v0.284.2 — the image clean-up sees digest-pulled (untagged) images (decision 53, R-736)
gates / gates (push) Successful in 26s

Found live on 9202: the product pins tag@digest, and such images are stored untagged (repo:<none>);
`docker image ls` without -a did not list them, so the retention saw almost no app image. Now `image ls -a`;
an anonymous <none>:<none> entry is never a candidate; the one-time marker is v2 so the corrected sweep runs
once everywhere. Test TestImageRetention_SeesUntaggedDigestPulledImages, red-proofed. 0.284.0/0.284.1 were
never floored.

MinAgent: 0.131.0 (unchanged).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-30 23:03:32 +02:00
parent 00fddd3816
commit a70c398dee
6 changed files with 53 additions and 5 deletions
+1 -1
View File
@@ -1938,7 +1938,7 @@ that folder is never a dead end, and an install never runs into it silently (R-6
- **Image retention (v0.284.0, decision 53)** — after a guarded Update and at remove, an app's older images are deleted:
kept are every container's image, every installed compose's, and each installed app's running + `previous_images`.
By exact id, never forced or pruned; no pass while any update runs; a one-time sweep at the first start after the
release (marker `image-retention-v1.done` in the data dir). See `internal/stacks/image_retention.go`.
release (marker `image-retention-v2.done` in the data dir). See `internal/stacks/image_retention.go`.
- **The setup gate (v0.280.0, decision 46)** — `.felhom.yml` `setup_gate: true` + optional `setup_done_probe: {url, field,
done}`. A FRESH install is closed to everyone but the household: the traefik file
`<stacks>/traefik/dynamic/setup-gate-<app>.yml` is written BEFORE the first start (a failed write refuses the install) and