# A7 — a backup stores the image's NAME, not the image: how many of today's digests still resolve Measured 2026-09-26T08:15:42Z from DooPlex, read-only: `a7head.py` sends one registry **HEAD** per `ref@digest` (anonymous token; a HEAD is not a pull and does not count against Docker Hub's pull limit). **The fact.** A recovery unit records `image_pins` and — since v0.275.0 — each data file's running `ref@digest` (`data.files[*].images`); the manifest's own note says "image NOT stored — re-pulled on restore". So a restore of a version works only while the registry still serves that version. If a maker deletes an old tag or digest, a unit of that version cannot start, and v0.275.0's rule (a restore brings the data back at its own version) makes that dependency sharper: the restore asks for exactly the old version. **Today.** The catalog records digests only in its ladder entries (`update_ladder[].digest`): **42 distinct `ref@digest` pairs, all 42 answer 200** (`a7-result.txt`). Negative control: the same instrument answers **404** for an invented digest on Docker Hub and on ghcr.io (`a7-negative-control.txt`), so a 200 is not the instrument's only answer. The 66 compose image lines carry no digest in the catalog (the box adds one when it pins from a ladder entry); a tag can be re-pointed or deleted without any digest to check against, so this measures what is checkable, not the whole exposure. **Not measured:** the digests actually recorded on boxes (`installed_images`), which include versions older than any ladder entry; how often makers delete old versions (no history kept); the `from` side of ladder entries (no digest recorded there). **Options, not decided (filed as a row):** (a) keep as is — a restore of a deleted version fails with the pull error, and the household's route is the next copy or a newer version; (b) mirror every image a box has INSTALLED into the DooPlex registry (`gitea.dooplex.hu`) and let a restore fall back to the mirror — storage and bandwidth on DooPlex, and a new moving part on the recovery path; (c) mirror only the versions the ladder names (bounded by the catalog, not by the fleet) — does not cover a box on a pre-ladder version; (d) store the image in the unit (`docker save`) — hundreds of MB per app per copy, on every tier including off-site.