Evidence: the first full monthly re-test (decision 55) — nextcloud and sonarr re-tested and written; runbook: every app by default, the standing brief
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-01 07:54:22 +02:00
parent 8699dba53d
commit c12fd46f54
34 changed files with 3526 additions and 8 deletions
@@ -1,11 +1,16 @@
# RUNBOOK — the monthly re-test of same-name security fixes (`09` §3 decision 52, R-740)
# RUNBOOK — the monthly re-test of same-name security fixes (`09` §3 decisions 52, 54, 55; R-740, R-743)
**What it does.** An image such as `postgres:18-alpine` or `redis:7-alpine` gets security fixes under the SAME name.
A box takes such a fix at night only when the catalog has re-tested the tag at the new digest on both venues and written
it as a ladder step. This runbook is that re-test, once a month. **One command does the work**; the steps around it set
up the two venues and tear them down.
**Who runs it:** a person or a CC session, from DooPlex, once a month (the operator decides who presses — STATUS).
**Scope (decision 55):** every app with a proven ladder — not only the database and redis lines. The web apps face the
internet; the databases do not. `--engines-only` is the narrow switch, not the default.
**Who runs it (decision 54):** a CC session the operator starts once a month with the standing brief
`claude/MONTHLY-security-retest.md` (in the planning project), from DooPlex. STATUS carries "Monthly security re-test:
last run <date>, next due <date>" — update it at the end of every run.
**Why not a cron job (measured 2026-09-30):** it needs a fresh bench LXC on demo-hp, scratch guest 9202 pointed at the
drill catalog, a drill reset (a force-push — the permission check refused it once and the operator allowed it), and pushes
to the LIVE catalog. None of that should happen with nobody watching.
@@ -14,16 +19,16 @@ to the LIVE catalog. None of that should happen with nobody watching.
```bash
cd /mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu && git pull -q
python3 scripts/retest-floating.py --dry-run --engines-only # the ruled start: database and redis lines
python3 scripts/retest-floating.py --dry-run # everything, for the record
python3 scripts/retest-floating.py --dry-run # every app with a proven ladder (decision 55)
```
`nothing to re-test today` ends the month. Otherwise go on.
## 2. The bench (LXC 9401 on demo-hp)
The recipe in `audits/more-night-apps-2026-09-30/bench/B1-bench-create.txt` (60 GB disk — 40 GB filled up on 2026-09-30),
swap 0 (the stricter venue, R-733). `retest-floating.py` syncs the catalog's scripts and templates to it itself.
The recipe in `audits/rulings-2026-10-01/A/A1-bench-create.txt` (60 GB disk on `nvme-scratch` — 40 GB filled up on
2026-09-30), swap 0 (the stricter venue, R-733); `pveam download` the Debian 13 template first if it is gone.
`retest-floating.py` syncs the catalog's scripts and templates to it itself (it checks only docker + python3 first, R-749).
## 3. The box (scratch guest 9202)
@@ -36,14 +41,19 @@ swap 0 (the stricter venue, R-733). `retest-floating.py` syncs the catalog's scr
## 4. The run
```bash
python3 scripts/retest-floating.py --engines-only --push \
python3 scripts/retest-floating.py --push \
--evidence $SC/evidence --evidence-rel felhom.eu/documentation/audits/retest-<YYYY-MM>
```
Per app: bench (the full method, 10-minute memory watch), box (fresh install at the OLD tested digest, seed, the re-test
entry in the drill, the guarded Update, read-back, the running digest must be the NEW one), then the writer, the catalog
gates and one commit (pushed with `--push`; the pre-push gates run). A failure stops that app and never the list; the
summary names each app DONE or STOPPED with its reason. Copy `$SC/evidence` to `felhom.eu/documentation/audits/retest-<YYYY-MM>/`.
summary names each app DONE or STOPPED with its reason. Order: database/redis lines first, then the rest alphabetically
(nextcloud — internet-facing, holds data — comes before the linuxserver apps). Copy `$SC/evidence/<date>/*` to
`felhom.eu/documentation/audits/retest-<YYYY-MM>/` (the ladder entries cite `retest-<YYYY-MM>/<app>/{bench,box}`).
**Monthly cost (measured 2026-10-01):** see "What it cost" below. linuxserver images (bookstack, radarr, sonarr,
code-server) are rebuilt upstream weekly under the same tag, so most months they come up.
## 5. Teardown (three layers, stated)