Adds a short "Running under upaas" section to the README, next to
"Running with Docker": the container port, the data volume and the
commands that create it, the environment variables upaas should set,
the health check upaas reads after a deploy, and where the first-run
admin password appears and how to reset it.
upaas bind-mounts a host directory it does not create, and a
directory made by root stops the container at its data directory
lock. The section has the operator create the directory owned by
UID 1000 before the first deploy; the image is unchanged.
Model: opus-5-5
The help text under the field on both target forms and the max_retries rows in the README now say the number is the total number of delivery attempts: 0 is a single attempt with no retries and no circuit breaker, and N is N attempts in total. The delivery code already worked this way; only the wording was wrong, so an operator wanting one try plus two retries would have entered 2 instead of 3. A UI copy test renders both forms and pins the wording. Delivery behaviour is unchanged.
Model: opus-4-8 (implementation); fable-5-1 (merge)
Two packages each declared the 0o750 mode for DATA_DIR and both created the directory. internal/datadir now exports DirPerm as the single definition, and internal/database uses it in both places it creates the directory. The value is unchanged, so existing deployments see no permission change. datadir owns it because guarding and creating DATA_DIR is that package's whole purpose and it imports nothing that would form a cycle.
Model: opus-4-8 (implementation and review); fable-5-1 (merge)