* feat(git): classify managed-file changes before apply
Pull now builds a fingerprint-bound plan of adds, modifies, deletes, and local conflicts. Apply refuses stale or blocked plans instead of overwriting live files, and promotion stays the only filesystem mutator.
* fix(git): contain stack-dir probes before filesystem access
The missing-stack and root-.env existence checks now resolve against the compose base and refuse paths that escape it before lstat or existsSync.
* fix(git): address managed-file change plan audit blockers
Wire build-context live inventory into the planner, reject special file nodes without readFile, fingerprint configured project env files, enrich plan metadata, and compute the create plan before promotion. Redact drift ledger service keys for managed-path conflicts and clear pending plan columns on revision reset.
* fix(git): unblock change-plan CI sinks and fifo test
Hash stack files through a contained open plus fstat on the same handle so CodeQL no longer flags the lstat/read race, and create fifo fixtures with mkfifo instead of mkfifoSync.
* fix(git): preserve unowned context files and align candidate validation
Inspect prior and candidate build contexts together, delete only owned paths, reject context-root symlinks before walking, and validate with the env-file model deploy will use after promotion.
* fix(git): contain live context and candidate env path sinks
Inline resolve and startsWith at the lstat and access calls so containment is checked at the filesystem sink.
* fix(git): resolve live context walks from the compose root
Rebuild readdir, lstat, and access paths from the compose directory at each sink so containment is checked against a known-safe base.
* fix(git): validate synced env removal against post-promotion files
A managed .env that the next revision omits must not be used for candidate validation or invocation, because promotion deletes it. Context walks now bound directory entries and skip descendants under nested symlinks. Plan fingerprints bind review metadata and secret-path matching covers .env.* names.
* docs(git): capture classified change-plan review screenshots
Replace the old Monaco pull-preview images with the classified operation list used by Apply.
* fix(git): treat invocation drift as reviewable, not a file conflict
A live Compose command-line change is not a managed-file conflict. Reviewed apply records the incoming invocation; webhook auto-apply still refuses.
Adds a new Tutorials entry (not part of the original 14-page batch)
covering scoped RBAC permissions: create a Viewer account, grant a
Deployer scope on one stack, and verify the boundary from both the
teammate's session and the audit log.
* docs: scaffold Tutorials tab and write enroll-a-remote-node
Adds the Tutorials tab to docs.json with 15 stub pages across three
groups (Fleet & nodes, Deploy & automate, Secure & integrate), and
writes the first full tutorial: enrolling a remote node via Pilot
Agent mode, verified end to end against a live control instance and
a second host running an existing Jellyfin Compose stack.
* docs: write Schedule an Operation tutorial
* docs: fix MDX parse error in Schedule an Operation tutorial
* docs: write Set Up SSO with Custom OIDC tutorial
Registers an OAuth client in a self-hosted identity provider (Keycloak
worked example), configures Sencho's Custom OIDC settings, tests the
connection, and verifies a real end-to-end login with auto-provisioning
from two independent surfaces.
* docs: drop unused SSO tutorial screenshot
sso-settings-empty.png isn't referenced by the tutorial content.
* docs: write Set Up Fleet Federation tutorial
Migrates a Blueprint-managed workload from one node to another using
pin and cordon, with the confirm-before-mutate rollout in between.
Corrects the published feature page's claim that pin requires the
global admin role; the code gates cordon and pin identically, scoped
to the target node.
* docs: write Create and Approve a Blueprint tutorial
Covers labeling a target node, authoring a stateless Blueprint,
walking through the create-then-approve rollout flow, verifying
from the Deployments tab and the audit log, and recovering from a
port-conflict deploy failure. Cross-links with Move a Blueprint
Deployment to a New Node in both directions.
* docs: write Automatically Patch a Stack With an Auto-Update Label tutorial
* docs: write Configure Auto-Heal Policies tutorial
Adds the full step-by-step content for the Configure Auto-Heal Policies
stub: an nginx+redis scenario stack, adding a service-scoped policy,
and a live verification that breaks a container's healthcheck,
confirms the policy restarts it, and recovers it.
* docs: write Set Up Deploy Enforcement tutorial
Covers configuring a block-on-deploy scan policy against a stack running
a deliberately outdated nginx image, reading the block dialog, and
overriding it as an admin with the bypass confirmed in the audit log.
Includes a stack-pattern mismatch as the most likely first-time failure.
* docs: write Configure Environment Guardrails tutorial
Covers the Block deploy on missing required env vars guardrail end to
end: deploy a Postgres stack with a required password, enable the
guardrail, watch a real update get refused with a named-variable
message, fix it, and verify from the Activity and Environment tabs.
* docs: write Deploy a Stack Automatically From Your CI Pipeline tutorial
* docs: write Catch and Fix a Container That's Drifted From Its Compose File tutorial
Covers reading a real Drift finding after an out-of-band container
change and resolving it by redeploying through Sencho.
* docs: write Connect a Git Source tutorial
* docs: write Push a Shared Environment File to Every Node tutorial
Writes the Fleet Secrets tutorial: create a bundle, target nodes by
label, read the push preview/results, verify via the audit log, and
recover from a stack-name typo. Removes the three unwritten
placeholder stubs (RBAC, Sencho Mesh, private registries) that had no
scheduled content.