c9d5ed575c
Protected whatever --keep says: the controller floor, the vouched golden, the vouched agent and min_agent (the hub's Configuration page), every image of ours the vouched golden baked (its bake.log), the hub manifest's image. The dry-run prints each kept version and why. tests/test-prune-plan.sh pins it without network (red-proofed). No --apply was run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
13 lines
952 B
Markdown
13 lines
952 B
Markdown
# REPORT — gitea-image-prune.sh gets the retention rule (2026-10-01)
|
|
|
|
Felhom `09` §3 decision 62 (operator ruling, R-750). Full report: `felhom.eu/REPORT-calibre-name-and-prune-2026-10-01.md`.
|
|
|
|
- **Rule:** keep the newest 20 + every version in use (floor, vouched golden, vouched agent, `min_agent`, the golden's
|
|
baked images, the running hub); refuse (exit 3) when the in-use list cannot be read; `--apply` only by a person.
|
|
- **Test:** `tests/test-prune-plan.sh` — 7 checks pass; red-proof: the in-use check removed from `is_protected` → 3 fail
|
|
(the plan deletes 5 and lists 0.262.0).
|
|
- **Live dry-run, 2026-10-01 (nothing deleted):** in use — controller 0.285.0, golden 0.285.0, agent 0.138.0 and 0.131.0,
|
|
hub 0.126.0, felhom-samba 1.1.0. Would delete: felhom-controller 70 tags, felhom-hub 8; every other package nothing.
|
|
Evidence: `felhom.eu/documentation/audits/calibre-name-and-prune-2026-10-01/B/`.
|
|
- **No `--apply` was run.**
|