Files
felhom.eu/REPORT.md
T
admin 0705942783
gates / gates (push) Successful in 16s
the badge IS proven live, and the 'stale password' finding was mine, not the box's
I reported that the vaulted dashboard password no longer worked on either demo
box, and quoted the controller's own 'Failed login' as the discriminator. The
password was fine. ~/.config/credentials quotes its values with SINGLE quotes and
my sed stripped only double quotes, so the quote characters went out as part of
the password. The operator corrected it in one line; one retry returned 302.

The instrumentation lesson is the finding and R-453 now carries it: 'Failed login'
separates wrong-password from wrong-Host-header, and that is ALL it separates. It
cannot tell a wrong password from wrong password HANDLING, and I read it as if it
could. This is the second time this file's quoting has produced a confident wrong
verdict, so the fix is one shared extraction helper, not a resolution to be careful.

With the session recovered, the badge is validated on live pages: Naprakesz twice
on /stacks and on /apps/bookstack; NO badge at all on /apps/docmost (a deployed app
with no record - absent is UNKNOWN, not current); and 'Frissites elerheto - 52
napja' on both surfaces, the age being real arithmetic on bentopdf's catalog_since.
The behind state was staged by editing one compose tag, with no restart and no
up -d, and reverted byte-identically (sha256 equal, diff empty, container never
touched). Capability-map row upgraded to PROVEN-LIVE with the one unexercised
badge state named. STATUS item 9 now needs nothing from the operator.
2026-09-02 20:47:53 +02:00

4.7 KiB

REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02)

Overwritten each session. Nothing durable lives only here.

What this session changed in THIS repo

file change
documentation/architecture/09-update-architecture.md CREATED — the deliverable. Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session.
documentation/tests/VALIDATION-update-slice12-2026-09-02.md CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it.
documentation/backlog/OPEN-ITEMS.md R-438 and R-440 amended (both stay OPEN); 8 new rows: R-446..R-453.
documentation/backlog/ROADMAP.md the update arc added as one item, naming the capability-map rows it flips.
documentation/architecture/00-capability-map.md one new row: what version a box runs, and whether it is behind.
STATUS.md one new operator item (9) and a new lead paragraph.

The architecture document — what it settles

  1. How an update works today, as measured — UpdateStack is pull then up -d --remove-orphans; the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check; thirteen non-API call sites end in compose up -d.
  2. What was chosen, and by whom — RestartStack's own comment, quoted. A design decision is not a defect. What was never decided is what the syncer does underneath a deployed app.
  3. The three operator rulings of 2026-09-02 — verified backup as a precondition; the support window runs on how far behind the CATALOG a box is; automatic within a major, never across one.
  4. The vocabulary ruling — "rollback" is struck. The available shapes are ABORT and RESTORE.
  5. The target shape — the live compose file becomes derived from a pin in app.yaml.
  6. The seven slices, each with a status line. 1 and 2 are shipped.
  7. Known limitations, including the floating-tag one.

Register

194 rows before, 205 after. Nothing closed, and that is stated rather than implied: R-438 and R-440 are amended and stay OPEN — the mechanism is now documented, not changed — so nothing moved to CLOSED-ITEMS.md and that file is untouched.

row what state
R-446 „Naprakész" can be FALSE for the 23 floating pins OPEN, P2-MEDIUM, CC
R-447 slice 3 — make the live compose DERIVED BLOCKED on an operator ruling, P1-HIGH
R-448 slice 4 — a guarded update (subsumes R-443) READY, P2-MEDIUM
R-449 slice 5 — an upgrade test that runs again READY, P2-MEDIUM
R-450 slice 6 — version sequence; an engine change gets its own edge READY, P2-MEDIUM
R-451 slice 7 — a fleet sweep (needs a hub change: no image field is reported) READY, P3-LOW
R-452 no gate enforces catalog_since (--depth 1 has no parent to diff) READY, P3-LOW
R-453 CORRECTED — the password was fine; ~/.config/credentials uses SINGLE quotes and the strip was half-applied. The finding is the instrumentation lesson, not the typo READY, P3-LOW
R-454 five gofmt-unclean internal/web test files, and no gate notices READY, P3-LOW
R-455 DooPlex has no Docker Hub login — the ceiling now blocks BUILDS, not just gates WAITING-ON-OPERATOR, P2-MEDIUM
R-456 a partly-dead stack is not a boot orphan, and that rule is written down nowhere READY, P3-LOW

Live validation

Full evidence: documentation/tests/VALIDATION-update-slice12-2026-09-02.md.

PROVEN LIVE on demo-hp at controller 0.233.0, through a real production caller (the boot reconciler — no hand-set state): bentopdf recorded 1 service, bookstack recorded 2, keyed by compose service name, all three digests matching ground truth read independently beforehand. Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned.

The badge is ALSO proven live, on both surfaces and in three of its four states — including the load-bearing one: a deployed app with no record renders no badge at all. „Frissítés elérhető — 52 napja" was produced by editing bentopdf's compose tag only (no restart, no up -d) and reverted byte-identically. One correction of my own is stated in §4.0 of the validation file rather than buried: I first reported the vaulted password as stale on both boxes. It was not — I stripped only double quotes from a single-quoted value. The operator caught it in one line.

Sibling repos

  • felhom-controller v0.233.0 — 8025304acc0a, deployed to demo-hp and verified healthy.
  • app-catalog-felhom.eu — 69761cf91bfc (backfill) + 8220f8d (REPORT).