# remove_hba_block drops the block write_pg_hba_block maintains, and nothing else.
# remove_hba_block drops the block bootstrap heads pg_hba.conf with (the rules of an
# install on the host server, or the lockout the move into k3s left), and nothing else.
remove_hba_block(){# file
local tmp
tmp="$(mktemp)"
@@ -374,23 +395,46 @@ SQL
die "the ${DB_USER} role still holds $(printf'%s'"$held" | paste-sd';' - | sed's/;/; /g'), so DROP ROLE would fail halfway through the purge; nothing was removed. Hand them to postgres first (sudo -u postgres psql -c 'ALTER DATABASE <name> OWNER TO postgres', or REASSIGN OWNED BY ${DB_USER} TO postgres; DROP OWNED BY ${DB_USER}; inside that database), or rerun without --purge"
}
# purge_database drops the felis database and role from a host PostgreSQL an earlier
# release installed; the cluster felis-postgres runs goes with DATA_DIR (purge_state). That
# host server either still serves the platform, or the move into felis-postgres stopped it
# with the pre-move copy left in it for a rollback: a purge takes that copy too and leaves
# the server stopped. The units and k3s are gone by now, so a failure here is a warning
# with the commands to finish by hand, and the purge goes on.
warn "could not start the host PostgreSQL, so its copy of the ${DB_NAME} database from before the move into k3s stays in it; drop it once it runs: sudo -u postgres dropdb ${DB_NAME}; sudo -u postgres dropuser ${DB_USER}"
warn "could not drop the ${DB_NAME} database and role from the host PostgreSQL; drop them by hand: sudo -u postgres dropdb ${DB_NAME}; sudo -u postgres dropuser ${DB_USER}"
return 0
fi
if[-n"$hba"]&&[-f"$hba"];then
remove_hba_block "$hba"
rm-f"${hba}.pre-pg-move"
fi
if["$started"= 1 ];then
systemctl stop postgresql
ok "the host PostgreSQL's copy of '${DB_NAME}' from before the move into k3s dropped; the server stays stopped"
else
systemctl restart postgresql
ok "database and role '${DB_NAME}' dropped; PostgreSQL listens on its default address again"
&&echo"PASS the database shuts down cleanly before k3s-killall.sh kills what is left"\
||{echo"FAIL felis-postgres was not stopped before k3s-killall.sh: $calls";fails=$((fails +1));}
expect "and the uninstall waits for it to stop""KUBE -n felis wait --for=delete pod -l app.kubernetes.io/name=felis,app.kubernetes.io/component=postgres""$calls"
refute "keep-data keeps the cluster directory's SELinux rule""SEMANAGE""$calls"
# --- a failed final bundle stops everything ------------------------------------------------