Files
felhom.eu/REPORT.md
T
admin 6035dfcc3a
gates / gates (push) Successful in 17s
09-update-architecture.md: the update path finally has a document, and it is a living one
R-438's document half. It records how an update works AS MEASURED, quotes the
RestartStack comment that proves the restart half was CHOSEN (a design decision
is not a defect), carries the three operator rulings of 2026-09-02, strikes the
word 'rollback' (once a migration has run the old image will not start), states
the target shape, and lists the seven slices with a status each.

R-438 and R-440 amended and BOTH STAY OPEN: the mechanism is documented, not
changed. Nothing closed, so CLOSED-ITEMS.md is untouched.

Eight new register rows, 194 -> 202: R-446 (Naprakesz can be false for the 23
floating pins), R-447..R-451 (one per remaining slice, with a rank and an owner),
R-452 (no gate enforces catalog_since - the runner fetches at --depth 1), and
R-453 (the vaulted dashboard password is stale on BOTH demo boxes, which is what
stopped the badge render from being validated live).

Live evidence for slices 1 and 2 in documentation/tests/. The record is PROVEN
LIVE through the boot reconciler on demo-hp - one entry per compose service,
digests matching ground truth read independently. The badge RENDER is not, and
the five attempts are listed rather than summarised.
2026-09-02 20:32:30 +02:00

4.0 KiB

REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02)

Overwritten each session. Nothing durable lives only here.

What this session changed in THIS repo

file change
documentation/architecture/09-update-architecture.md CREATED — the deliverable. Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session.
documentation/tests/VALIDATION-update-slice12-2026-09-02.md CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it.
documentation/backlog/OPEN-ITEMS.md R-438 and R-440 amended (both stay OPEN); 8 new rows: R-446..R-453.
documentation/backlog/ROADMAP.md the update arc added as one item, naming the capability-map rows it flips.
documentation/architecture/00-capability-map.md one new row: what version a box runs, and whether it is behind.
STATUS.md one new operator item (9) and a new lead paragraph.

The architecture document — what it settles

  1. How an update works today, as measured — UpdateStack is pull then up -d --remove-orphans; the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check; thirteen non-API call sites end in compose up -d.
  2. What was chosen, and by whom — RestartStack's own comment, quoted. A design decision is not a defect. What was never decided is what the syncer does underneath a deployed app.
  3. The three operator rulings of 2026-09-02 — verified backup as a precondition; the support window runs on how far behind the CATALOG a box is; automatic within a major, never across one.
  4. The vocabulary ruling — "rollback" is struck. The available shapes are ABORT and RESTORE.
  5. The target shape — the live compose file becomes derived from a pin in app.yaml.
  6. The seven slices, each with a status line. 1 and 2 are shipped.
  7. Known limitations, including the floating-tag one.

Register

194 rows before, 202 after. Nothing closed, and that is stated rather than implied: R-438 and R-440 are amended and stay OPEN — the mechanism is now documented, not changed — so nothing moved to CLOSED-ITEMS.md and that file is untouched.

row what state
R-446 „Naprakész" can be FALSE for the 23 floating pins OPEN, P2-MEDIUM, CC
R-447 slice 3 — make the live compose DERIVED BLOCKED on an operator ruling, P1-HIGH
R-448 slice 4 — a guarded update (subsumes R-443) READY, P2-MEDIUM
R-449 slice 5 — an upgrade test that runs again READY, P2-MEDIUM
R-450 slice 6 — version sequence; an engine change gets its own edge READY, P2-MEDIUM
R-451 slice 7 — a fleet sweep (needs a hub change: no image field is reported) READY, P3-LOW
R-452 no gate enforces catalog_since (--depth 1 has no parent to diff) READY, P3-LOW
R-453 the vaulted dashboard password is stale on BOTH demo boxes WAITING-ON-OPERATOR, P2-MEDIUM

Live validation

Full evidence: documentation/tests/VALIDATION-update-slice12-2026-09-02.md.

PROVEN LIVE on demo-hp at controller 0.233.0, through a real production caller (the boot reconciler — no hand-set state): bentopdf recorded 1 service, bookstack recorded 2, keyed by compose service name, all three digests matching ground truth read independently beforehand. Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned.

NOT live-validated: the rendered badge. The vaulted dashboard password is stale on both demo controllers (R-453) and there is no operator route to a customer's password. Five attempts are listed in §4 of the validation file. The render is covered by tests that render the PRODUCTION templates.

Sibling repos

  • felhom-controller v0.233.0 — 8025304acc0a, deployed to demo-hp and verified healthy.
  • app-catalog-felhom.eu — 69761cf91bfc (backfill) + 8220f8d (REPORT).