The shared rule file carries the same wording in felhom.eu, felhom-controller, felhom-agent, app-catalog-felhom.eu and the workspace root on DooPlex -- "change all five or none" -- so this is this repo's copy of a rule added in felhom.eu a08bd3cbd5. A session that changes a fact listed in architecture/felhom-system-poster.facts.md (a machine, a role, a traffic path, a backup tier, a time, a retention, a key, a known gap) updates that file in the same commit; fixes the poster's text if the change is text only; or adds "System poster needs a refresh: <what changed>" to STATUS. The report names which of the three it did. The poster is drawn in Claude Design and nothing in the repo renders it, so scripts/poster_facts_gate.py only WARNS when the facts outrun the drawing -- it never fails a push, because a refresh needs the operator and another tool. Verified identical to the other four copies by diff, before and after.
6.3 KiB
unconditional
| unconditional |
|---|
| true |
Unprompted work — rules for any session without a task file
Goal sessions, nightly sessions, "work the register" sessions. A session that starts from
/goalor a standing brief inherits these rules exactly as it inherits the gates. They are the part ofPROMPT-TEMPLATE.mdthat a task file used to carry and a goal does not. Same wording lives infelhom.eu,felhom-controller,felhom-agentandapp-catalog-felhom.eu.claude/rules/, and in the workspace root's unversioned.claude/rules/; change all five or none.
1. What you may pick up on your own
- A register row you or another CC session filed, with owner CC, at P3 or a bounded P2, that needs no operator decision, touches no customer data by design, and introduces no mechanism nobody has measured. Smallest first.
- A defect you find while exercising the product, filed as a row before you fix it — unless it is small:
a small finding is fixed in the session and never filed (the size rule,
OPEN-ITEMS.md„How a row is filed"). - Hygiene: register compression, stale citations, rows with no owner, documents that contradict live source.
Not yours, ever, without a task file or an operator word: money; anything that changes risk to
customer data; anything that changes a promise the product makes to a customer; anything that
reverses a documented design decision (documentation/architecture/ — a design decision is not a
defect, R-370); anything on DooPlex or ep0; baking or vouching a golden; promoting a
catalog version; a new external dependency; a hub image build or hub deploy in a session the operator does not
attend (operator ruling 2026-10-07, 09 §3 decision 162).
2. When you may decide instead of ask (operator grant, 2026-09-14)
You may take a decision yourself when all of these hold: the architecture folder and the register
give a clear direction; your choice follows that direction; it is reversible without customer-data
risk; and you can write it in the 09-update-architecture.md §3 shape — one answerable sentence, the
options, what each costs, why this one. Then record it as a dated decision in CONTEXT.md and
the owning architecture document, tagged decided by CC unattended — operator may reverse, and put
it first in the morning note. A decision you cannot write in that shape is one you do not take.
3. The discipline a task file used to carry
- Baselines first. Read each repo's
mainhash and version from live source before touching it. - Read the architecture document for the area, and name it in the report, before any claim.
- Red-proof every correctness fix. A test never seen failing has not been shown to test anything.
- Live-validate on a Tier-0 box through the endpoints the UI invokes.
demo-hpisssh hp. Throwaway apps only; the standing apps andbentopdfstay. - Evidence off the machine at the end of each phase, before any revert (R-320).
- One release per repo per session, with a CHANGELOG entry (controller: with its
MinAgentline), REPORT overwritten, floor raised to deliver it. No golden unless a drill or fresh install needs one (the waiver, R-468). No--no-verify. - An enumerated gap becomes a row in the same session — or, if it is small, is fixed in it (the size rule). Prose is not a record.
- Hungarian text is searched with ASCII fragments, with a positive and a negative control.
- Never leave a half-state. If time runs out, revert to clean and say what was reverted.
- Teardown, three layers, stated — machine, host, hub — or "provisioned nothing".
- Every helper prompt carries the brief's fences in full (operator ruling 2026-10-07). A helper session (a
subagent, a fork, a workflow agent) gets the brief's fence list word for word — every protected machine, every
„no", every delivery and Docker limit — not a summary and not „the usual fences". Earned on 2026-10-06 night: two
helpers whose prompts carried only part of the fences ran
docker volume pruneon the bench and a Docker-using gate on DooPlex.
4. The morning note
One screen, plain language, in this order: decisions you took (§2) first; what you exercised; what broke and whether you fixed it; rows opened and closed with the register size before and after; what needs the operator, each with what happens if they do nothing. No file paths, no function names, no row numbers as the subject of a sentence.
5. Instruction files
Instruction files (CLAUDE.md, .claude/rules/*) are kept true by the session that finds them wrong
(operator ruling 2026-10-06, 09 §3 decision 150). A session MAY, without asking: correct a stale fact (a command, a
count, a version, a path, a description of what a gate does), add a fact it proved, and remove a reference to something
that no longer exists. Each edit is named in the report (file, line, before, after, why). A session MAY NOT, without the
operator's word: loosen a safety rule, a fence, a „never", a protected machine, a secret rule, or a review step; or
remove a rule. When in doubt, it is a rule change, and it goes to the operator. If Claude Code's own permission check
asks before such an edit, wait for the operator's click; if it refuses, record that and file the exact line.
6. The system poster stays true
A session that changes a fact listed in architecture/felhom-system-poster.facts.md (a machine, a
role, a traffic path, a backup tier, a time, a retention, a key, a known gap) updates that file in
the same commit. If the change is text only, it also edits the matching text in
felhom-system-poster.html. If it needs a new drawing, it adds the line
"System poster needs a refresh: " to STATUS.md's "waiting on the operator" list.
The session report names which of the three it did.
Why the three-way split: the poster is a drawing made in Claude Design, and nothing in this
repository renders it — unlike where-felhom-stands.html, which has render_stands.py. So the
facts file is the source of truth and the drawing trails it. scripts/poster_facts_gate.py warns
when the facts file has a newer commit than the poster; it never fails a push, because a refresh
needs the operator and another tool, and a gate nobody can clear is a gate people learn to route
around.