Files
felhom.eu/documentation/backlog
admin eba522f06e
gates / gates (push) Successful in 5m44s
secrets: the 12 remaining reused logins as a checklist; repo stays public (operator rulings)
Operator ruled 2026-10-09, after seeing the measurement:
  (a) he rotates the remaining services himself -- CC's scope stopped at the
      Felhom boundary;
  (b) felhom.eu STAYS anonymously readable for now, because making it private
      breaks the website git-sync and the installer tag fetch, which both
      clone with NO credentials (R-110).

The standing consequence of (b): no secret may ever enter this repo again,
which manifest_bearer_gate.py now enforces with no exemption. If (b) is ever
reversed, the 32 <!-- source --> comments served on /adatkezeles must be
stripped in the same change, because they are a map of the repo.

secrets.md now carries the exact checklist -- namespace / secret / key, 12
rows, RE-MEASURED after the Felhom rotation by hashing against the value git
history still serves, which also confirms the three CC rotated are absent
from it.

Two things recorded with it, both learned the hard way the same day:
  - a DATABASE password is not changed by editing the Secret. bookstack-db
    root-password is read at first init and then lives in the engine, exactly
    like umami's POSTGRES_PASSWORD did.
  - check the app can still RESTART before trusting the rotation: umami ran
    124 days at 512Mi and was OOMKilled on every restart attempt.

And the urgency, measured rather than assumed: these are not LAN-only.
nextcloud / paperless / bookstack / qbittorrent .dooplex.hu all resolve in
PUBLIC DNS to the public address and answer HTTPS with a login page. No login
was attempted; reachability is the point.
2026-10-09 13:37:28 +02:00
..
…

documentation/backlog/

OPEN-ITEMS.md is the register of open work and the file to read first — it holds only what is open, one row per item, every row with a category, a severity, a state and an owner (the layout is at its top). CLOSED-ITEMS.md holds every finished row, compressed, with the commit that keeps its full text; a row moves there in the same commit that closes it (scripts/closed_register_gate.py RULE 3). ROADMAP.md holds intentions — features and spikes that do not exist yet — and ROADMAP-HISTORY.md the shipped and killed ones. An R-n id is minted once and never reused.

The other files in this folder — verdict per file (2026-10-03 triage)

File Verdict
SPEC-app-data-placement-2026-08-21.md KEEP — still referenced by open rows R-352 (placement still open) and R-368.
SPEC-r85-phase4-5-2026-07-26.md KEEP as history — a spec of shipped work (R-85, agent v0.104.0). CONTEXT.md and architecture/00-capability-map.md link here.
FOLLOWUP-nas-automount-guest-reboot-reassert.md FINISHED, kept in place — shipped in agent v0.84/v0.85 (CAMPAIGN-3). Not moved because CONTEXT.md, controller/network-storage-nas.md and felhom-controller/CONTEXT.md link to this path.

Moved to documentation/archive/ on 2026-10-03 (finished; nothing open refers to them):

  • FIX-M18-NOTES.md — dump re-validation every 5 min. FIXED in controller v0.62.0 @ f8afe5c (2026-06-14).
  • FIX-M19-NOTES.md — deriveStackName misattribution edge. FIXED in controller v0.62.0 @ 6bab68b (2026-06-14).
  • FOLLOWUP-golden-default-controller-tag.md — the golden baked a stale controller. FIXED in felhom-agent @ ceca355 (2026-07-03): build-golden.sh v2.0.0 makes the controller tag a mandatory argument. Evidence: ../audits/DRILL-golden-098-2026-07-03.md.
  • DIAGNOSIS-f9-storage-registration-gap-2026-06-14.md — a read-only diagnosis of June 2026, superseded by the shipped F9 fixes (controller CHANGELOG.md cites it as history).

The archive also holds OPEN-ITEMS-narratives-2026-10-03.md: the campaign write-ups, rulings and ranking paragraphs that sat between the register's tables until the triage, word for word.