ba7174012a
gates / gates (push) Successful in 4m28s
Operator refinements after looking at the rebuilt pictures. No geometry changed: R-919's measured constants, its band and every check stand, and the red-proof still convicts the old layout. Profile picture: the logo MARK only. The mark plus the "felhom.eu" lettering was too much for the 176 px Facebook shows -- and smaller than the shape the Page carried before this work, because build.py shrinks the artwork to fit inside the circle where the original was simply cropped by it. Dropping the lettering grows the mark from 69% to 76% of the circle; canvas 932 -> 648 and the profile_width floor 720 -> 640 (twice Meta's recommended 320 source; 720 was above what the mark alone needs and would have shrunk it for nothing). logo.png is split at a MEASURED row: ink y 5-289, blank band y 290-295, wordmark y 296-403. Covers: the headline is now set the way the WEBSITE sets its h1. site.css .page-index .hero-text h1 is font-weight 700, letter-spacing -0.03em; this file used ExtraBold 800 with no tracking, so the cover did not actually match the page. HEADLINE_WEIGHT/HEADLINE_TRACK now carry those, with real per-glyph spacing. Bold is narrower so headlines grew: A 57->62, B 58->63, C 47->50. "felhom.eu" is no longer typed anywhere: wordmark() draws the logo's own lettering, which is set in "M+ 2c"/"Vremena Grotesk" -- fonts this machine does not have (R-916) -- so any typed version was a look-alike. The website hero shows the same logo.png on the same dark background, so the covers match the page. The DOMAIN constant is removed rather than left as dead code. Caught before it shipped: the preview's new profile paragraph added a fourth %d and the argument tuple stayed in the old order, so the phone paragraph rendered "the centre 76 px of the 938-pixel width, with a profile circle 1640 cover-pixels across". Every number was real, just in the wrong slot, which is why it read as plausible instead of crashing. Found by reading the rendered paragraph back, not by the exit code. Built on DooPlex; all checks pass, the phone simulation still shows 0 px cut and 0 px under the profile circle on all three covers. R-919 stays VERIFY.
Felhom — Documentation
Felhom is a managed home-server service for Hungarian households, built on a three-component model over Proxmox:
- Hub — operator backend on k3s (
hub.felhom.eu). Repo:felhom.eu/hub/. - Host agent — one per Proxmox host; operator-tier; owns all Proxmox interaction. Repo:
felhom-agent/. - In-guest controller — one per customer LXC; Docker-only; manages the customer's apps. Repo:
felhom-controller/.
This directory is the central, code-verified documentation home for all three components plus the platform and the security-audit record.
Sections
Controller (in-guest) — controller/
The Docker-only app-domain controller. Full per-area docs grounded in current source (v0.59.0).
→ controller/README.md: module map, deploy & stack lifecycle, backup
architecture, storage/monitoring/metrics, auth/hub/sync/integrations.
Where we stand — architecture/where-felhom-stands.*
The operator's one-page picture of what is proven, built, partial and missing.
architecture/where-felhom-stands.html— generated; do not hand-editarchitecture/where-felhom-stands.yaml— the data behind it; every claim cites its source. Gate:scripts/check_stands.py; regenerate withscripts/render_stands.pyarchitecture/where-felhom-stands-2026-08-09-snapshot.html— a dated snapshot, NOT maintained. The original React bundle, kept for the record; its statuses are those of 2026-08-09 before the verification pass
Host agent & platform — architecture/, proxmox-platform.md
The operator-tier agent and the Proxmox platform.
architecture/01-topology-and-trust.md— topology & trust modelarchitecture/03-host-agent.md— the host agent (Go; v0.29.1)architecture/04-control-plane-authorization.md— signing, escrow, authzarchitecture/02-controller-module-map.md— historical v0.33 planning map; the live map iscontroller/module-map.mdproxmox-platform.md— Proxmox platform referencearchitecture/11-os-updates.md— operating-system updates: host, guest, Docker engine (NOT RATIFIED, 2026-10-04)
Hub (operator backend) — architecture/05
architecture/05-hub-architecture.md— hub architecture (v0.11.0)
Security audits & remediation — audits/
audits/deep-sweep-2026-06-13.md— cross-repo deep audit (controller + agent) with remediation statusaudits/bughunt-reconcile-2026-06-13.md— reconciliation of the v0.30.3 BUGHUNT against current code + merged fix list
Spike & test findings — tests/
Per-slice spike/validation findings (phases 0–5, slices 7–10). See tests/.
Conventions
- Code-verified, not memory-derived. Architectural claims here are checked against the actual current source; if a claim can't be verified it is omitted and flagged, not guessed.
- Per-repo operational working files (
CLAUDE.md,CONTEXT.md,CHANGELOG.md,BUGHUNT.md,REPORT.md,TASK.md) live in their own repos — they are operational, not published docs. - Authoritative versions at last refresh: controller v0.59.0, agent v0.29.1, hub v0.11.0.