da20722e76
gates / gates (push) Successful in 27s
INTERIM CHECKPOINT — evidence off the machine at the end of the phase that produced it (R-320), not at the end of the session. Phases 2-5 follow in a later commit. Phase 0, all three mechanisms proven with their controls: - the fleet floor to 0.261.0 with its declared MinAgent — both demo boxes in 13 s, the hub logging `managed floor SERVED ... from declared (golden 0.258.0)`. - a PRIVATE DRILL CATALOG (admin/app-catalog-drill), so that broken, dummy, cross-repo and engine-major edges can be measured without the live catalog ever carrying one. Positive control quoted, and two negative controls: the live catalog's main and both real boxes' caches unchanged. - a throwaway image store on the scratch guest, which is what makes an UNATTENDED HOLD measurable at all: an edge that PASSES the within-a-major test and still fails. CompareImageRefs was proven to order host:port/ references by RUNNING it (4 positive cases + 1 negative control), not by reading it. Phase 1: real within-a-major upstream edges walked on guest 9202 through the product's own guarded Update, each app seeded and read back through its OWN front door (R-156), with a per-edge verdict record in 09's shape. `inconclusive` is never collapsed into `failed`. TWO INSTRUMENT FIXES, both in this repo's own evidence code: - 00-api-recipe.md said the app page is /app/<n>; it is /apps/<n>, and every call it described 404s. Corrected, with the session-expiry note that cost the same time. - unattended-caller.py's follow() read update_phase/updating off the API ENVELOPE, so both were always None and EVERY followed update ran to its 900 s timeout and was then recorded `timeout` and never-press-again. Fixed before B1 relied on it. R-623. No controller, agent or hub code was written. The live catalog carries no broken reference. Gates: repo_gates.py --fast — all 15 OK, exit 0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
21 lines
1.1 KiB
Bash
Executable File
21 lines
1.1 KiB
Bash
Executable File
#!/bin/bash
|
|
# Remove images BY NAME for apps that are no longer deployed. NEVER `docker image prune` and never
|
|
# `docker system prune`: a global cleanup on any Felhom host is forbidden, and the scratch guest is
|
|
# not an exception worth making. Every removal below names one exact reference and is skipped if any
|
|
# container still uses it.
|
|
cat <<'SCRIPT' | ssh -o ConnectTimeout=30 demo-hp 'cat > /tmp/rc.sh; pct push 9202 /tmp/rc.sh /tmp/rc.sh >/dev/null 2>&1; pct exec 9202 -- bash /tmp/rc.sh; rm -f /tmp/rc.sh' 2>/dev/null
|
|
set -u
|
|
echo "free before: $(df -h /var/lib/felhom | tail -1 | awk '{print $4}')"
|
|
INUSE=$(docker ps -a --format '{{.Image}}' | sort -u)
|
|
N=0
|
|
for i in $(docker images --format '{{.Repository}}:{{.Tag}}' | grep -v '<none>' | sort -u); do
|
|
case "$i" in
|
|
gitea.dooplex.hu/admin/felhom-controller:*|traefik:*|gtstef/filebrowser:*|registry:2|localhost:5000/drill/*) continue;;
|
|
esac
|
|
if echo "$INUSE" | grep -qxF "$i"; then continue; fi
|
|
if docker rmi "$i" >/dev/null 2>&1; then echo " removed $i"; N=$((N+1)); fi
|
|
done
|
|
echo "removed $N images BY NAME (no prune was run)"
|
|
echo "free after: $(df -h /var/lib/felhom | tail -1 | awk '{print $4}')"
|
|
SCRIPT
|