Part 0 and Part A of the home-page redesign. Nothing under website/ is touched.
skills/
- design-taste-frontend installed to ~/.claude/skills/ as a VERBATIM copy of
github.com/Leonxlnx/taste-skill @ 717446e07a (2026-10-09, MIT). Body verified
byte-identical line by line; the only addition is a provenance block. The repo
holds scripts (skill.sh, scripts/*.mjs) but the SKILL FOLDER holds only SKILL.md,
so no script was copied and none was run. Not installed via npx or skill.sh.
- skills/felhom-web-design/SKILL.md is the override layer and names every conflict:
the static-HTML stack fence (no React/Tailwind/Motion/npm), nothing fetched from
another server (kills taste-skill's picsum/Unsplash/SimpleIcons ladder and its
npm icon libraries, since we have a self-hosted sprite), real images only, the
Hungarian gondolatjel surviving the en-dash ban, the claim rule, and the SEO-keep
list. 137 lines, check_skills.py PASS.
- SOURCES.md records the provenance and the kept/overridden table.
documentation/audits/redesign-2026-10-10/AUDIT.md
Measured against the LIVE site, not the file. 12 patterns to retire (R1-R12), each
naming the taste-skill rule it breaks; 7 to keep; dial reading 3/2/4 -> 6/3/4;
8 levers in priority order for the operator to approve at STOP 1.
Headline measurements: 10 922 px tall at 1440 and 19 913 px at 390 (23.6 phone
screens); 11 sections but only 8 layout families, why-grid used 3x and
apps-showcase 2x; 18 em dashes; 16 requests / 533 KB from exactly two hosts.
Contrast measures 7.56:1 body and 16.67:1 headings - AAA, and an accessibility win
to preserve rather than a thing to fix.
Method note: resize_window does not move window.innerWidth on this workstation and
DevTools device mode could not be driven, so the page was rendered in a same-origin
iframe at each width. Faithful, with two positive observables: the hamburger
computes to display:block at 390, and clientWidth == scrollWidth == 375.
Gates: site, hostinstall, hub-confirm, register and the rest green. instructions and
script-tests fail on this Windows workstation for environment reasons that predate
this change (E:\git\CLAUDE.md is the deliberate Windows adaptation the gate wants
identical; fcntl missing; relpath across C:/E:; the cp1250 console trap). Re-run on
DooPlex follows.
POST /configuration/global-floor with min_controller_version=0.255.0 and the
declared min_agent=0.131.0 (R-472); 303 flash=floor_set, read back from the
form, not from the POST.
The proof is the N100: it was never hand-deployed and its own Docker reports
felhom-controller:0.255.0 healthy within five minutes of the save. Three boxes
remain below — all BLOCKED or DOWN, which is a floor being held, not a floor
failing; each takes it on its next check-in.
R-580 filed: curl's %{redirect_url} rebuilds the request URL WITH the --netrc
credentials in it, so the hub password was printed into the session's own
output. Nothing written to a file, nothing committed. The build-deploy skill
now carries the rule.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The four existing skills cover the product; nothing covered how work is
reported. Two rules this project has paid for — check the artifact rather
than the report, and do not state a claim more firmly than the evidence
allows — lived only in the operator's head and in chat, where Claude Code
never read them.
- felhom-evidence five confidence tiers, artifact-over-report
- felhom-diagnosis no hypothesis until a command has been seen red
- felhom-plain-language ASD-STE100, two options, the re-pitch
- felhom-handoff the note goes to a FILE, not the conversation
- felhom-doc-authoring the pointer decides whether material is reached
scripts/check_skills.py asserts what decides whether a skill is EVER
reached: frontmatter parses, name == directory, description and body
non-empty, under 150 lines, installed copy still samefile()s into the
repo. install_skills.py globs and never reads the file, so a missing
description installs perfectly and then silently never loads.
It convicted on its first run: felhom-build-deploy is 179 lines. NOT
trimmed here (pre-existing skills are out of scope, and trimming a
deploy skill without exercising its commands is how a wrong command
reaches a live host) — a named single-entry GRANDFATHERED exception,
WARNed every run, R-394. A new skill over the limit is convicted.
Red-proof run and seen failing: description removed from
felhom-evidence -> exit 1, "frontmatter field 'description' is missing
or empty". Restored, tree clean.
skills/SOURCES.md records both MIT upstreams, that these are adaptations
not copies, and the six pieces deliberately EXCLUDED with reasons.
Register: R-392 (no architecture doc covers the two-AI workflow),
R-393 (decision-log skill deferred, with the reason), R-394.
New shared scripts/instructions_gate.py, registered in controller_gates.py and
agent_gates.py, never copied into a sibling repo (the reuse_refs_check.py
precedent). 20 fixture tests, all asserting the effect: exit code AND that the
message names the file and the reason.
It is a consistency gate, not a budget gate, and the failure message says so. A
/context reading measured the instruction files at 15k tokens against 869k free in
a 1M window -- space is not the constraint, and a future reader must not re-derive
the wrong reason. The 200-line ceiling is adherence guidance; a file nobody can
hold in their head is where contradictions hide, and five were found here.
Checks run against effective text (HTML comments stripped, because they are
stripped before injection): the line ceiling; every .claude/rules/*.md declares
paths: or an explicit unconditional: true; no component version literal; no
TEMPORARY block carrying a past date; and the workspace-root CLAUDE.md is
byte-identical to its versioned copy -- the live file sits outside any git repo,
so that copy is its only version-controlled record.
Two traps recorded so they are not reintroduced: a bare \d+\.\d+\.\d+ matches the
first three octets of every IPv4 (the gate excludes dotted quads, or it fails on
192.168.0.180 in the agent's own file); and unconditional: true is NOT a Claude
Code feature but this project's own marker.
Workspace-root CLAUDE.md 208 -> 182 lines (142 effective), copy kept identical.
The nine-instance invariant table moved into the felhom-testing skill, which
triggers when writing or reviewing a test; all three directive bullets stayed in
the core. felhom.eu/CLAUDE.md got surgical corrections only and is knowingly still
over the ceiling at 227 effective lines -- closing it needs the restructure R-229
defers, said plainly rather than quietly absorbed.
CONTEXT.md gains standing ruling S-35. OPEN-ITEMS.md gains R-229.
Docs only -- no Go, no version bump, nothing built or deployed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJc8sAGRWmavP3rMtdpkr2
The skill's own description claimed 'ANY Felhom artifact' and 'publish', and had no ISO section —
a description asserting coverage that did not exist. Description corrected and a section added.
POINTERS, NOT COPIES. The 13-criterion release gate stays in
documentation/runbooks/iso-release-gate.md and the measurements stay in the four spike audits;
duplicating them into a skill guarantees drift (the R-94/R-128 class). What the skill adds is the
ROUTING that was missing: nothing told anyone the gate exists, which is R-29's exact shape.
Records the two modes (--release public vs --pairing appliance) because picking the wrong one ships
the wrong product, the build and publish commands (rclone env-only, so no credential file is ever
written), and the round-trip verification.
The traps it carries existed only in commit messages until now, and each cost a wrong diagnosis:
- 'qm set --scsi0 ... --boot order=' in ONE call silently yields boot: order=net0;ide2
- after install the CD must be detached, or a COMPLETED install looks exactly like a stuck one
- verify focus by screendump before every Enter (GTK Enter lands in fields, not Next)
- proof installs register appliances; the verb is POST /appliances/<id>/discard, not /delete
- scratch storage at the /mnt/nvme-1tb ROOT (a subdirectory reads disconnected forever)
Also flags that the ISO gate is NOT wired into repo_gates.py, so nothing reminds you to run it.
Docs only. python3 scripts/repo_gates.py --fast: all gates OK (rc=0).
PROMPT-TEMPLATE: standard 'For the operator' plain-language section, mandatory
for M+ tasks and anything with a STOP.
ROADMAP rulings (operator, 2026-07-21): R-25b full-teardown cascade with three
acks + typed name (M-sized, spec to follow, no longer blocks R-3); R-11 channel
= direct Messenger, doc is the architect's; R-42 option (a), sidecars follow the
app; R-17 delete the archive - spike-lite found NO tooling verb targets it, so
it is an operator console action; R-4 complete (freemail.hu verified).
R-55 + R-41 slice 1 marked shipped; new R-56 (app difficulty classification -
the constructive half of the glance ruling).
scripts/build-hub.sh v1.23.0: the hub build script was outside any repo. Adopted
verbatim + versioned; the build-dir path is now a symlink to it.
felhom-testing skill: the ~1/5 recovery-code 'known flake' is retired - it was a
real defect the test was correctly detecting.
felhom-pve joins the tailnet as a host package (100.70.170.35, expiry
disabled); DooPlex already advertised 192.168.0.0/24 via its GitOps k3s
tailscale pod (100.107.87.53). ssh felhom-pve now targets the tailnet IP
(direct-over-LAN at home, tunnel when away); felhom-pve-lan = LAN fallback.
--accept-dns=false on the host. Host converted static->DHCP (reservation
keeps .162 at home). Measured: --accept-routes hairpins the local subnet
at home -> travel-only opt-in. PBS is offsite (own WireGuard tunnel), needs
none of this. Recorded not fixed: controller<->agent plane hard-pinned to
192.168.0.162 (agent listen_addr + guest bootstrap.json) -> not yet portable
off-LAN. No code changed. Full doc: documentation/operations/tailscale.md
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMForrE4c1wZxd9LukxYVt