ops: fleet floor raised to 0.255.0 — and it delivered on its own
gates / gates (push) Successful in 23s

POST /configuration/global-floor with min_controller_version=0.255.0 and the
declared min_agent=0.131.0 (R-472); 303 flash=floor_set, read back from the
form, not from the POST.

The proof is the N100: it was never hand-deployed and its own Docker reports
felhom-controller:0.255.0 healthy within five minutes of the save. Three boxes
remain below — all BLOCKED or DOWN, which is a floor being held, not a floor
failing; each takes it on its next check-in.

R-580 filed: curl's %{redirect_url} rebuilds the request URL WITH the --netrc
credentials in it, so the hub password was printed into the session's own
output. Nothing written to a file, nothing committed. The build-deploy skill
now carries the rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-18 15:37:15 +02:00
parent 4df2cd5174
commit 20aafc3dec
4 changed files with 67 additions and 5 deletions
@@ -0,0 +1,49 @@
# Fleet floor raised to 0.255.0 — 2026-09-18
**Method: endpoint-level.** The operator UI's own form, driven with Basic auth against the hub's
ClusterIP. No hand-deploy around the floor (R-472).
```
before : min_controller_version = 0.254.0, declared MinAgent 0.131.0
impact : POST /configuration/global-floor/impact?v=0.255.0 -> {"below":4}
save : POST /configuration/global-floor
min_controller_version=0.255.0 min_agent=0.131.0
-> 303 /configuration?flash=floor_set
after : min_controller_version = 0.255.0 (re-read from the form, not from the POST)
```
## It delivered — the positive observable
The N100 was NOT hand-deployed. It self-updated from the floor alone, and its own Docker says so:
```
demo-felhom guest 9201 : felhom-controller:0.255.0 Up 5 minutes (healthy)
demo-hp guest 9201 : felhom-controller:0.255.0 Up 26 minutes (healthy) [hand-deployed earlier]
```
The hub's config table agrees, from each box's own report:
| customer | status | version | floor |
|---|---|---|---|
| demo-felhom | OK | **0.255.0** | v0.255.0 |
| demo-hp | OK | **0.255.0** | v0.243.0 (per-customer override) |
| drill-r50 | BLOCKED | 0.213.0 | v0.255.0 ● held |
| peti-felhom | DOWN | 0.115.0 | v0.255.0 ● held |
| tester-1 | DOWN | 0.245.0 | v0.255.0 ● held |
## Three boxes are still below, and that is the floor working, not failing
`below` went 4 -> 3 and stopped. The three are BLOCKED or DOWN: a floor is delivered on a box's
next check-in, and a box that never checks in never receives it. **`below: 3` is therefore not a
delivery failure** — it is the count of machines that have not reported since the save. Each will
take 0.255.0 on its next report. The one that WAS reachable took it in under five minutes.
**demo-hp's own floor is a per-customer override at v0.243.0**, so the global save does not move it;
it is on 0.255.0 because this session deployed it by hand. Counting it as proof of delivery would be
the mistake — the N100 is the proof.
## A finding, filed: the hub password was printed back by curl
`curl -w '%{redirect_url}'` re-injects the credentials into the URL it prints, so the hub password
appeared in this session's own output. Nothing was written to a file and nothing was committed.
Filed as **R-580**. Never pair `%{redirect_url}` with `--netrc`/`-u`; print `%{http_code}` alone.