die "could not ask PostgreSQL what the ${DB_USER} role still holds, so nothing was removed: ${held}"
fi
rm-f"$err"
[-n"$held"]||return 0
die "the ${DB_USER} role still holds $(printf'%s'"$held" | paste-sd';' - | sed's/;/; /g'), so DROP ROLE would fail halfway through the purge; nothing was removed. Hand them to postgres first (sudo -u postgres psql -c 'ALTER DATABASE <name> OWNER TO postgres', or REASSIGN OWNED BY ${DB_USER} TO postgres; DROP OWNED BY ${DB_USER}; inside that database), or rerun without --purge"
objects in database shop (privileges)" run_uninstall "default felis minecraft"--purge--yes)"
expect "a purge the role cannot survive is refused""the felis role still holds database felis_pgint (owned); objects in database shop (privileges)""$out"
expect "with the way to hand the database over""ALTER DATABASE <name> OWNER TO postgres""$out"
untouched "nothing is removed when DROP ROLE would fail"
expect "a server that cannot be asked stops the purge""could not ask PostgreSQL what the felis role still holds, so nothing was removed: psql: error: connection refused""$out"
untouched "nothing is removed when the check cannot run"
Changes for docs/operations.md: 1 added line, 1 removed line.
Original line number
Diff line number
Diff line
@@ -189,7 +189,7 @@ the cluster holds nothing but Felis's namespaces; when it runs anything else onl
| | keep data (default) | `--purge` |
|---|---|---|
| Final database bundle | taken first (`felis db backup -label manual`); a failure stops the uninstall before anything is removed. `--no-backup` skips it | none |
| `felis` database and role | kept | dropped; `listen_addresses` and `pg_hba.conf` go back to how they were |
| `felis` database and role | kept | dropped; `listen_addresses` and `pg_hba.conf` go back to how they were. Checked before anything is removed: a role that still owns another database (a `felis_pgint` left by `felis db pgint`) or holds grants elsewhere stops the purge up front with the list and the `ALTER DATABASE … OWNER TO postgres` to run |
| `/etc/felis` (secrets, `felis.toml`, `offsite.env`, tunnel config) | kept; `bootstrap.done` and the per-run records go | deleted, with the tunnel's credentials file |
| Worlds, archives, registry, uploads | moved to `/var/lib/felis/retained/k3s-storage-<stamp>/` (with `--keep-k3s`: their volumes switch to `Retain` and stay in place) | deleted |