## 0.75.2 - **The documented install command could not work, and now does.** `install.sh` defaulted to `--tier connected`, `install.py` requires `--receiver-url` at that tier, and the script had no such flag: every invocation in `INSTALL.md` died at argument validation after a 300 MB download, on every host, at the last step before anything was written. The default is now `air-gapped`, the one tier that needs nothing the operator does not already have, and `--receiver-url` exists and is forwarded only when set, because `install.py` refuses that flag at `air-gapped` rather than ignoring it. A deployment that starts air-gapped is not stuck there: `tier` and `receiver_url` live in `config/deployment.yaml`, which nothing rewrites, an upgrade included. - **The Docker refusal names a command.** A host without Docker was told what was missing and not what to run. `install.sh` now reads `/etc/os-release` and prints the install line for the Debian, RHEL, Amazon Linux and SUSE families, falling back to the upstream documentation for anything it does not recognise, because a confidently wrong package command is worse than none. The script still installs nothing. - **Guards that covered one end of a contract now cover both.** The install tests asserted what `install.sh` handed to `install.py` and never that the receiving end accepted it, which is how a broken default shipped. The published-digest guard read `INSTALL.md` by name while `DOGFOODING.md` carried a digest that had stopped being true; it now discovers every document publishing one.