Files
felhom.eu/REPORT-the-28-2026-09-22.md
admin 186546d562
gates / gates (push) Successful in 27s
THE TWENTY-EIGHT: every app no drill had touched, walked in one night
All 28 walked on scratch guest 9202 against the private drill catalog. 26 deployed, 6 proven,
5 inconclusive, 14 with no upstream edge, 1 failed honestly (outline 1.9.1->1.10.1, HELD with the
right sentence), 2 undeployable - one (plant-it) by design, refused by the lifecycle gate, proven
live for the first time. Each app also got the half the update night skipped: a restore from its own
copy with the seed read back again - 21 restored, 2 correctly REFUSED per 07 6.2.

R-630 RAISED TO P1 by measurement: a stack with NO probe container does not skip verifying - it
waits out the full health timeout and HOLDS, stopping an app whose three containers read healthy.
The controller's own words: "not healthy within 5m0s (last: no probe container)".

R-633 opened: a remove sent during a restore reports success and leaves a container restarting with
a live public route. The product already refuses that clash for update and for restore, naming the
blocker; remove has no such guard.

R-634 opened: an app can be running, healthy and serving while recorded as deployed=false, and is
then unremovable. Reproducible alone on sparkyfitness; concurrency-linked on two others.

R-631 and R-632 CLOSED. Register 321 -> 323. Seven interventions, six of them my own harness -
named, with what each cost. No product code. The live catalog's image: lines are byte-identical to
the start of the night.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 16:00:56 +02:00

3.3 KiB

REPORT — THE TWENTY-EIGHT, 2026-09-22

The full record is documentation/audits/DRILL-the-28-2026-09-22.md. The shared REPORT.md is deliberately untouched (two sessions in this repo clobber it).

Not done, or changed from the brief

  1. Interventions: SEVEN, over the brief's limit of five — and six of the seven were my own harness, not the product. Three driver bugs fixed mid-run, two deliberate method changes, one deadlocked waiter. The seventh was the product's: three leftovers it could not clear.
  2. There is no requires: key in .felhom.yml. The constraints live under resources: (needs_hdd, pi_compatible), and 9202 met all of them — nothing was skipped for a resource reason.
  3. The brief's file-leg list is wrong. Read from 07 §6.2 as the brief itself instructs, only four of the 28 are class A: calibre-web, immich, komga, paperless-ngx. jellyfin, plex and emby are class B because their only bind is a :ro media mount.
  4. The brief's database list is incomplete — immich also carries PostgreSQL and redis, and wanderer carries meilisearch.
  5. plant-it cannot be installed at all, by design (lifecycle: abandoned), refused by the product's lifecycle gate — the only such template in the catalog, proven live for the first time.
  6. A REFUSED restore is recorded as its own verdict, not as a failure. The first version of the harness collapsed them and mislabelled calibre-web, where the product had done the right thing.
  7. Verified true by looking, not assumed: the drill repo's Actions are off (47 CI jobs before the first push, 47 after, all night); repoint_drill.py still works; 9202 had the capacity.

What ran

All 28 walked: deploy at the live pin → seed through the app's own front door → read back → backup → the guarded Update where a real within-a-major edge exists → restore and read back again → remove and a 60-second check. Plus both side jobs.

26 of 28 deployed · 6 proven · 5 inconclusive · 14 no upstream edge · 1 failed honestly · 2 could not deploy · 21 restored · 2 correctly refused a restore.

What shipped

  • felhom.eu — this report, the audit, the evidence, R-633 and R-634 opened, R-630 raised to P1 by measurement, R-631 and R-632 closed, 09 §6.4 leg F and §8.8, the capability map, the rotation file (28 lines rewritten + tandoor corrected), and STATUS.md.
  • app-catalog-felhom.eu — nothing. No fixture was ready to ship tonight and no template moved.
  • No controller, agent or hub code.

What is owed

  • R-630's fix: a container_name on paperless-ngx's webserver, or a verifying phase that treats "no probe target" as something other than a failure. Both are decisions, not clean-ups.
  • R-634's mechanism — runComposeDeploy's pin write was not read; the brief forbade product code.
  • Fixtures for 20 of the 28 that have no non-browser route yet, and a second look at kimai (its own user:create succeeded but user:list did not show the user) and jellyfin (the /Startup/User wizard route that worked for emby did not).
  • The six edges that reached done with no data proof — code-server, crafty-controller, komga, plex, rallly — need a fixture before they can be promoted.