night 2026-09-13/14: first "be a customer" rotation (adventurelog) — 7 defects found, 13 rows closed
gates / gates (push) Successful in 18s
gates / gates (push) Successful in 18s
New runbooks/nightly-rotation.md; observations_gate.py reads every section (R-471); target-selection.md names real paths (R-461); R-93 carries the fact that drill-r50 is gone. Register: R-473/R-474/R-466/R-471/R-453/R-461 and v0.240.0's R-477/R-478/R-480/R-482/R-484/R-485/R-486 closed; R-481, R-483, R-487, R-488, R-489 opened. 09 §6.1, 07 §6, CONTEXT, STATUS note. Evidence: audits/nightly-2026-09-13-adventurelog/, audits/v0240-2026-09-13/.
This commit is contained in:
@@ -274,7 +274,10 @@ The tiers are **inputs to recovery**, not recovery routes. §7 and §8 say what
|
||||
v0.239.0, R-475): the first fresh copy in the order Tier 2, Tier 1, Tier 3; with none, it backs up
|
||||
first. Design: `09-update-architecture.md` §3 decision 8. **What a Tier-1 route back restores is only
|
||||
what the unit holds** — for an app whose data is a bind mount that is the definition, not the data
|
||||
(R-479).
|
||||
(R-479). **Removal and the tiers (controller v0.240.0):** removing an app with its backups KEPT keeps
|
||||
the unit, the Tier-2 mirror AND the Tier-2 record, so „Teljes visszaállítás" still works afterwards
|
||||
(R-486); „Mentési adatok törlése" deletes the unit, every mirror and the app's backup preferences, and
|
||||
never touches off-site snapshots (R-474). A removed app is listed on neither backup page (R-487, open).
|
||||
|
||||
### 6.1 The four tiers, as configured on the live fleet
|
||||
|
||||
|
||||
@@ -398,6 +398,15 @@ health wait, 53 s before the hold — and wrote the never-started definition int
|
||||
The Tier-2 mirror the hold names survived only because Tier 2 is daily. `backup.Manager.isHeld` now also
|
||||
answers true for an app a guarded update is moving (`SetUpdatingCheck`).
|
||||
|
||||
**v0.240.0 (2026-09-13, evening) — what the afternoon's proof and the first nightly rotation found, fixed.**
|
||||
Seven rows: removal with backups kept now keeps the Tier-2 RECORD, so the second-drive restore is not
|
||||
refused over an intact mirror (R-486, P1 — the disaster the second copy exists for); PostGIS/pgvector/
|
||||
TimescaleDB images are Postgres, so such apps get their logical dump (R-484); "delete backups" deletes
|
||||
the unit, the mirror(s) and the prefs (R-474/R-466); the backup card sizes them (R-485); a held
|
||||
update's sentence leaves the card with the hold (R-480); the Tier-3 lookup is one `snapshots` call
|
||||
(R-477); a unit older than the app's `deployed_at` does not count (R-478). Delivered by the floor in
|
||||
16 s / 18 s; every row proven live with a throwaway adventurelog. `audits/v0240-2026-09-13/`.
|
||||
|
||||
**Proven live on demo-hp, 2026-09-13**, with a throwaway uptime-kuma and real catalog tag changes (each
|
||||
reverted in the same phase): A (2.3.2→2.4.0, done after health), B (`backup_max_age: 2m` → backup first),
|
||||
E (non-existent tag → pin back, container untouched), F (`alpine:3.20` → held), H (three buttons and the
|
||||
|
||||
Reference in New Issue
Block a user