### STEP 8 — TEARDOWN

== LAYER 1 — the guest (9202): remove the throwaway app through the product ==
-- POST /api/stacks/uptime-kuma/remove {remove_hdd_data:true, remove_backups:true} --
{"ok":false,"error":"stack \"uptime-kuma\" is still running — stop it first before removing"}

HTTPCODE:409
   -> 409: the product requires a stop first. Doing that through the product too.
-- POST /api/stacks/uptime-kuma/stop --
{"ok":true,"message":"Stack uptime-kuma stop completed"}

HTTPCODE:200

-- POST /api/stacks/uptime-kuma/remove --
{"ok":true,"data":{"removed":"uptime-kuma","volumes_removed":["uptime-kuma_uptime_kuma_data"],"hdd_paths_removed":[],"hdd_paths_preserved":[],"hdd_note":"Az alkalmazás nem tárolt saját adatot külső meghajtón, így ott nem volt mit törölni.","backup_paths_removed":["/mnt/sys_drive/felhom-data/backups/primary/uptime-kuma (24K)"]},"message":"Stack uptime-kuma removed"}

HTTPCODE:200

-- verify the guest is back to how I found it --
felhom-controller | gitea.dooplex.hu/admin/felhom-controller:0.260.0 | Up 5 minutes (healthy)
filebrowser | gtstef/filebrowser:1.3.3-stable | Up 5 minutes (healthy)
traefik | traefik:v3.6.7 | Up 5 minutes
  stack dir /opt/docker/stacks/uptime-kuma : STILL-PRESENT
  docker volume uptime-kuma_uptime_kuma_data : 0
  deployed stacks now (expect only protected traefik, as at baseline):
    total templates: 55
    traefik deployed= False protected= True orphaned= False

  update-journal.json: ABSENT

== LAYER 2 — the host (demo-hp): guest 9202 left RUNNING, 9201 untouched ==
status: running
  9201 -> status: running
  (9201 was never a target: no pct exec, no stop, no start was issued against it this session)
  helper files I left on the host/guest, now removed:
    cleaned

== LAYER 3 — the hub ==
  Nothing provisioned. Guest 9202 has hub reporting OFF and no tunnel, so no host, no escrow,
  no report and no customer record was created at any point. Nothing to tear down.

-- NOTE: /opt/docker/stacks/uptime-kuma survived the remove. Contents: --
total 20
drwxr-xr-x  2 root root 4096 Sep 21 11:11 .
drwxr-xr-x 57 root root 4096 Sep 13 20:22 ..
-rw-r--r--  1 root root 3318 Sep 21 11:04 .felhom.yml
-rw-r--r--  1 root root 1597 Sep 21 11:08 applied-compose.yml
-rw-r--r--  1 root root 1597 Sep 21 11:08 docker-compose.yml
-- is this normal for this box? compare with another never-deployed app's dir --
actualbudget
adventurelog
audiobookshelf
bentopdf
bookstack
calcom
calibre-web
claper
code-server
crafty-controller
docmost
emby
filebrowser
ghost
gitea
glance
gokapi
grafana
gramps-web
home-assistant
-- does app.yaml still claim deployed? --
(no app.yaml — the deploy record is gone)
-- POSITIVE CONTROL: a never-deployed app has the SAME shape, so this is not a leftover --
total 16
drwxr-xr-x  2 root root 4096 Sep 13 20:22 .
drwxr-xr-x 57 root root 4096 Sep 13 20:22 ..
-rw-r--r--  1 root root 3517 Sep 20 14:47 .felhom.yml
-rw-r--r--  1 root root 1412 Sep 13 20:22 docker-compose.yml
  -> uptime-kuma now matches: .felhom.yml + docker-compose.yml + applied-compose.yml, NO app.yaml.
  -> the pre-update-compose.yml / pre-update-applied.yml copies the update left are GONE.
  CORRECTION to the line above: applied-compose.yml is NOT present on both. actualbudget has only
  .felhom.yml + docker-compose.yml; uptime-kuma additionally retains applied-compose.yml after the
  remove. So the remove leaves ONE residual file that a never-deployed app does not have.
  Stated as observed, not diagnosed: I did not establish whether that is intended (a record of what
  was last applied) or a small gap in RemoveStack. It carries no customer data. Not called a defect
  on one observation.

== CATALOG REPO — back to the pre-bump image, clean, pushed ==
-- git log --
ff9717d REVERT the drill bump: uptime-kuma back to 2.4.0 (update-arc measurement finished)
89304ab DRILL: uptime-kuma 2.4.0 -> 2.5.0 for the update-arc measurement (reverted in this session)
bd22749 REPORT for the R-469 rule lift
-- working tree --
   (empty above = clean)
-- HEAD vs origin/main --
   HEAD=ff9717d3794974724e09f8fd58abf058d4cdc2d0
   origin/main=ff9717d3794974724e09f8fd58abf058d4cdc2d0
-- the actual image: line --
11:    image: louislam/uptime-kuma:2.4.0
-- catalog_since (deliberately today, not 2026-07-18 — the gate's rule) --
13:catalog_since: "2026-09-21"

-- diff of the whole drill against the pre-drill commit 5ff36d0 --
-catalog_since: "2026-07-18"
+catalog_since: "2026-09-21"
   (image line identical to pre-drill; only catalog_since differs, as the gate requires)
-- and the box's cached copy agrees --
    image: louislam/uptime-kuma:2.4.0

== FINAL STATE CHECK ==
9202 status: status: running
felhom-controller | gitea.dooplex.hu/admin/felhom-controller:0.260.0 | Up 6 minutes (healthy)
filebrowser | gtstef/filebrowser:1.3.3-stable | Up 6 minutes (healthy)
traefik | traefik:v3.6.7 | Up 6 minutes
credential file /tmp/.ctlpw on DooPlex: removed

NOTE: 00-drift.py and 00-upstream-drift-raw.txt in this directory are NOT mine — they predate
      my first write (12:53 vs 12:56) and belong to another session. Files 01-20 are mine.
