From 12d2697801720a32feb7b83ec953d396570ab89d Mon Sep 17 00:00:00 2001 From: Lemon-miaow Date: Sat, 26 Sep 2026 11:38:34 +0800 Subject: [PATCH] =?UTF-8?q?docs(uninstall):=20=E6=9B=B4=E6=AD=A3=20felis?= =?UTF-8?q?=5Fpgint=20=E7=9A=84=E6=9D=A5=E5=8E=86=E8=AF=B4=E6=98=8E?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- deploy/uninstall.sh | 9 +++++---- deploy/uninstall_test.sh | 2 +- docs/operations.md | 2 +- 3 files changed, 7 insertions(+), 6 deletions(-) diff --git a/deploy/uninstall.sh b/deploy/uninstall.sh index 36cf7bc..d54b30f 100644 --- a/deploy/uninstall.sh +++ b/deploy/uninstall.sh @@ -340,10 +340,11 @@ remove_hba_block() { # file rm -f "$tmp" } -# check_database_purge runs before anything is removed: DROP ROLE refuses a role that -# still owns a database or holds anything in one besides felis (a felis_pgint left by -# `felis db pgint`, a grant made by hand), and by then the units and k3s are already gone. -# It lists what holds the role instead, so the purge either runs to the end or not at all. +# check_database_purge runs before anything is removed. DROP ROLE refuses a role that +# still owns a database or holds anything in one besides felis (the felis_pgint database +# CONTRIBUTING.md has developers make for the PG contract tests, a grant made by hand), +# and by the time purge_database runs the units and k3s are already gone. It lists what +# holds the role instead, so the purge either runs to the end or not at all. check_database_purge() { [ "$PURGE" = 1 ] || return 0 systemctl is-active --quiet postgresql 2>/dev/null || return 0 diff --git a/deploy/uninstall_test.sh b/deploy/uninstall_test.sh index a625341..5747034 100644 --- a/deploy/uninstall_test.sh +++ b/deploy/uninstall_test.sh @@ -191,7 +191,7 @@ esac expect "purge cleans Docker's build cache" "DOCKER builder prune -af" "$calls" # --- a purge DROP ROLE would refuse ------------------------------------------------------- -# The VM drill: `felis db pgint` had left felis_pgint owned by felis, the purge removed the +# The VM drill: the PG contract tests' felis_pgint was owned by felis, the purge removed the # units and k3s, then stopped at DROP ROLE with half the host gone. untouched() { # label [ -d "$root/h/opt" ] && [ -f "$root/h/units/felis-velocity.service" ] && [ -d "$root/h/etc" ] \ diff --git a/docs/operations.md b/docs/operations.md index c98bf90..7fec058 100644 --- a/docs/operations.md +++ b/docs/operations.md @@ -210,7 +210,7 @@ the cluster holds nothing but Felis's namespaces; when it runs anything else onl | | keep data (default) | `--purge` | |---|---|---| | Final database bundle | taken first (`felis db backup -label manual`); a failure stops the uninstall before anything is removed. `--no-backup` skips it | none | -| `felis` database and role | kept | dropped; `listen_addresses` and `pg_hba.conf` go back to how they were. Checked before anything is removed: a role that still owns another database (a `felis_pgint` left by `felis db pgint`) or holds grants elsewhere stops the purge up front with the list and the `ALTER DATABASE … OWNER TO postgres` to run | +| `felis` database and role | kept | dropped; `listen_addresses` and `pg_hba.conf` go back to how they were. Checked before anything is removed: a role that still owns another database (the `felis_pgint` the PG contract tests use, CONTRIBUTING.md) or holds grants elsewhere stops the purge up front with the list and the `ALTER DATABASE … OWNER TO postgres` to run | | `/etc/felis` (secrets, `felis.toml`, `offsite.env`, tunnel config) | kept; `bootstrap.done` and the per-run records go | deleted, with the tunnel's credentials file | | `/var/lib/felis` (database bundles) | kept | deleted | | Worlds, archives, registry, uploads | moved to `/var/lib/felis/retained/k3s-storage-/` (with `--keep-k3s`: their volumes switch to `Retain` and stay in place) | deleted |