- update.py builds target commits in temporary detached worktrees with
temporary image tags; checkouts and runtime tags move only after the API
fence and quiescence check pass, so refused/build-only runs keep
--verify-only passing.
- Activation includes the execution profile (worker/watchdog restart under
the fence) and verifies every service container runs the built image
before writing approved-commits.env.
- Compose: bounded local logging, API healthcheck via `otche healthcheck`,
web healthcheck and healthy API dependency, env-driven worker limits.
- TLS example: request-time upstream resolution, gzip, immutable assets,
headers not duplicated on /api.
- README: new update flow, sizing for parallel runs, fenced backup and
restore drill.