evening: rules file in place; R-483 CLOSED (catalog, operator-confirmed); R-479 CLOSED (controller v0.241.0, proven live); R-481 blocked on the one-host-one-customer model; R-491 filed
gates / gates (push) Successful in 18s

This commit is contained in:
2026-09-13 21:57:47 +02:00
parent 550fd84754
commit 72ee053a9e
12 changed files with 312 additions and 37 deletions
@@ -277,7 +277,7 @@ what the unit holds** — for an app whose data is a bind mount that is the defi
(R-479). **Removal and the tiers (controller v0.240.0):** removing an app with its backups KEPT keeps
the unit, the Tier-2 mirror AND the Tier-2 record, so „Teljes visszaállítás" still works afterwards
(R-486); „Mentési adatok törlése" deletes the unit, every mirror and the app's backup preferences, and
never touches off-site snapshots (R-474). A removed app is listed on neither backup page (R-487, open).
never touches off-site snapshots (R-474). A removed app is listed on neither backup page (R-487, open). **For a bind-data app the update's tier order is second drive → off-site → own unit (R-479, v0.241.0), because the unit does not hold the files.**
### 6.1 The four tiers, as configured on the live fleet
@@ -178,6 +178,14 @@ These are rulings, not proposals. Anything specced against a different assumptio
`audits/rulings-r472-r475-2026-09-13/` 04 (nothing anywhere → backup first), 05 (Tier 1 alone),
07 (a failed update held naming „saját meghajtó"), 08 (restored from „helyi", hold cleared).
9. **A bind-data app's route back is off-site before its own unit, and the hold says what the copy
holds** (R-479, controller v0.241.0). An app whose data is bind-mounted files has a recovery unit
that holds the definition and the database dumps and NOT the files (measured: gokapi restored from
„helyi" came back with settings and no data). For such an app the update walks second drive →
off-site → own unit; for an app whose data is in named volumes the v0.239.0 order (second drive →
own unit → off-site) stands. Either way the hold sentence ends with what the named copy holds, so a
customer is never sent to a copy that cannot bring the data back without being told so.
## 4. The vocabulary ruling — "rollback" is struck
**App data CANNOT be rolled back.** Measured on Nextcloud (spike §7): once a migration has actually