deployment.md only said "replace the jar and restart", which left out the runtime-bundle case entirely — including the trap that the tarball unpacks to a `gittally/` directory and must not be extracted over ~/opt. Both variants now list the actual commands, with a rollback copy and the note that a restart is safe because in-flight builds are re-enqueued. Co-Authored-By: Claude <noreply@anthropic.com>