controller v0.264.0: the household is told when an update is undone or held, in its language
gates / gates (push) Successful in 25s

app_update_undone / app_update_held events (09 decision 15), on by
default and seeded once on existing boxes; R-606 update sentences as
key+args rendered per reader; R-646 startup applied-meta backfill for
apps current with the catalog; R-620 a disabled notifier WARNs once per
event type. Needs hub v0.120.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-23 13:51:21 +02:00
parent c3a2aba0d2
commit bc278944a3
27 changed files with 1086 additions and 86 deletions
+12
View File
@@ -650,6 +650,16 @@ the old version back; a power cut while undoing resumes the undo. Reasoning and
`felhom.eu/documentation/architecture/09-update-architecture.md` §6.1a,
`felhom.eu/documentation/audits/undo-bakeoff-2026-09-23/`.
**The household is told (v0.264.0).** An undone update sends `app_update_undone` (warning) ONCE; an
update that ends held sends `app_update_held` (error) ONCE — also when the hold itself could not be
saved. Details `{app, stack_name, from, to, at, copy_tier, copy_date, copy_holds}`. Both are in
`DefaultEnabledEvents` and on the notifications page; an existing box gets them once, add-only
(`app_update_events_seeded`). Needs hub v0.120.0 (allow-list, mail entries in hu and en, per-app
cooldown). Every update sentence — the phase label, the refusals, the failure lines, the hold
sentence and its prefix — is stored as a key + args and rendered in the READER's language (R-606);
the Hungarian stored text is unchanged. At startup, an app already CURRENT with the catalog gets its
`applied-meta/` record (R-646); a behind app is skipped by name, never guessed.
**Start/restart never answer "completed" (v0.263.0, R-642)** — they answer what was requested and the
state the containers are in at that moment; whether the app works is the health probe's to say.
@@ -2420,6 +2430,8 @@ The controller pushes structured events to the Hub's `/api/v1/event` endpoint. T
| `app_deployed` | info | New app deployed via API |
| `app_removed` | info | App removed via API |
| `app_start_failed` | **warning** | A DEPLOYED app is not running (fix-3) — fired ONCE per running→down transition. **Customer-switchable („Alkalmazás nem fut"), OFF by default; the OPERATOR is e-mailed regardless.** Was `warn` until v0.223.0 — see the severity note below |
| `app_update_undone` | warning | v0.264.0 — a guarded update failed and the box put the previous version and its data back. Once per app per failed step. Household ON by default |
| `app_update_held` | **error** | v0.264.0 — a guarded update (or its undo) failed and the app is held until a restore. The mail's line is the hold sentence in the household's language. Household ON by default |
| `disaster_recovery_started` | warning | DR restore begins |
| `disaster_recovery_completed` | info/error | DR restore finishes (success/partial) |