The README banner showed v0.9.40 while the badge showed v0.9.58 — static fields
that go stale and disagree. Removed the per-release version from both the badge row
and the banner SVG (the release version lives in tags/changelog, not a frozen
image). Added a "Supported operating systems" matrix (Debian/Ubuntu · RHEL · SUSE
full; Arch partial; Alpine metrics-only; anything else metrics-only) and real
minimum requirements (CPU/RAM/disk for the panel host; nothing on managed servers).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- promote.sh: add a leak guard that refuses to publish a tree still carrying a
private identifier (git.bave.dev / boban/clusev / clusev-staging) or an internal
doc (CLAUDE.md, rules.md, handoff.md, kickoff-prompt.md, docs/). This makes
promotion safe even for a tag cut BEFORE the export-ignore fixes — such a tree is
refused instead of leaking the dev/staging repos. Negative test added.
- .gitattributes: export-ignore kickoff-prompt.md (internal bootstrap doc; leaked
the VM IP + infra topology).
- README: move the banner/architecture SVGs out of the export-ignored docs/ into
art/ so the public README images are actually published.
- .env.example: comment out CLUSEV_REPOSITORY — a present-but-empty value defeats
the config default (env() returns ''), which would silently disable the public
update check. Left unset, the public-repo default applies.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>