Correct the placement mis-framing, and file what we wrote down and never filed (R-368..R-375)
gates / gates (push) Successful in 16s

Documentation and survey only. No code, no machine contacted.

THE CORRECTION. The 40 catalogue templates without a configurable path are not missing a
choice: 01-topology-and-trust.md:150-152 classes each volume hot (DB/config/cache -> fast
storage, ENFORCED) or bulk (media/files), and the 40 are all-hot apps. The deploy page has
been saying so to the customer all along (deploy.html:624-625). SPEC-app-data-placement and
R-352 are corrected in place with the framing MARKED, not deleted; every measurement stands.
R-356 was re-checked and survives, strengthened - an absent HDD_PATH is the normal state, so
reading it as "not installed" misreads a correct configuration.

The disk claim, precisely: since R-165 there is ONE guest data volume with two binds, not two
volumes (build-golden.sh:29-40, 99). A physical-disk failure losing data and first-tier copy
together is REAL and is what the other tiers exist for. A full data volume stopping the OS is
NOT real and was the overstated one.

THE SWEEP. 113 survey-class documents examined, 14 statements of "not filed", 2 already filed.
Its positive control convicted the sweep itself twice before it convicted the corpus - markdown
bold broke the strongest pattern, and the reporter re-searched a truncated line - both false
zeros of the exact class being hunted, and together worth 2 of the 14.

THE HEADLINE. The gap the 2026-08-21 drill rediscovered WAS filed - as R-107, ROADMAP.md:122,
M/READY, 2026-07-28 - and is absent from OPEN-ITEMS.md, which calls itself the single source of
truth. OPEN-ITEMS and that rule both landed 2026-07-27; R-107 went to ROADMAP alone the day
after. 72 ids live only in ROADMAP, 29 not done, some of them findings. Filed as R-369 (HIGH).

Five more still-open gaps filed with their ages: R-371 (17d), R-372 (38d, the oldest), R-373
(20d), R-374 (14d), R-375 (4d). R-368 corrects Part 4: the storage default IS applied at deploy
time via deploy.html:612 - the earlier "the deploy route never reads it" came from grepping Go
and never the templates. R-370 records the process failure and is closed by the template change.

PROMPT-TEMPLATE gains the two rules it lacked: name the architecture document for the area and
say what it says (with a file->area map and the test "is this something we chose?"), and an
enumerated gap becomes a register row in the same session - a ROADMAP row alone does not count.

Ceiling R-367 -> R-375.
This commit is contained in:
2026-08-22 11:18:08 +02:00
parent 5a7502b6d5
commit 091a4b7444
6 changed files with 822 additions and 346 deletions
+48 -2
View File
@@ -130,8 +130,35 @@ never park it on a branch.
conventions, access). Versioned copy: `felhom.eu/documentation/runbooks/workspace-CLAUDE.md`.
2. `<repo>/CLAUDE.md` — repo build/deploy, code-quality rules, trunk-based + live-validation rules.
3. `<repo>/CONTEXT.md` — current project state / decisions / roadmap.
4. `felhom.eu/documentation/architecture/02-controller-module-map.md` — KEEP/PORT/DELETE/MODIFY
per-package classification. **Read before touching `backup/`, `storage/`, `system/`, `config/`.**
4. **THE ARCHITECTURE DOCUMENT FOR THE AREA THIS TASK TOUCHES — NAME IT AND SAY WHAT IT SAYS.**
Not "read the architecture folder": name the file, and state in one line what it rules about this
area. **A prompt that cannot name one says so explicitly, and that absence is itself recorded** —
an undocumented architectural decision is how a deliberate design gets "fixed" by someone who did
not know it was one.
| area | file |
|---|---|
| what the platform does today, per scenario | `00-capability-map.md` |
| topology, trust, **app-data placement (hot vs bulk)**, backup scoping | `01-topology-and-trust.md` |
| controller packages: KEEP/PORT/DELETE/MODIFY | `02-controller-module-map.md` |
| the host agent | `03-host-agent.md` |
| control-plane authorization | `04-control-plane-authorization.md` |
| the hub | `05-hub-architecture.md` |
| off-site connectivity | `06-offsite-connectivity.md` |
| tiers, capture sets, restore paths, recovery model | `07-backup-architecture.md` |
**Three sources, in this order, before any claim: the architecture folder holds the REASONING, the
register holds the WORK, source holds the TRUTH.** Skipping the first is how a decision gets
reported as a bug.
**And the test that catches it: _is what I am about to call a defect something we chose?_** If it
was chosen and the choice is wrong, that is **a proposal to change a decision** — it goes to the
operator as a decision, not filed as a bug. **Cost of learning this (R-370):** between 19 and 22
August a documented placement decision was called a defect in four places, because the register and
live source were read and `documentation/architecture/` was not.
`02-controller-module-map.md` remains **required reading before touching `backup/`, `storage/`,
`system/`, `config/`.**
5. `felhom.eu/documentation/controller/<feature>.md` — code-verified feature docs (authoritative; match
code, not summaries, if they drift).
6. `controller/README.md` (or `felhom-agent/README.md`) — module map, feature reference, REST API.
@@ -347,6 +374,25 @@ or **what is open changed**), update **all four** in the SAME session:
that changes what is open without touching it re-creates exactly the thread-loss the register was
built to solve: `REPORT.md` is overwritten every session, so nothing durable may live only there.
> **AN ENUMERATED GAP BECOMES A ROW, IN THE SAME SESSION. PROSE IS NOT A RECORD.**
>
> This binds **surveys, inventories, spikes, reviews and diagnoses**, not only implementation
> sessions — those are the documents that enumerate gaps, and they are the ones that have lost them.
> If a document says a thing is missing, unhandled, unreachable or *"not currently filed"*, it does
> not leave the session as prose. It leaves as a row here, with a rank and an owner. Writing
> *"not filed"* is not a disposition; it is a note that the work was seen and dropped.
>
> **A row in `ROADMAP.md` alone does not satisfy this.** Both files hold open work and only this one
> calls itself the source of truth, so a finding recorded solely there is invisible to every
> standing rule that says *"grep the register before minting"* (**R-369**).
>
> **The cost, recorded so the rule can be narrowed later rather than becoming permanent by
> accident:** R-107 — *"no offsite action unpacks the named-volume tars Tier-3 captures"* — was
> enumerated on **2026-07-28**, given a number, written into `ROADMAP.md` and
> `07-backup-architecture.md`, and never entered here. **It was rediscovered from scratch 25 days
> later by an overnight drill that planted files and watched them not come back**, and shipped as
> R-354. The work was right the first time; only the filing was missing.
**Report which `OPEN-ITEMS.md` rows the task opened, closed or re-ranked** (§15). Every row carries
an owner — a row nobody owns is how items got lost in the first place.