e3741ae493
gates / gates (push) Successful in 6m5s
Not public. It sits in Planner until Monday evening and can still be changed or deleted there. THE POST. Operator chose version 6.2 (kozepes), Hungarian only, 638 Unicode characters, 0 emoji, 0 hashtags. He chose Monday over today on the reasoning offered: it was Friday 15:08, the weakest evening of the week for a first post, and three days in Planner is review time. post id 1360018983863273_122096547315511222 due 2026-10-12 19:00 Europe/Budapest = epoch 1791824400 = 17:00 UTC link https://felhom.eu/ READ BACK, and the hex check recomputed OUTSIDE the probe so it is not the same instrument twice: is_published False; scheduled time sent == read; message sha256 887514383eff997c on both sides (COPY.md 6.2 and what Facebook returned). Present in GET /{page}/scheduled_posts. And from a DIFFERENT CHANNEL than the API: Planner shows it on H 12 at 19:00 with the link card. SCENARIO A, the dry check that had to come first. A throwaway scheduled post WITH THE LINK was accepted -- so `link` is not refused on a scheduled post, which was the open question. Read back hex-equal and unpublished, seen PRESENT in the scheduled list, deleted, seen ABSENT in the same list. The removal proof comes from the LIST, not from an error after DELETE, which is what R-914 asked for. CHECKED RATHER THAN COPIED. The post repeats the website's "56 alkalmazas". The apps page carries 57 <div class="app-card"> while saying 56 -- which reads as an off-by-one until you read the category line, "6 alkalmazas + 1 beepitett". The 57th card is FileBrowser, built into every box and deliberately not counted; index.html says "56 telepitheto alkalmazas" too. NOT-A-FINDING, and a "fix" would have made a live public page wrong. R-917 -> VERIFY (close when the operator confirms it published and is pinned). R-914 noted, NOT closed: schedule-post covers text + link only; the photo path stays unbuilt because the spike could not prove a scheduled PHOTO stays hidden, and the pin, comment moderation and post-insight read-back are still missing. Secret scan on the committed evidence: planted EAA decoy 1 -> 0 after deletion, 0 access_token, no run.log.
Felhom — Documentation
Felhom is a managed home-server service for Hungarian households, built on a three-component model over Proxmox:
- Hub — operator backend on k3s (
hub.felhom.eu). Repo:felhom.eu/hub/. - Host agent — one per Proxmox host; operator-tier; owns all Proxmox interaction. Repo:
felhom-agent/. - In-guest controller — one per customer LXC; Docker-only; manages the customer's apps. Repo:
felhom-controller/.
This directory is the central, code-verified documentation home for all three components plus the platform and the security-audit record.
Sections
Controller (in-guest) — controller/
The Docker-only app-domain controller. Full per-area docs grounded in current source (v0.59.0).
→ controller/README.md: module map, deploy & stack lifecycle, backup
architecture, storage/monitoring/metrics, auth/hub/sync/integrations.
Where we stand — architecture/where-felhom-stands.*
The operator's one-page picture of what is proven, built, partial and missing.
architecture/where-felhom-stands.html— generated; do not hand-editarchitecture/where-felhom-stands.yaml— the data behind it; every claim cites its source. Gate:scripts/check_stands.py; regenerate withscripts/render_stands.pyarchitecture/where-felhom-stands-2026-08-09-snapshot.html— a dated snapshot, NOT maintained. The original React bundle, kept for the record; its statuses are those of 2026-08-09 before the verification pass
Host agent & platform — architecture/, proxmox-platform.md
The operator-tier agent and the Proxmox platform.
architecture/01-topology-and-trust.md— topology & trust modelarchitecture/03-host-agent.md— the host agent (Go; v0.29.1)architecture/04-control-plane-authorization.md— signing, escrow, authzarchitecture/02-controller-module-map.md— historical v0.33 planning map; the live map iscontroller/module-map.mdproxmox-platform.md— Proxmox platform referencearchitecture/11-os-updates.md— operating-system updates: host, guest, Docker engine (NOT RATIFIED, 2026-10-04)
Hub (operator backend) — architecture/05
architecture/05-hub-architecture.md— hub architecture (v0.11.0)
Security audits & remediation — audits/
audits/deep-sweep-2026-06-13.md— cross-repo deep audit (controller + agent) with remediation statusaudits/bughunt-reconcile-2026-06-13.md— reconciliation of the v0.30.3 BUGHUNT against current code + merged fix list
Spike & test findings — tests/
Per-slice spike/validation findings (phases 0–5, slices 7–10). See tests/.
Conventions
- Code-verified, not memory-derived. Architectural claims here are checked against the actual current source; if a claim can't be verified it is omitted and flagged, not guessed.
- Per-repo operational working files (
CLAUDE.md,CONTEXT.md,CHANGELOG.md,BUGHUNT.md,REPORT.md,TASK.md) live in their own repos — they are operational, not published docs. - Authoritative versions at last refresh: controller v0.59.0, agent v0.29.1, hub v0.11.0.