Files
felhom.eu/documentation/audits/version-travel-2026-09-26/A7

A7 — a backup stores the image's NAME, not the image: how many of today's digests still resolve

Measured 2026-09-26T08:15:42Z from DooPlex, read-only: a7head.py sends one registry HEAD per ref@digest (anonymous token; a HEAD is not a pull and does not count against Docker Hub's pull limit).

The fact. A recovery unit records image_pins and — since v0.275.0 — each data file's running ref@digest (data.files[*].images); the manifest's own note says "image NOT stored — re-pulled on restore". So a restore of a version works only while the registry still serves that version. If a maker deletes an old tag or digest, a unit of that version cannot start, and v0.275.0's rule (a restore brings the data back at its own version) makes that dependency sharper: the restore asks for exactly the old version.

Today. The catalog records digests only in its ladder entries (update_ladder[].digest): 42 distinct ref@digest pairs, all 42 answer 200 (a7-result.txt). Negative control: the same instrument answers 404 for an invented digest on Docker Hub and on ghcr.io (a7-negative-control.txt), so a 200 is not the instrument's only answer. The 66 compose image lines carry no digest in the catalog (the box adds one when it pins from a ladder entry); a tag can be re-pointed or deleted without any digest to check against, so this measures what is checkable, not the whole exposure.

Not measured: the digests actually recorded on boxes (installed_images), which include versions older than any ladder entry; how often makers delete old versions (no history kept); the from side of ladder entries (no digest recorded there).

Options, not decided (filed as a row): (a) keep as is — a restore of a deleted version fails with the pull error, and the household's route is the next copy or a newer version; (b) mirror every image a box has INSTALLED into the DooPlex registry (gitea.dooplex.hu) and let a restore fall back to the mirror — storage and bandwidth on DooPlex, and a new moving part on the recovery path; (c) mirror only the versions the ladder names (bounded by the catalog, not by the fleet) — does not cover a box on a pre-ladder version; (d) store the image in the unit (docker save) — hundreds of MB per app per copy, on every tier including off-site.