Files
felhom.eu/documentation
admin 94ac6afbe8
gates / gates (push) Failing after 12m59s
audit: the preview's pre-flight, before/after shots, and two filed rows
PREFLIGHT.md - taste-skill §14 plus the Felhom additions, run in writing against
the DEPLOYED preview, Pass/Fail per line. Measured, not assumed:

  page height 1440: 10 922 -> 6 780 px (38% shorter)
  page height  390: 19 913 -> 10 865 px (45%, 23.6 -> 12.9 phone screens)
  initial load:     13 req / 308 KB -> 11 req / 260 KB   (same conditions)
  fully loaded:     16 req / ~540 KB -> 15 req / ~545 KB (ESSENTIALLY UNCHANGED -
                    the 93 KB portrait is paid for by dropping the 49 KB hero logo
                    and the 31 KB mono font; stated rather than spun)
  third-party hosts: 0 -> 0
  em dashes in our copy: 18 -> 0
  layout families: 8 for 11 sections (3 repeats) -> 10 for 10 (none)
  no horizontal scroll: clientWidth == scrollWidth at 390 and at 1440

Contrast: three NEW styles measured 3.88 / 3.14 / 3.57 on the first pass, all under
WCAG AA. Fixed to --text-2 and re-measured on the deployed file: 7.56 / 6.12 / 6.96.

A measurement that lied, recorded because it nearly shipped a false verdict: the
first helper reported .limits p at 1.17:1 by treating the translucent --warn-dim
as opaque. Compositing the whole ancestor stack gives the true 5.67:1, a pass. The
three real failures in the same run were real. An instrument that can report a
wrong number silently is not a measurement.

Two rows filed, both needing something this session may not do alone:
  R-930 (Business & legal, P3) the primary CTA is 4.01:1, under AA. MEASURED
        IDENTICAL ON THE LIVE PAGE, so pre-existing and site-wide, not a regression
        of this redesign. Three fixes offered, each touching brand, so it goes to
        the operator rather than being changed unilaterally.
  R-931 (Process & tooling, P4) felhom.eu serves NO compression at all - site.css
        goes over the wire as 94 310 raw bytes with no Content-Encoding even when
        gzip is offered. An nginx setting in manifests/, not a website change.
        Worth more than anything on this page.

Register: 127 -> 129 rows, 2 opened, 0 closed. register_shape_gate.py OK.
2026-10-10 22:12:47 +02:00
..

Felhom — Documentation

Felhom is a managed home-server service for Hungarian households, built on a three-component model over Proxmox:

  • Hub — operator backend on k3s (hub.felhom.eu). Repo: felhom.eu/hub/.
  • Host agent — one per Proxmox host; operator-tier; owns all Proxmox interaction. Repo: felhom-agent/.
  • In-guest controller — one per customer LXC; Docker-only; manages the customer's apps. Repo: felhom-controller/.

This directory is the central, code-verified documentation home for all three components plus the platform and the security-audit record.

Sections

Controller (in-guest) — controller/

The Docker-only app-domain controller. Full per-area docs grounded in current source (v0.59.0). → controller/README.md: module map, deploy & stack lifecycle, backup architecture, storage/monitoring/metrics, auth/hub/sync/integrations.

Where we stand — architecture/where-felhom-stands.*

The operator's one-page picture of what is proven, built, partial and missing.

The whole system on one page — architecture/felhom-system-poster.*

A poster for the operator: every machine, path, backup tier, time and key on a single sheet.

  • architecture/felhom-system-poster.html — the drawing. Made in Claude Design, NOT generated by anything in this repo, so do not expect a renderer; it is self-contained (fonts and scripts are inlined — it opens with no network)
  • architecture/felhom-system-poster.facts.md — the source of every fact on it. Change the facts here first. Rule: .claude/rules/unprompted-work.md §6. Gate: scripts/poster_facts_gate.py WARNS (never fails) when this file has a newer commit than the drawing

Host agent & platform — architecture/, proxmox-platform.md

The operator-tier agent and the Proxmox platform.

Hub (operator backend) — architecture/05

Security audits & remediation — audits/

Spike & test findings — tests/

Per-slice spike/validation findings (phases 0–5, slices 7–10). See tests/.

Conventions

  • Code-verified, not memory-derived. Architectural claims here are checked against the actual current source; if a claim can't be verified it is omitted and flagged, not guessed.
  • Per-repo operational working files (CLAUDE.md, CONTEXT.md, CHANGELOG.md, BUGHUNT.md, REPORT.md, TASK.md) live in their own repos — they are operational, not published docs.
  • Authoritative versions at last refresh: controller v0.59.0, agent v0.29.1, hub v0.11.0.