20af94c0a0
The tools had been on 3.6.0 while the container sat on 3.0.0 for seven days, so the operator verbs failed with "no tool named delete_handle" — they live in the post office, not the client. Image built on nh3-dev from a clean tree at 4d26226 and pushed under the claude-bot namespace; the compose pin moves to the new digest rather than floating on the tag, since this container is the fleet's whole message bus. The backup procedure this file documents earned itself again: at stop time the database was 23.8 MB with a 5.9 MB WAL beside it, so a plain copy would have produced a database that opens cleanly, smokes green, and is missing the day's mail. Stop, explicit checkpoint to a zero-byte WAL, copy, then verify counts on both sides — 76 handles, 995 messages, 1022 recipients, integrity ok. Post-deploy the same counts came back with handles.retired_at present, and the memory cap and OOM guard were confirmed by `docker inspect` rather than by reading the yaml, which is what that file asks for and the only check that can tell a working cap from a decorative one. Bus down about four minutes.