gitea-image-prune.sh: keep the newest 20 and every version in use; refuse when the in-use list is unreadable (Felhom 09 decision 62, R-750)

Protected whatever --keep says: the controller floor, the vouched golden, the vouched agent and min_agent (the hub's
Configuration page), every image of ours the vouched golden baked (its bake.log), the hub manifest's image. The dry-run
prints each kept version and why. tests/test-prune-plan.sh pins it without network (red-proofed). No --apply was run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-01 13:05:31 +02:00
parent 7739c830cb
commit c9d5ed575c
5 changed files with 209 additions and 133 deletions
+15 -8
View File
@@ -96,21 +96,28 @@ GITEA_TOKEN=… ./gitea-image-prune.sh
./gitea-image-prune.sh --all list
./gitea-image-prune.sh --all --no-sizes list # fast, skip size resolution
# Dry-run prune (DEFAULT — shows what would go, mutates nothing):
./gitea-image-prune.sh --repo felhom-hub --keep 10
# Dry-run prune (DEFAULT — shows what would go, mutates nothing). --keep defaults to 20:
./gitea-image-prune.sh --all prune # containers
./gitea-image-prune.sh --type generic --all prune # agent + golden
./gitea-image-prune.sh --repo felhom-controller --older-than 90
# Apply for real (typed confirmation unless --yes):
./gitea-image-prune.sh --repo felhom-hub --keep 10 --apply
./gitea-image-prune.sh --repo felhom-hub --keep 10 --apply --reclaim --measure
# Apply for real — a PERSON's act, after reading the dry-run (typed confirmation unless --yes):
./gitea-image-prune.sh --all prune --apply --reclaim --measure
# Reclaim only (delete orphaned manifests + trigger/await GC):
./gitea-image-prune.sh --repo felhom-hub reclaim --apply
# Cron-friendly, non-interactive, all packages:
./gitea-image-prune.sh --all --keep 15 --apply --yes --reclaim
```
### The retention rule (Felhom `09` §3 decision 62, operator ruling 2026-10-01)
A prune keeps the **newest 20** versions of every package **plus every version in use**, whatever `--keep` or
`--older-than` says: the controller floor, the vouched golden, the vouched agent and its `min_agent` (read from the
hub's operator Configuration page with `HUB_PW` — env, or `~/.config/credentials` through
`felhom.eu/scripts/read_credential.py`), every `gitea.dooplex.hu/admin/<pkg>:<tag>` the vouched golden baked (its
`bake.log` under `felhom.eu/documentation/tests/`), and the hub image `felhom.eu/manifests/hub.yaml` runs. The dry-run
prints each kept version with its reason. **If any of these cannot be read, the prune refuses (exit 3).** Nothing runs
this script on a schedule; `--apply` is a person's act. `tests/test-prune-plan.sh` pins the rule without network.
### Flags
| Flag | Meaning |