never read).
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
state the containers are in at that moment; whether the app works is the health probe's to say.