Files
felhom.eu/documentation/audits/the-28-2026-09-22/BODY-teardown.md
T
admin 186546d562
gates / gates (push) Successful in 27s
THE TWENTY-EIGHT: every app no drill had touched, walked in one night
All 28 walked on scratch guest 9202 against the private drill catalog. 26 deployed, 6 proven,
5 inconclusive, 14 with no upstream edge, 1 failed honestly (outline 1.9.1->1.10.1, HELD with the
right sentence), 2 undeployable - one (plant-it) by design, refused by the lifecycle gate, proven
live for the first time. Each app also got the half the update night skipped: a restore from its own
copy with the seed read back again - 21 restored, 2 correctly REFUSED per 07 6.2.

R-630 RAISED TO P1 by measurement: a stack with NO probe container does not skip verifying - it
waits out the full health timeout and HOLDS, stopping an app whose three containers read healthy.
The controller's own words: "not healthy within 5m0s (last: no probe container)".

R-633 opened: a remove sent during a restore reports success and leaves a container restarting with
a live public route. The product already refuses that clash for update and for restore, naming the
blocker; remove has no such guard.

R-634 opened: an app can be running, healthy and serving while recorded as deployed=false, and is
then unremovable. Reproducible alone on sparkyfitness; concurrency-linked on two others.

R-631 and R-632 CLOSED. Register 321 -> 323. Seven interventions, six of them my own harness -
named, with what each cost. No product code. The live catalog's image: lines are byte-identical to
the start of the night.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 16:00:56 +02:00

2.3 KiB


Teardown — three layers plus Gitea, every claim READ BACK

The machine (9202). controller.yaml restored from controller.yaml.pre-28; git.repo_url reads back as the live catalog with an empty token; and — the one that actually decides which remote is followed (R-615) — the cache reads origin https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git at 1ad1f34. No drill images. Disk 1.9 GB used of 32 GB, unchanged from the start.

Three things the product could NOT clear, and a shell had to. This is not tidy-up, it is the finding: the termix and gokapi containers left by R-633, and sparkyfitness's app.yaml left by R-634. gokapi was still Restarting two hours later. They were removed by name (docker rm -f termix gokapi, rm .../sparkyfitness/app.yaml) — never a prune. Afterwards 9202 runs exactly felhom-controller, filebrowser, traefik, and no app.yaml exists anywhere. A household has no shell. Evidence: teardown/manual-cleanup.txt.

The host (demo-hp). pct list before and after: 9201 demo-hp and 9202 demo-hp-scratch, both running, unchanged. pvesm status unchanged but for expected scratch growth (nvme-scratch 5.19% → 6.95%). Guest 9201 was never touched.

The hub. Nothing provisioned, nothing changed. 9202 runs hub.enabled: false (R-620).

Gitea. The drill repo is reset to the live main (1ad1f34b6e51). git diff of the live catalog's templates/ against the night's baseline: 0 lines, and image: lines changed: NONE.

The fences, each read back rather than asserted:

fence at the start at the end
live catalog origin/main 1ad1f34b6e51 1ad1f34b6e51
demo-hp guest 9201 catalog cache 1ad1f34, live remote 1ad1f34, live remote
demo-felhom guest 9201 catalog cache 1ad1f34, live remote 1ad1f34, live remote
drill repo CI jobs 47 47 — no run, no mail, all night (R-629 holds)

Peti's box is parked and received nothing. Nothing ran on DooPlex beyond ordinary pushes, and nothing on ep0. felhom-controller, felhom-agent and the hub were read only — no product code was written. No golden, no bake, no vouch, no --no-verify, no branch. local-lvm untouched, no prune, tester-1 never reset, drill-r50 untouched.