From 2a813d323a263987bd8a424db4454f80dd3950ac Mon Sep 17 00:00:00 2001 From: tmk241 Date: Sat, 15 Aug 2026 20:42:35 +0200 Subject: [PATCH] docs(apsuflow): separate host data migration --- skills/apsuflow/SKILL.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/skills/apsuflow/SKILL.md b/skills/apsuflow/SKILL.md index b3dcedd..c0afd07 100644 --- a/skills/apsuflow/SKILL.md +++ b/skills/apsuflow/SKILL.md @@ -96,7 +96,13 @@ supply them with `--admin-token` and `--agent-token`. Pass `--allow-secret-env` and `--acknowledge-recovery-risk` when the reviewed migration declaration requires those same explicit apply acknowledgments. Commit as root only after review; it quiesces persisted services and reapplies -the exact declarations through public controls. Retain its rollback +the exact declarations through public controls. If the reviewed declaration +changes an existing writable host-volume source, do not add data movement to +`host migrate` and do not weaken apply's path-change refusal. First retire the +old workloads explicitly with public `apply --prune`, prove zero desired/live +containers, verify an operator-owned application backup off-host, perform the +reviewed host-data move with its own rollback boundary, and only then run +unchanged `host migrate` and reapply the exact declaration. Retain its rollback directory until the split services, exact declaration reapply, and application-level data checks pass. Never recursively chown workload data or repair migration through SQLite, OCI, CNI, firewall, or namespace mutation.