Files
felhom.eu/REPORT-the-28-2026-09-22.md
T
admin 186546d562
gates / gates (push) Successful in 27s
THE TWENTY-EIGHT: every app no drill had touched, walked in one night
All 28 walked on scratch guest 9202 against the private drill catalog. 26 deployed, 6 proven,
5 inconclusive, 14 with no upstream edge, 1 failed honestly (outline 1.9.1->1.10.1, HELD with the
right sentence), 2 undeployable - one (plant-it) by design, refused by the lifecycle gate, proven
live for the first time. Each app also got the half the update night skipped: a restore from its own
copy with the seed read back again - 21 restored, 2 correctly REFUSED per 07 6.2.

R-630 RAISED TO P1 by measurement: a stack with NO probe container does not skip verifying - it
waits out the full health timeout and HOLDS, stopping an app whose three containers read healthy.
The controller's own words: "not healthy within 5m0s (last: no probe container)".

R-633 opened: a remove sent during a restore reports success and leaves a container restarting with
a live public route. The product already refuses that clash for update and for restore, naming the
blocker; remove has no such guard.

R-634 opened: an app can be running, healthy and serving while recorded as deployed=false, and is
then unremovable. Reproducible alone on sparkyfitness; concurrency-linked on two others.

R-631 and R-632 CLOSED. Register 321 -> 323. Seven interventions, six of them my own harness -
named, with what each cost. No product code. The live catalog's image: lines are byte-identical to
the start of the night.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 16:00:56 +02:00

53 lines
3.3 KiB
Markdown

# REPORT — THE TWENTY-EIGHT, 2026-09-22
**The full record is `documentation/audits/DRILL-the-28-2026-09-22.md`.** The shared `REPORT.md` is
deliberately untouched (two sessions in this repo clobber it).
## Not done, or changed from the brief
1. **Interventions: SEVEN, over the brief's limit of five** — and six of the seven were my own
harness, not the product. Three driver bugs fixed mid-run, two deliberate method changes, one
deadlocked waiter. The seventh was the product's: three leftovers it could not clear.
2. **There is no `requires:` key in `.felhom.yml`.** The constraints live under `resources:`
(`needs_hdd`, `pi_compatible`), and 9202 met all of them — nothing was skipped for a resource
reason.
3. **The brief's file-leg list is wrong.** Read from `07` §6.2 as the brief itself instructs, only
four of the 28 are class A: `calibre-web`, `immich`, `komga`, `paperless-ngx`. `jellyfin`, `plex`
and `emby` are class B because their only bind is a `:ro` media mount.
4. **The brief's database list is incomplete** — `immich` also carries PostgreSQL and redis, and
`wanderer` carries meilisearch.
5. **`plant-it` cannot be installed at all, by design** (`lifecycle: abandoned`), refused by the
product's lifecycle gate — the only such template in the catalog, proven live for the first time.
6. **A REFUSED restore is recorded as its own verdict, not as a failure.** The first version of the
harness collapsed them and mislabelled `calibre-web`, where the product had done the right thing.
7. **Verified true by looking, not assumed:** the drill repo's Actions are off (**47 CI jobs before
the first push, 47 after, all night**); `repoint_drill.py` still works; 9202 had the capacity.
## What ran
All 28 walked: deploy at the live pin → seed through the app's own front door → read back → backup →
the guarded Update where a real within-a-major edge exists → **restore and read back again** → remove
and a 60-second check. Plus both side jobs.
**26 of 28 deployed · 6 proven · 5 inconclusive · 14 no upstream edge · 1 failed honestly ·
2 could not deploy · 21 restored · 2 correctly refused a restore.**
## What shipped
- `felhom.eu` — this report, the audit, the evidence, R-633 and R-634 opened, R-630 **raised to P1**
by measurement, R-631 and R-632 **closed**, `09` §6.4 leg F and §8.8, the capability map, the
rotation file (28 lines rewritten + tandoor corrected), and `STATUS.md`.
- `app-catalog-felhom.eu` — **nothing.** No fixture was ready to ship tonight and no template moved.
- **No controller, agent or hub code.**
## What is owed
- **R-630's fix**: a `container_name` on paperless-ngx's webserver, or a `verifying` phase that
treats "no probe target" as something other than a failure. Both are decisions, not clean-ups.
- **R-634's mechanism** — `runComposeDeploy`'s pin write was not read; the brief forbade product code.
- **Fixtures for 20 of the 28** that have no non-browser route yet, and a second look at `kimai`
(its own `user:create` succeeded but `user:list` did not show the user) and `jellyfin` (the
`/Startup/User` wizard route that worked for `emby` did not).
- **The six edges that reached `done` with no data proof** — `code-server`, `crafty-controller`,
`komga`, `plex`, `rallly` — need a fixture before they can be promoted.