- TAG guidance points at pinned release tags (e.g. v0.14.0) instead of
the pre-release `test` tag; concrete curl commands fetch the three
reference files.
- Backup wording (guide + .env.example) names all four data volumes in
the restore set (uploads, plugins, custom fonts, branding).
- Updating section states the back-up-first step and links the update
runbook.
- Pass the external-authentication variables (OIDC_*, AUTH_LOCAL_ENABLED,
AUTH_PROXY_*) through the reference compose and document them in
.env.example: they were documented in security.md but unreachable from
.env. Empty values count as unset (app-config.service.ts), so the block
is inert until configured.
- New guide section "External authentication (optional)"; neutral
APP_BASE_URL example.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017aviRTgWCcAHUh1SBoxf6P