docs: rulings 7 and 8 shipped and proven live (R-470/R-472/R-475 CLOSED); R-477..R-480 opened
gates / gates (push) Successful in 21s
gates / gates (push) Successful in 21s
Hub v0.112.0 serves a floor above the golden with a declared MinAgent;
controller v0.239.0 reached both demo boxes by that floor in 14 s and 15 s
and updates on any backup tier. 09 §3 decisions 7 and 8, §6/§6.1; 07 §6
line; capability map row; STATUS items 15/16 done and the cadence line
corrected; CONTEXT; register: R-470/R-472/R-475 compressed to CLOSED-ITEMS
(full text at 2f5d3af), R-477..R-480 opened, R-474 reproduced a third
time. OPEN-ITEMS 431689 -> 432156 bytes, CLOSED-ITEMS 118051 -> 120598.
Evidence: documentation/audits/rulings-r472-r475-2026-09-13/.
This commit is contained in:
@@ -270,6 +270,12 @@ Recorded here so the encryption policy is not read as covering it. → **R-108**
|
||||
|
||||
The tiers are **inputs to recovery**, not recovery routes. §7 and §8 say what they can actually do.
|
||||
|
||||
**The app update's safety precondition accepts ANY tier** (operator ruling 2026-09-13, controller
|
||||
v0.239.0, R-475): the first fresh copy in the order Tier 2, Tier 1, Tier 3; with none, it backs up
|
||||
first. Design: `09-update-architecture.md` §3 decision 8. **What a Tier-1 route back restores is only
|
||||
what the unit holds** — for an app whose data is a bind mount that is the definition, not the data
|
||||
(R-479).
|
||||
|
||||
### 6.1 The four tiers, as configured on the live fleet
|
||||
|
||||
| Tier | Location | Captures | Cadence (LIVE) | Retention (LIVE) | Encrypted |
|
||||
|
||||
Reference in New Issue
Block a user