I reported that the vaulted dashboard password no longer worked on either demo box, and quoted the controller's own 'Failed login' as the discriminator. The password was fine. ~/.config/credentials quotes its values with SINGLE quotes and my sed stripped only double quotes, so the quote characters went out as part of the password. The operator corrected it in one line; one retry returned 302. The instrumentation lesson is the finding and R-453 now carries it: 'Failed login' separates wrong-password from wrong-Host-header, and that is ALL it separates. It cannot tell a wrong password from wrong password HANDLING, and I read it as if it could. This is the second time this file's quoting has produced a confident wrong verdict, so the fix is one shared extraction helper, not a resolution to be careful. With the session recovered, the badge is validated on live pages: Naprakesz twice on /stacks and on /apps/bookstack; NO badge at all on /apps/docmost (a deployed app with no record - absent is UNKNOWN, not current); and 'Frissites elerheto - 52 napja' on both surfaces, the age being real arithmetic on bentopdf's catalog_since. The behind state was staged by editing one compose tag, with no restart and no up -d, and reverted byte-identically (sha256 equal, diff empty, container never touched). Capability-map row upgraded to PROVEN-LIVE with the one unexercised badge state named. STATUS item 9 now needs nothing from the operator.
4.7 KiB
REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02)
Overwritten each session. Nothing durable lives only here.
What this session changed in THIS repo
| file | change |
|---|---|
documentation/architecture/09-update-architecture.md |
CREATED — the deliverable. Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session. |
documentation/tests/VALIDATION-update-slice12-2026-09-02.md |
CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it. |
documentation/backlog/OPEN-ITEMS.md |
R-438 and R-440 amended (both stay OPEN); 8 new rows: R-446..R-453. |
documentation/backlog/ROADMAP.md |
the update arc added as one item, naming the capability-map rows it flips. |
documentation/architecture/00-capability-map.md |
one new row: what version a box runs, and whether it is behind. |
STATUS.md |
one new operator item (9) and a new lead paragraph. |
The architecture document — what it settles
- How an update works today, as measured —
UpdateStackispullthenup -d --remove-orphans; the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check; thirteen non-API call sites end incompose up -d. - What was chosen, and by whom —
RestartStack's own comment, quoted. A design decision is not a defect. What was never decided is what the syncer does underneath a deployed app. - The three operator rulings of 2026-09-02 — verified backup as a precondition; the support window runs on how far behind the CATALOG a box is; automatic within a major, never across one.
- The vocabulary ruling — "rollback" is struck. The available shapes are ABORT and RESTORE.
- The target shape — the live compose file becomes derived from a pin in
app.yaml. - The seven slices, each with a status line. 1 and 2 are shipped.
- Known limitations, including the floating-tag one.
Register
194 rows before, 205 after. Nothing closed, and that is stated rather than implied: R-438 and
R-440 are amended and stay OPEN — the mechanism is now documented, not changed — so nothing moved
to CLOSED-ITEMS.md and that file is untouched.
| row | what | state |
|---|---|---|
| R-446 | „Naprakész" can be FALSE for the 23 floating pins | OPEN, P2-MEDIUM, CC |
| R-447 | slice 3 — make the live compose DERIVED | BLOCKED on an operator ruling, P1-HIGH |
| R-448 | slice 4 — a guarded update (subsumes R-443) | READY, P2-MEDIUM |
| R-449 | slice 5 — an upgrade test that runs again | READY, P2-MEDIUM |
| R-450 | slice 6 — version sequence; an engine change gets its own edge | READY, P2-MEDIUM |
| R-451 | slice 7 — a fleet sweep (needs a hub change: no image field is reported) | READY, P3-LOW |
| R-452 | no gate enforces catalog_since (--depth 1 has no parent to diff) |
READY, P3-LOW |
| R-453 | CORRECTED — the password was fine; ~/.config/credentials uses SINGLE quotes and the strip was half-applied. The finding is the instrumentation lesson, not the typo |
READY, P3-LOW |
| R-454 | five gofmt-unclean internal/web test files, and no gate notices |
READY, P3-LOW |
| R-455 | DooPlex has no Docker Hub login — the ceiling now blocks BUILDS, not just gates | WAITING-ON-OPERATOR, P2-MEDIUM |
| R-456 | a partly-dead stack is not a boot orphan, and that rule is written down nowhere | READY, P3-LOW |
Live validation
Full evidence: documentation/tests/VALIDATION-update-slice12-2026-09-02.md.
PROVEN LIVE on demo-hp at controller 0.233.0, through a real production caller (the boot
reconciler — no hand-set state): bentopdf recorded 1 service, bookstack recorded 2, keyed by
compose service name, all three digests matching ground truth read independently beforehand.
Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned.
The badge is ALSO proven live, on both surfaces and in three of its four states — including the
load-bearing one: a deployed app with no record renders no badge at all. „Frissítés elérhető —
52 napja" was produced by editing bentopdf's compose tag only (no restart, no up -d) and reverted
byte-identically. One correction of my own is stated in §4.0 of the validation file rather than
buried: I first reported the vaulted password as stale on both boxes. It was not — I stripped only
double quotes from a single-quoted value. The operator caught it in one line.
Sibling repos
felhom-controllerv0.233.0 —8025304acc0a, deployed to demo-hp and verified healthy.app-catalog-felhom.eu—69761cf91bfc(backfill) +8220f8d(REPORT).