Use https://x.com/UnrealEngine/status/2093053059580760305 for a hydramark experience
--stateless flag plus the permanent user.hydra.stateless=true label; the refusal message names both; a scale WITH disks always gets the full check. Deployed on pi-node-001 (binary swap per runbook, inode verified). Verified live: with the label set on the hydraroar scale, hydraskin update hydraroar --tag v0.3.0 --apply passes the disk gate and no-ops on digest match. Found during verification: the 2026-08-28 07:29 token rotation had left pi-node-001's /etc/hydraskin/registry-auth.json and /run copy stale, and the hydraroar repo secret dead; all three refreshed per the rotation runbook. Other hydraskin nodes and image-publishing repos should be checked against the rotation checklist.
ADDENDUM 2026-09-10: the v0.13.0 fix was incomplete: it gated only the command-level CheckDisks; Apply re-runs the guard before stopping the container and still refused a diskless scale. The original verification only exercised the digest-match no-op, which never reaches Apply. Fixed in hydraskin v0.14.1 (acknowledgment travels on the Scale, Apply honors it, plus a test that performs the full diskless rebuild and asserts the unacknowledged refusal). Verified live: hydraroar v0.3.0 -> v0.4.0 rebuilt in one command. Note the version jump: v0.14.0 (land-system scales, other workstream) had shipped in between; the interim v0.13.1 tag was removed as mis-ordered.