From b8e554dac70342146f49bede731c803ed15493fc Mon Sep 17 00:00:00 2001 From: Lemon-miaow Date: Wed, 23 Sep 2026 19:09:57 +0800 Subject: [PATCH] fix(bootstrap): carry the operator's [archive] keys across re-runs too Same class as 765a892, same table-level amnesia: [archive] retention / warn_before / max_local_bytes are the reaper's runtime knobs (read from the config Secret at job time; built-ins 90d / 3d,1d / no cap), and write_felis_toml rewrote the whole table as store+local_path on every re-run. An operator who narrowed the retention window silently got the 90d built-in back. persisted_archive_block carries the three keys forward; store and local_path stay installer-owned (FELIS_ARCHIVE_LOCAL_PATH must equal the mount the render passes). Extends the bootstrap_test carry case with the archive keys and the installer-owned exclusion. --- deploy/bootstrap.sh | 36 ++++++++++++++++++++++++++++++++---- deploy/bootstrap_test.sh | 17 +++++++++++++---- 2 files changed, 45 insertions(+), 8 deletions(-) diff --git a/deploy/bootstrap.sh b/deploy/bootstrap.sh index b518d1e..3217e66 100644 --- a/deploy/bootstrap.sh +++ b/deploy/bootstrap.sh @@ -2129,6 +2129,29 @@ persisted_auth_source_blocks() { 'url = "https://littleskin.cn/api/yggdrasil/sessionserver/session/minecraft/hasJoined"' } +# persisted_archive_block echoes the operator-owned [archive] keys an earlier run +# left behind — the retention window, the pre-reap warn offsets, the local cap — +# so a re-run does not silently revert them to the built-ins the reaper carries +# (felis reaper reads these from the config Secret at run time; defaults: 90d +# retention, 3d/1d warnings, no cap). store and local_path are NOT carried: this +# script owns them (FELIS_ARCHIVE_LOCAL_PATH must equal the mount). Same +# first-readable-file rule as persisted_smtp_block; warn_before must be a +# single-line TOML array (the shape every writer here emits). +persisted_archive_block() { + local f out + for f in "${STATE_DIR}/felis.host.toml" "${STATE_DIR}/felis.pod.toml"; do + [ -r "$f" ] || continue + out="$(awk ' + /^[[:space:]]*\[/ { sect = $0; next } + sect ~ /^[[:space:]]*\[archive\][[:space:]]*$/ && + /^[[:space:]]*(retention|warn_before|max_local_bytes)[[:space:]]*=/ { print } + ' "$f")" + [ -n "$out" ] || continue + printf '%s\n' "$out" + return 0 + done +} + # persisted_registry_block echoes the operator-owned [registry] keys an earlier run # left behind — the build-lane executor mirrors, the resource caps, the uploads # backend and its [registry.s3] subtable — so §15's upgrade path (re-run the @@ -2157,7 +2180,7 @@ persisted_registry_block() { } write_felis_toml() { - local target="$1" db_host="$2" smtp_block auth_source_blocks registry_block + local target="$1" db_host="$2" smtp_block auth_source_blocks registry_block archive_block smtp_block="$(persisted_smtp_block)" if [ -n "$smtp_block" ]; then log "carrying forward the configured [smtp] relay" @@ -2169,10 +2192,15 @@ write_felis_toml() { log "carrying forward the configured [registry] overrides" registry_block="${registry_block}"$'\n' # keep a blank line before the next section fi + archive_block="$(persisted_archive_block)" + if [ -n "$archive_block" ]; then + log "carrying forward the configured [archive] overrides" + archive_block="${archive_block}"$'\n' # keep a blank line before the next section + fi cat > "$target" < "$fnfile" +printf '%s\n%s\n%s\n' "$prblock" "$pablock" "$wrblock" > "$fnfile" rdir="$(mktemp -d)" cat > "$rdir/felis.host.toml" <<'TOML' @@ -751,6 +752,11 @@ trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2" [registry.s3] endpoint = "https://s3.example" region = "us-east-1" + +[archive] +store = "tarLocal" +local_path = "/stale/path" +retention = "30d" TOML run_write() { # out-file @@ -772,8 +778,11 @@ expect "a re-run carries the build-lane executor mirrors" \ expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out" expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out" expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out" +expect "a re-run carries the archive retention window" 'retention = "30d"' "$out" +expect "the archive mount stays installer-owned" 'local_path = "/a"' "$out" case "$out" in - *stale.invalid* | *stale-ns*) echo "FAIL: stale installer-owned registry values survived the re-run"; fails=$((fails + 1)) ;; + *stale.invalid* | *stale-ns* | *stale/path*) + echo "FAIL: stale installer-owned values survived the re-run"; fails=$((fails + 1)) ;; esac cp "$rdir/out.toml" "$rdir/felis.host.toml"