# REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02) *Overwritten each session. Nothing durable lives only here.* ## What this session changed in THIS repo | file | change | |---|---| | **`documentation/architecture/09-update-architecture.md`** | **CREATED — the deliverable.** Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session. | | `documentation/tests/VALIDATION-update-slice12-2026-09-02.md` | CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it. | | `documentation/backlog/OPEN-ITEMS.md` | R-438 and R-440 amended (both stay OPEN); **8 new rows: R-446..R-453**. | | `documentation/backlog/ROADMAP.md` | the update arc added as one item, naming the capability-map rows it flips. | | `documentation/architecture/00-capability-map.md` | one new row: what version a box runs, and whether it is behind. | | `STATUS.md` | one new operator item (9) and a new lead paragraph. | ## The architecture document — what it settles 1. **How an update works today, as measured** — `UpdateStack` is `pull` then `up -d --remove-orphans`; the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check; **thirteen** non-API call sites end in `compose up -d`. 2. **What was chosen, and by whom** — `RestartStack`'s own comment, quoted. **A design decision is not a defect.** What was never decided is what the syncer does underneath a deployed app. 3. **The three operator rulings of 2026-09-02** — verified backup as a precondition; the support window runs on how far behind the CATALOG a box is; automatic within a major, never across one. 4. **The vocabulary ruling** — "rollback" is struck. The available shapes are ABORT and RESTORE. 5. **The target shape** — the live compose file becomes derived from a pin in `app.yaml`. 6. **The seven slices**, each with a status line. 1 and 2 are shipped. 7. **Known limitations**, including the floating-tag one. ## Register **194 rows before, 205 after.** Nothing closed, and that is stated rather than implied: R-438 and R-440 are **amended and stay OPEN** — the mechanism is now documented, not changed — so nothing moved to `CLOSED-ITEMS.md` and that file is untouched. | row | what | state | |---|---|---| | R-446 | „Naprakész" can be FALSE for the 23 floating pins | OPEN, P2-MEDIUM, CC | | R-447 | slice 3 — make the live compose DERIVED | **BLOCKED** on an operator ruling, P1-HIGH | | R-448 | slice 4 — a guarded update (subsumes R-443) | READY, P2-MEDIUM | | R-449 | slice 5 — an upgrade test that runs again | READY, P2-MEDIUM | | R-450 | slice 6 — version sequence; an engine change gets its own edge | READY, P2-MEDIUM | | R-451 | slice 7 — a fleet sweep (needs a hub change: no image field is reported) | READY, P3-LOW | | R-452 | no gate enforces `catalog_since` (`--depth 1` has no parent to diff) | READY, P3-LOW | | R-453 | **the vaulted dashboard password is stale on BOTH demo boxes** | **WAITING-ON-OPERATOR**, P2-MEDIUM | | R-454 | five `gofmt`-unclean `internal/web` test files, and no gate notices | READY, P3-LOW | | R-455 | **DooPlex has no Docker Hub login — the ceiling now blocks BUILDS, not just gates** | **WAITING-ON-OPERATOR**, P2-MEDIUM | | R-456 | a partly-dead stack is not a boot orphan, and that rule is written down nowhere | READY, P3-LOW | ## Live validation Full evidence: `documentation/tests/VALIDATION-update-slice12-2026-09-02.md`. **PROVEN LIVE on demo-hp at controller 0.233.0**, through a real production caller (the boot reconciler — no hand-set state): `bentopdf` recorded 1 service, `bookstack` recorded **2**, keyed by compose service name, **all three digests matching ground truth read independently beforehand**. Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned. **NOT live-validated: the rendered badge.** The vaulted dashboard password is stale on both demo controllers (R-453) and there is no operator route to a customer's password. Five attempts are listed in §4 of the validation file. The render is covered by tests that render the PRODUCTION templates. ## Sibling repos - `felhom-controller` **v0.233.0** — `8025304acc0a`, deployed to demo-hp and verified healthy. - `app-catalog-felhom.eu` — `69761cf91bfc` (backfill) + `8220f8d` (REPORT).