R-438's document half. It records how an update works AS MEASURED, quotes the RestartStack comment that proves the restart half was CHOSEN (a design decision is not a defect), carries the three operator rulings of 2026-09-02, strikes the word 'rollback' (once a migration has run the old image will not start), states the target shape, and lists the seven slices with a status each. R-438 and R-440 amended and BOTH STAY OPEN: the mechanism is documented, not changed. Nothing closed, so CLOSED-ITEMS.md is untouched. Eight new register rows, 194 -> 202: R-446 (Naprakesz can be false for the 23 floating pins), R-447..R-451 (one per remaining slice, with a rank and an owner), R-452 (no gate enforces catalog_since - the runner fetches at --depth 1), and R-453 (the vaulted dashboard password is stale on BOTH demo boxes, which is what stopped the badge render from being validated live). Live evidence for slices 1 and 2 in documentation/tests/. The record is PROVEN LIVE through the boot reconciler on demo-hp - one entry per compose service, digests matching ground truth read independently. The badge RENDER is not, and the five attempts are listed rather than summarised.
4.0 KiB
REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02)
Overwritten each session. Nothing durable lives only here.
What this session changed in THIS repo
| file | change |
|---|---|
documentation/architecture/09-update-architecture.md |
CREATED — the deliverable. Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session. |
documentation/tests/VALIDATION-update-slice12-2026-09-02.md |
CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it. |
documentation/backlog/OPEN-ITEMS.md |
R-438 and R-440 amended (both stay OPEN); 8 new rows: R-446..R-453. |
documentation/backlog/ROADMAP.md |
the update arc added as one item, naming the capability-map rows it flips. |
documentation/architecture/00-capability-map.md |
one new row: what version a box runs, and whether it is behind. |
STATUS.md |
one new operator item (9) and a new lead paragraph. |
The architecture document — what it settles
- How an update works today, as measured —
UpdateStackispullthenup -d --remove-orphans; the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check; thirteen non-API call sites end incompose up -d. - What was chosen, and by whom —
RestartStack's own comment, quoted. A design decision is not a defect. What was never decided is what the syncer does underneath a deployed app. - The three operator rulings of 2026-09-02 — verified backup as a precondition; the support window runs on how far behind the CATALOG a box is; automatic within a major, never across one.
- The vocabulary ruling — "rollback" is struck. The available shapes are ABORT and RESTORE.
- The target shape — the live compose file becomes derived from a pin in
app.yaml. - The seven slices, each with a status line. 1 and 2 are shipped.
- Known limitations, including the floating-tag one.
Register
194 rows before, 202 after. Nothing closed, and that is stated rather than implied: R-438 and
R-440 are amended and stay OPEN — the mechanism is now documented, not changed — so nothing moved
to CLOSED-ITEMS.md and that file is untouched.
| row | what | state |
|---|---|---|
| R-446 | „Naprakész" can be FALSE for the 23 floating pins | OPEN, P2-MEDIUM, CC |
| R-447 | slice 3 — make the live compose DERIVED | BLOCKED on an operator ruling, P1-HIGH |
| R-448 | slice 4 — a guarded update (subsumes R-443) | READY, P2-MEDIUM |
| R-449 | slice 5 — an upgrade test that runs again | READY, P2-MEDIUM |
| R-450 | slice 6 — version sequence; an engine change gets its own edge | READY, P2-MEDIUM |
| R-451 | slice 7 — a fleet sweep (needs a hub change: no image field is reported) | READY, P3-LOW |
| R-452 | no gate enforces catalog_since (--depth 1 has no parent to diff) |
READY, P3-LOW |
| R-453 | the vaulted dashboard password is stale on BOTH demo boxes | WAITING-ON-OPERATOR, P2-MEDIUM |
Live validation
Full evidence: documentation/tests/VALIDATION-update-slice12-2026-09-02.md.
PROVEN LIVE on demo-hp at controller 0.233.0, through a real production caller (the boot
reconciler — no hand-set state): bentopdf recorded 1 service, bookstack recorded 2, keyed by
compose service name, all three digests matching ground truth read independently beforehand.
Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned.
NOT live-validated: the rendered badge. The vaulted dashboard password is stale on both demo controllers (R-453) and there is no operator route to a customer's password. Five attempts are listed in §4 of the validation file. The render is covered by tests that render the PRODUCTION templates.
Sibling repos
felhom-controllerv0.233.0 —8025304acc0a, deployed to demo-hp and verified healthy.app-catalog-felhom.eu—69761cf91bfc(backfill) +8220f8d(REPORT).