6035dfcc3a
gates / gates (push) Successful in 17s
R-438's document half. It records how an update works AS MEASURED, quotes the RestartStack comment that proves the restart half was CHOSEN (a design decision is not a defect), carries the three operator rulings of 2026-09-02, strikes the word 'rollback' (once a migration has run the old image will not start), states the target shape, and lists the seven slices with a status each. R-438 and R-440 amended and BOTH STAY OPEN: the mechanism is documented, not changed. Nothing closed, so CLOSED-ITEMS.md is untouched. Eight new register rows, 194 -> 202: R-446 (Naprakesz can be false for the 23 floating pins), R-447..R-451 (one per remaining slice, with a rank and an owner), R-452 (no gate enforces catalog_since - the runner fetches at --depth 1), and R-453 (the vaulted dashboard password is stale on BOTH demo boxes, which is what stopped the badge render from being validated live). Live evidence for slices 1 and 2 in documentation/tests/. The record is PROVEN LIVE through the boot reconciler on demo-hp - one entry per compose service, digests matching ground truth read independently. The badge RENDER is not, and the five attempts are listed rather than summarised.
64 lines
4.0 KiB
Markdown
64 lines
4.0 KiB
Markdown
# REPORT — update arc slices 1 & 2: documents, register, roadmap, capability map (2026-09-02)
|
|
|
|
*Overwritten each session. Nothing durable lives only here.*
|
|
|
|
## What this session changed in THIS repo
|
|
|
|
| file | change |
|
|
|---|---|
|
|
| **`documentation/architecture/09-update-architecture.md`** | **CREATED — the deliverable.** Its absence was R-438. A LIVING document: every slice of this arc updates it in the same session. |
|
|
| `documentation/tests/VALIDATION-update-slice12-2026-09-02.md` | CREATED — the live evidence, copied off demo-hp at the end of the phase that produced it. |
|
|
| `documentation/backlog/OPEN-ITEMS.md` | R-438 and R-440 amended (both stay OPEN); **8 new rows: R-446..R-453**. |
|
|
| `documentation/backlog/ROADMAP.md` | the update arc added as one item, naming the capability-map rows it flips. |
|
|
| `documentation/architecture/00-capability-map.md` | one new row: what version a box runs, and whether it is behind. |
|
|
| `STATUS.md` | one new operator item (9) and a new lead paragraph. |
|
|
|
|
## The architecture document — what it settles
|
|
|
|
1. **How an update works today, as measured** — `UpdateStack` is `pull` then `up -d --remove-orphans`;
|
|
the syncer overwrites a deployed app's compose on a 15-minute cycle with no deployed check;
|
|
**thirteen** non-API call sites end in `compose up -d`.
|
|
2. **What was chosen, and by whom** — `RestartStack`'s own comment, quoted. **A design decision is not
|
|
a defect.** What was never decided is what the syncer does underneath a deployed app.
|
|
3. **The three operator rulings of 2026-09-02** — verified backup as a precondition; the support window
|
|
runs on how far behind the CATALOG a box is; automatic within a major, never across one.
|
|
4. **The vocabulary ruling** — "rollback" is struck. The available shapes are ABORT and RESTORE.
|
|
5. **The target shape** — the live compose file becomes derived from a pin in `app.yaml`.
|
|
6. **The seven slices**, each with a status line. 1 and 2 are shipped.
|
|
7. **Known limitations**, including the floating-tag one.
|
|
|
|
## Register
|
|
|
|
**194 rows before, 202 after.** Nothing closed, and that is stated rather than implied: R-438 and
|
|
R-440 are **amended and stay OPEN** — the mechanism is now documented, not changed — so nothing moved
|
|
to `CLOSED-ITEMS.md` and that file is untouched.
|
|
|
|
| row | what | state |
|
|
|---|---|---|
|
|
| R-446 | „Naprakész" can be FALSE for the 23 floating pins | OPEN, P2-MEDIUM, CC |
|
|
| R-447 | slice 3 — make the live compose DERIVED | **BLOCKED** on an operator ruling, P1-HIGH |
|
|
| R-448 | slice 4 — a guarded update (subsumes R-443) | READY, P2-MEDIUM |
|
|
| R-449 | slice 5 — an upgrade test that runs again | READY, P2-MEDIUM |
|
|
| R-450 | slice 6 — version sequence; an engine change gets its own edge | READY, P2-MEDIUM |
|
|
| R-451 | slice 7 — a fleet sweep (needs a hub change: no image field is reported) | READY, P3-LOW |
|
|
| R-452 | no gate enforces `catalog_since` (`--depth 1` has no parent to diff) | READY, P3-LOW |
|
|
| R-453 | **the vaulted dashboard password is stale on BOTH demo boxes** | **WAITING-ON-OPERATOR**, P2-MEDIUM |
|
|
|
|
## Live validation
|
|
|
|
Full evidence: `documentation/tests/VALIDATION-update-slice12-2026-09-02.md`.
|
|
|
|
**PROVEN LIVE on demo-hp at controller 0.233.0**, through a real production caller (the boot
|
|
reconciler — no hand-set state): `bentopdf` recorded 1 service, `bookstack` recorded **2**, keyed by
|
|
compose service name, **all three digests matching ground truth read independently beforehand**.
|
|
Encrypted secrets byte-identical across the write. Both apps up and healthy; nothing provisioned.
|
|
|
|
**NOT live-validated: the rendered badge.** The vaulted dashboard password is stale on both demo
|
|
controllers (R-453) and there is no operator route to a customer's password. Five attempts are listed
|
|
in §4 of the validation file. The render is covered by tests that render the PRODUCTION templates.
|
|
|
|
## Sibling repos
|
|
|
|
- `felhom-controller` **v0.233.0** — `8025304acc0a`, deployed to demo-hp and verified healthy.
|
|
- `app-catalog-felhom.eu` — `69761cf91bfc` (backfill) + `8220f8d` (REPORT).
|