The incremental deploy planner now selects full service paths, including vpn/xui, and detects owned image changes for nested services.
Compose recovery uses the complete previous configuration, including commands, environment, mounts, ports, and removed services. Successful deploys save private resolved configurations outside the retained run directories. Recovery captures deployed image digests and preserves Nextcloud AIO tags. The manual recovery command removes newly added services with --remove-orphans. It does not restore volume data or reverse database migrations.
Migration uses the last successful run configuration. If no saved configuration exists, it checks the persistent configuration against the running containers before accepting it. A mismatch stops preflight.
Namespace preflight defers server validation only for declared missing namespaces. Apply creates the namespaces, including those declared by Kustomize, then completes server validation before application resources change. Undeclared missing namespaces remain errors. Plan mode creates no resources.
Validation:
Gitea CI run 1692 passed for commit c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2. All eight validation jobs passed; image release jobs were skipped for this PR.
35 Python tests pass, including nested service selection and full Compose recovery configuration.
Shell regression checks pass for deferred validation and missing namespaces.
Ruff, ShellCheck, and git diff --check pass.
Read-only server dry-run on workstation passes for the revised namespace preflight.
Full deployment and Docker runtime recovery remain unverified. The local Docker daemon is unavailable.
The workstation controller is installed from commit c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2. Its SHA-256 matches the reviewed source. The controller help command passes. No deploy was active and no application was restarted. Previous Headscale and Nextcloud configurations are readable with mode 0600.
Controller rollback on workstation: bash ~/.local/state/homelab-deploy/updates/c4cbd87/rollback.sh. The script restores the saved controller and unit only when no deployment is active. Its shell syntax was checked; rollback was not executed.
The deployment scripts in this PR take effect after merge and a successful main CI release. This PR does not deploy or restart applications.
The incremental deploy planner now selects full service paths, including `vpn/xui`, and detects owned image changes for nested services.
Compose recovery uses the complete previous configuration, including commands, environment, mounts, ports, and removed services. Successful deploys save private resolved configurations outside the retained run directories. Recovery captures deployed image digests and preserves Nextcloud AIO tags. The manual recovery command removes newly added services with `--remove-orphans`. It does not restore volume data or reverse database migrations.
Migration uses the last successful run configuration. If no saved configuration exists, it checks the persistent configuration against the running containers before accepting it. A mismatch stops preflight.
Namespace preflight defers server validation only for declared missing namespaces. Apply creates the namespaces, including those declared by Kustomize, then completes server validation before application resources change. Undeclared missing namespaces remain errors. Plan mode creates no resources.
Validation:
- Gitea CI run [1692](https://git.forust.xyz/forust/homelab/actions/runs/1692) passed for commit `c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2`. All eight validation jobs passed; image release jobs were skipped for this PR.
- 35 Python tests pass, including nested service selection and full Compose recovery configuration.
- Shell regression checks pass for deferred validation and missing namespaces.
- Ruff, ShellCheck, and `git diff --check` pass.
- Read-only server dry-run on workstation passes for the revised namespace preflight.
- Full deployment and Docker runtime recovery remain unverified. The local Docker daemon is unavailable.
The workstation controller is installed from commit `c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2`. Its SHA-256 matches the reviewed source. The controller help command passes. No deploy was active and no application was restarted. Previous Headscale and Nextcloud configurations are readable with mode 0600.
Controller rollback on workstation: `bash ~/.local/state/homelab-deploy/updates/c4cbd87/rollback.sh`. The script restores the saved controller and unit only when no deployment is active. Its shell syntax was checked; rollback was not executed.
The deployment scripts in this PR take effect after merge and a successful main CI release. This PR does not deploy or restart applications.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The incremental deploy planner now selects full service paths, including
vpn/xui, and detects owned image changes for nested services.Compose recovery uses the complete previous configuration, including commands, environment, mounts, ports, and removed services. Successful deploys save private resolved configurations outside the retained run directories. Recovery captures deployed image digests and preserves Nextcloud AIO tags. The manual recovery command removes newly added services with
--remove-orphans. It does not restore volume data or reverse database migrations.Migration uses the last successful run configuration. If no saved configuration exists, it checks the persistent configuration against the running containers before accepting it. A mismatch stops preflight.
Namespace preflight defers server validation only for declared missing namespaces. Apply creates the namespaces, including those declared by Kustomize, then completes server validation before application resources change. Undeclared missing namespaces remain errors. Plan mode creates no resources.
Validation:
c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2. All eight validation jobs passed; image release jobs were skipped for this PR.git diff --checkpass.The workstation controller is installed from commit
c4cbd8759031fe0a2d6bbfbd3e385c8b4c0057e2. Its SHA-256 matches the reviewed source. The controller help command passes. No deploy was active and no application was restarted. Previous Headscale and Nextcloud configurations are readable with mode 0600.Controller rollback on workstation:
bash ~/.local/state/homelab-deploy/updates/c4cbd87/rollback.sh. The script restores the saved controller and unit only when no deployment is active. Its shell syntax was checked; rollback was not executed.The deployment scripts in this PR take effect after merge and a successful main CI release. This PR does not deploy or restart applications.