e994bf35d2
Documentation only — no code, no box, no build.
STATUS.md (repo root, 652 words / 67 lines): what works · what's broken ·
what we're working on · waiting on you · changed since. A VIEW of
OPEN-ITEMS.md, holding nothing of its own; not CONTEXT.md, and both files
now say why they stay separate. No R-n is the subject of a sentence —
identifiers are bracketed pointers only.
CONTEXT.md S-5 records the four operator decisions taken 2026-08-02
(D-a … D-d), none of them implemented:
D-a merge mp1 into mp0 rather than resize it — before any external
install, and D-c ships in the same step → R-165
D-b desired/observed app state in its own store, with the state-store
safety rule verbatim → R-166 (BLOCKED)
D-c customer fill warning + operator backup-failure alert → R-167
D-d only DooPlex and Peti's box are protected → target-selection.md
R-163 RE-FRAMED, not closed: the sizing question is withdrawn rather than
answered; the row survives as the record of the constraint until R-165
lands. R-156's papra referral RESOLVED — deployed nowhere, so the template
fix strands nothing; the docker ps evidence is recorded with its
provenance and its scope limit.
target-selection.md: two protected machines, everything else disposable.
ep0 is no longer Tier 2 but is not scratch (it holds the only off-premises
copy of real customer data) — flagged for explicit operator confirmation.
The demo-box backup-target fence drops from prohibition to stated cost,
because D-d spends that reference anyway.
CLAUDE.md gains an End-of-session checklist carrying the STATUS.md
maintenance rule and "a finding goes in OPEN-ITEMS.md first".
169 lines
11 KiB
Markdown
169 lines
11 KiB
Markdown
# REPORT — `STATUS.md` created, and the 2026-08-02 operator decisions recorded (2026-08-02)
|
|
|
|
**Overwritten** per the standing rule. The prior contents (hub v0.85.0 Network card + v0.86.0 Copy
|
|
without reveal, 2026-07-31) have their durable record in `hub/CHANGELOG.md` and
|
|
`documentation/audits/host-addresses-visible-2026-07-31.md`; nothing was lost by this overwrite.
|
|
|
|
**Class: documentation only.** No code, no template, no box, no build. Repo `felhom.eu` only —
|
|
`app-catalog-felhom.eu` was read for context and **not** modified. **No `CHANGELOG.md` entry exists
|
|
for this change and none is missing:** this repo has no root changelog, only per-area `hub/`,
|
|
`scripts/`, `website/` (`CLAUDE.md`), and this session touched none of those areas.
|
|
|
|
Baselines: `felhom.eu` @ `260a8f6`, `app-catalog-felhom.eu` @ `fd7747d`. Part 1 was derived by reading
|
|
the register's rows and both ranking sections, not from memory.
|
|
|
|
---
|
|
|
|
## 1. `STATUS.md` — the file
|
|
|
|
Root of `felhom.eu`, so it is the first thing visible. Sections in the specified order: what works ·
|
|
what's broken · what we're working on · waiting on you · changed since last update.
|
|
|
|
**Word count: 652 total, 581 excluding the header block** (`wc -w`; the header carries the
|
|
view-not-source, not-`CONTEXT.md` and maintenance rules, which the spec requires). **That is over the
|
|
~500 target and it is a deliberate miss, stated rather than hidden.** Five passes took it from 819 to
|
|
652. Getting under 500 needed either dropping a mandated item or dropping the off-site-credential line
|
|
— the register's **top-ranked** open item and the largest customer-data exposure on it. Cutting the
|
|
biggest data risk to save forty words is the wrong trade on a page whose job is to show the operator
|
|
what is at stake. It is 67 lines and fits a screen. **If the operator disagrees, the line to cut is
|
|
the R-95/R-87 one** and the page drops to ~545.
|
|
|
|
Content, in the operator's ranking: an app can stay off after a power cut, silently (R-157) · the
|
|
off-site copy can be erased by the box that wrote it, and has never been restored from (R-95, R-87) ·
|
|
three of fifty-three apps saved data where backups never looked (R-156) · 20 GB of backup space
|
|
against 50 GB of apps (R-163) · when that trips, one page says so and nothing alerts (R-158) · the
|
|
checker exists but a person has to remember it (R-161).
|
|
|
|
**Constraints honoured:** no `R-n` is the subject of any sentence — every identifier is a bracketed
|
|
pointer at the end of a line; no file paths, function names or version numbers appear; every broken
|
|
item is stated as what a customer or the operator would notice. Shipped, watching and
|
|
blocked-on-a-predicate rows (R-159, R-160, R-162, R-164) are absent by design.
|
|
|
|
**One deviation, flagged per standing rule 4.** "Waiting on you" is specified as *decisions only*, and
|
|
it carries one non-decision: **the hub password needs rotating** (R-132, owner Viktor). It is the only
|
|
thing on the register waiting on the operator with a live credential consequence, and omitting it from
|
|
the operator's own page to honour a section rule would be the letter over the point. It is labelled
|
|
*"a job, not a decision"* so the section's shape is not quietly eroded.
|
|
|
|
## 2. The decisions — where each one went
|
|
|
|
All four are in **`CONTEXT.md` as standing ruling S-5**, labelled **D-a … D-d** as in the discussion
|
|
and deliberately kept distinct from S-3's `D1…D6`. Open work is carried as backlog rows, per the
|
|
existing convention — no new home was created for either.
|
|
|
|
| Decision | Recorded | Work |
|
|
|---|---|---|
|
|
| **D-a** — merge the backup partition away (not resize) | `CONTEXT.md` S-5 | **R-165** (new) |
|
|
| **D-b** — desired/observed app state, own store | `CONTEXT.md` S-5 | **R-166** (new, `BLOCKED`) |
|
|
| **D-c** — storage monitoring + backup alerts | `CONTEXT.md` S-5 | **R-167** (new) |
|
|
| **D-d** — only DooPlex and Peti's box are protected | `CONTEXT.md` S-5 | `runbooks/target-selection.md`, this session — no row; the decision *is* the change |
|
|
| **Maintenance rule** (Part 3) | `STATUS.md` header **and** `CLAUDE.md` § End-of-session checklist | — |
|
|
|
|
Recorded verbatim inside D-b, because it is the decision's binding constraint: *losing the state store
|
|
must never cause an app to be deleted, restarted wrongly, or reported healthy when it is not — the
|
|
worst acceptable outcome is re-running a backup that already ran.* Its two "establish before speccing"
|
|
items are carried on R-166 as the reason that row is `BLOCKED` rather than `READY`.
|
|
|
|
**Deliverable 5 asks for "the five decisions".** Part 2 defines four (D-a … D-d); the fifth deliverable
|
|
line is the Part-3 maintenance rule, and it is in the table above. Nothing else in the task reads as a
|
|
fifth decision — flagged rather than invented.
|
|
|
|
**D-a's two conditions are recorded as conditions, not commentary:** it changes the disk layout so it
|
|
must land **before any external install**, and it removes a wall that currently fails safely so
|
|
**R-167 ships in the same step, never after**. R-165 restates both; R-167 names R-165 as the thing it
|
|
gates.
|
|
|
|
**None of D-a, D-b or D-c is implemented.** No controller, agent, installer or hub file was opened for
|
|
editing.
|
|
|
|
## 3. R-163 re-framed, and R-156's papra referral resolved
|
|
|
|
**R-163 is re-framed, not closed** — as instructed. State went `WAITING-ON-OPERATOR — the ratio is a
|
|
tier-sizing ruling` → `RE-FRAMED 2026-08-02 — open, no longer waiting on a ratio`; "Blocked on" went
|
|
from `the operator's sizing decision` to a pointer at R-165; owner `operator` → `CC`. The cell now says
|
|
the sizing **question is withdrawn rather than answered**, that the row survives as the record of the
|
|
constraint until the merge lands, and that the original finding follows unchanged. The intake ranking
|
|
(item 4) was updated with it, and records that **R-165 inherits R-163's rank and is the highest-ranked
|
|
item that must land before any external install**.
|
|
|
|
**R-156's papra referral is resolved.** The referral existed because moving a mount relocates live data
|
|
out from under a running app; with papra deployed nowhere there is nothing to strand, so the cheaper
|
|
leg — the template mounts `/app/app-data` — is takeable without waiting on upstream.
|
|
|
|
**The provenance is recorded with the claim, because it decides the row.** The evidence is
|
|
`docker ps -a` on **demo-hp's guest 9201** returning empty, **supplied with the task**; this session
|
|
**did not re-measure** — it is documentation-only and every box was fenced. The recorded scope is
|
|
honest about its edge: it covers the one guest papra was convicted on in Campaign 10, and **no other
|
|
customer's guest was enumerated**, so the row instructs the task that edits the template to re-check
|
|
first. Next action on the row is the catalog edit plus `catalog_gates.py`, explicitly not done here.
|
|
|
|
## 4. `target-selection.md` per D-d
|
|
|
|
The rule at the top is now D-d: **two protected machines, everything else disposable**, with the
|
|
correction stated as a correction — the earlier caution was costing sessions and pushing drills onto
|
|
DooPlex. The tier table's Tier 2 row is DooPlex + Peti's cluster "and, by D-d, nothing else".
|
|
|
|
**Two consequences the decision did not name, both handled visibly rather than silently:**
|
|
|
|
- **`ep0` + the Hetzner Storage Boxes.** D-d's protected list has two machines and ep0 is not one, so
|
|
the page no longer calls it Tier 2. It is **not** thereby scratch: it holds the PBS-DR datastore and
|
|
the restic copy of a real customer's data — the only off-premises copy that exists. Read the narrow
|
|
way (not protected, but not wipeable), using the page's own *fences-name-acts* rule, and **flagged
|
|
in the page for the operator to confirm explicitly.**
|
|
- **The shared "do not re-point either backup target" fence** on the two demo boxes was **downgraded
|
|
from a prohibition to a stated cost**, because D-d makes both boxes freely reinstallable, which
|
|
spends that reference configuration just as thoroughly — keeping the fence would have left the page
|
|
self-contradicting. The reason survives: know you are spending the regression reference, and put the
|
|
box back.
|
|
|
|
Also corrected while in the file: the *fences-name-acts* example cited the fence this edit removed, and
|
|
demo-hp's access line asserted "no baked SSH key" — which **R-129** records as measured false on
|
|
2026-07-31. It now points at R-129 instead of sending the next session to the hub vault for a
|
|
credential it may not need.
|
|
|
|
## 5. The maintenance rule
|
|
|
|
In two places, as specified: the `STATUS.md` header block, and a new **`## End-of-session checklist`**
|
|
in `CLAUDE.md` — which also gathers the couplings that were previously scattered (CHANGELOG + REPORT,
|
|
REUSE, the capability map's own end-of-session line, S-1's architecture coupling) and closes with *a
|
|
finding goes in `OPEN-ITEMS.md` first, never only in a report, an audit or `STATUS.md`*.
|
|
|
|
`CONTEXT.md` gained a header block stating why it and `STATUS.md` are separate — same subjects,
|
|
different readers, and `STATUS.md` holds nothing of its own. `STATUS.md` says the same from its side.
|
|
|
|
## 6. What could not be translated into plain language
|
|
|
|
Asked for explicitly, because an untranslatable row usually means the row itself is unclear.
|
|
|
|
- **R-29** — *"gates are enforced nowhere"*. The class is stateable ("we have checks nobody runs"), but
|
|
its instances are four differently-broken scripts across two repos with no shared consequence, so
|
|
every plain sentence either says nothing or misstates one instance. **R-161 is its readable
|
|
fragment**, which is why R-161 is on the page and R-29 is not.
|
|
- **R-123 / R-125** — process findings about how the register and how tests are written. Real, and they
|
|
belong on the register; there is no customer-visible symptom to lead with, so they have no honest
|
|
first sentence for this page. They are not "broken" in the operator's sense.
|
|
- **R-133 (the plaintext break-glass credential)** — translatable, and left off only for space. It is
|
|
the strongest candidate for the next update if something else closes.
|
|
- **R-115 vs R-110** — separate rows, one plain-language paragraph. Merged into a single "Waiting on
|
|
you" bullet carrying both pointers, because two adjacent bullets about publishing read as one item
|
|
the operator has already half-decided.
|
|
|
|
**A register defect found while reading, filed here because the fix is not mine to guess: `R-133` is
|
|
used TWICE** — `OPEN-ITEMS.md:80` (duplicate `domain` values accepted by the hub) and `:86` (the
|
|
plaintext break-glass credential). Two different findings, one ID, both `READY`. One needs renumbering,
|
|
and which one is the operator's call since both are cited from elsewhere (`CONTEXT.md` S-4 cites the
|
|
credential one).
|
|
|
|
## 7. Files changed
|
|
|
|
| File | Change |
|
|
|---|---|
|
|
| `STATUS.md` | **new** — the operator page |
|
|
| `CONTEXT.md` | S-5 (D-a … D-d); header note on the `STATUS.md` separation |
|
|
| `documentation/backlog/OPEN-ITEMS.md` | R-165/166/167 filed; R-163 re-framed (state, blocked-on, owner, ranking); R-156's referral resolved with its provenance |
|
|
| `documentation/runbooks/target-selection.md` | D-d rule; tier table; ep0; the demo-box fence; two stale lines |
|
|
| `CLAUDE.md` | new `## End-of-session checklist`, carrying the `STATUS.md` maintenance rule |
|
|
|
|
Nothing was built, deployed, published or touched on any host. Every claim about the register above is
|
|
a claim about pushed source in this repo at the commit below.
|