fix(bootstrap): carry the operator's [archive] keys across re-runs too
Same class as 765a892, same table-level amnesia: [archive] retention /
warn_before / max_local_bytes are the reaper's runtime knobs (read from the
config Secret at job time; built-ins 90d / 3d,1d / no cap), and write_felis_toml
rewrote the whole table as store+local_path on every re-run. An operator who
narrowed the retention window silently got the 90d built-in back.
persisted_archive_block carries the three keys forward; store and local_path
stay installer-owned (FELIS_ARCHIVE_LOCAL_PATH must equal the mount the render
passes). Extends the bootstrap_test carry case with the archive keys and the
installer-owned exclusion.
This commit is contained in:
2 files changed
+45
-8
No files matched your search
+32
-4
@@ -2129,6 +2129,29 @@ persisted_auth_source_blocks() {
|
|||||||
'url = "https://littleskin.cn/api/yggdrasil/sessionserver/session/minecraft/hasJoined"'
|
'url = "https://littleskin.cn/api/yggdrasil/sessionserver/session/minecraft/hasJoined"'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# persisted_archive_block echoes the operator-owned [archive] keys an earlier run
|
||||||
|
# left behind — the retention window, the pre-reap warn offsets, the local cap —
|
||||||
|
# so a re-run does not silently revert them to the built-ins the reaper carries
|
||||||
|
# (felis reaper reads these from the config Secret at run time; defaults: 90d
|
||||||
|
# retention, 3d/1d warnings, no cap). store and local_path are NOT carried: this
|
||||||
|
# script owns them (FELIS_ARCHIVE_LOCAL_PATH must equal the mount). Same
|
||||||
|
# first-readable-file rule as persisted_smtp_block; warn_before must be a
|
||||||
|
# single-line TOML array (the shape every writer here emits).
|
||||||
|
persisted_archive_block() {
|
||||||
|
local f out
|
||||||
|
for f in "${STATE_DIR}/felis.host.toml" "${STATE_DIR}/felis.pod.toml"; do
|
||||||
|
[ -r "$f" ] || continue
|
||||||
|
out="$(awk '
|
||||||
|
/^[[:space:]]*\[/ { sect = $0; next }
|
||||||
|
sect ~ /^[[:space:]]*\[archive\][[:space:]]*$/ &&
|
||||||
|
/^[[:space:]]*(retention|warn_before|max_local_bytes)[[:space:]]*=/ { print }
|
||||||
|
' "$f")"
|
||||||
|
[ -n "$out" ] || continue
|
||||||
|
printf '%s\n' "$out"
|
||||||
|
return 0
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
# persisted_registry_block echoes the operator-owned [registry] keys an earlier run
|
# persisted_registry_block echoes the operator-owned [registry] keys an earlier run
|
||||||
# left behind — the build-lane executor mirrors, the resource caps, the uploads
|
# left behind — the build-lane executor mirrors, the resource caps, the uploads
|
||||||
# backend and its [registry.s3] subtable — so §15's upgrade path (re-run the
|
# backend and its [registry.s3] subtable — so §15's upgrade path (re-run the
|
||||||
@@ -2157,7 +2180,7 @@ persisted_registry_block() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
write_felis_toml() {
|
write_felis_toml() {
|
||||||
local target="$1" db_host="$2" smtp_block auth_source_blocks registry_block
|
local target="$1" db_host="$2" smtp_block auth_source_blocks registry_block archive_block
|
||||||
smtp_block="$(persisted_smtp_block)"
|
smtp_block="$(persisted_smtp_block)"
|
||||||
if [ -n "$smtp_block" ]; then
|
if [ -n "$smtp_block" ]; then
|
||||||
log "carrying forward the configured [smtp] relay"
|
log "carrying forward the configured [smtp] relay"
|
||||||
@@ -2169,10 +2192,15 @@ write_felis_toml() {
|
|||||||
log "carrying forward the configured [registry] overrides"
|
log "carrying forward the configured [registry] overrides"
|
||||||
registry_block="${registry_block}"$'\n' # keep a blank line before the next section
|
registry_block="${registry_block}"$'\n' # keep a blank line before the next section
|
||||||
fi
|
fi
|
||||||
|
archive_block="$(persisted_archive_block)"
|
||||||
|
if [ -n "$archive_block" ]; then
|
||||||
|
log "carrying forward the configured [archive] overrides"
|
||||||
|
archive_block="${archive_block}"$'\n' # keep a blank line before the next section
|
||||||
|
fi
|
||||||
cat > "$target" <<EOF
|
cat > "$target" <<EOF
|
||||||
# Generated by deploy/bootstrap.sh; rerun the installer to regenerate. Hand edits are
|
# Generated by deploy/bootstrap.sh; rerun the installer to regenerate. Hand edits are
|
||||||
# overwritten, except [smtp], [[auth_source]], and the operator-owned [registry]
|
# overwritten, except [smtp], [[auth_source]], and the operator-owned [registry] /
|
||||||
# overrides, which carry forward.
|
# [archive] overrides, which carry forward.
|
||||||
[server]
|
[server]
|
||||||
listen = "0.0.0.0:8080"
|
listen = "0.0.0.0:8080"
|
||||||
root_domain = "${FELIS_ROOT_DOMAIN}"
|
root_domain = "${FELIS_ROOT_DOMAIN}"
|
||||||
@@ -2197,7 +2225,7 @@ ${registry_block}
|
|||||||
[archive]
|
[archive]
|
||||||
store = "tarLocal"
|
store = "tarLocal"
|
||||||
local_path = "${FELIS_ARCHIVE_LOCAL_PATH}"
|
local_path = "${FELIS_ARCHIVE_LOCAL_PATH}"
|
||||||
|
${archive_block}
|
||||||
[auth]
|
[auth]
|
||||||
admin_hostname = "op.console.${FELIS_ROOT_DOMAIN}"
|
admin_hostname = "op.console.${FELIS_ROOT_DOMAIN}"
|
||||||
panel_hostname = "console.${FELIS_ROOT_DOMAIN}"
|
panel_hostname = "console.${FELIS_ROOT_DOMAIN}"
|
||||||
|
|||||||
@@ -733,12 +733,13 @@ esac
|
|||||||
|
|
||||||
wrblock="$(awk '/^write_felis_toml\(\) \{/,/^}/' "$BS")"
|
wrblock="$(awk '/^write_felis_toml\(\) \{/,/^}/' "$BS")"
|
||||||
prblock="$(awk '/^persisted_registry_block\(\) \{/,/^}/' "$BS")"
|
prblock="$(awk '/^persisted_registry_block\(\) \{/,/^}/' "$BS")"
|
||||||
[ -n "$wrblock" ] && [ -n "$prblock" ] \
|
pablock="$(awk '/^persisted_archive_block\(\) \{/,/^}/' "$BS")"
|
||||||
|| { echo "FAIL: write_felis_toml / persisted_registry_block not found in $BS"; exit 1; }
|
{ [ -n "$wrblock" ] && [ -n "$prblock" ] && [ -n "$pablock" ]; } \
|
||||||
|
|| { echo "FAIL: write_felis_toml / persisted_{registry,archive}_block not found in $BS"; exit 1; }
|
||||||
# The blocks quote themselves (the awk program uses single quotes), so they are
|
# The blocks quote themselves (the awk program uses single quotes), so they are
|
||||||
# sourced from a file instead of being spliced into a single-quoted bash -c.
|
# sourced from a file instead of being spliced into a single-quoted bash -c.
|
||||||
fnfile="$(mktemp)"
|
fnfile="$(mktemp)"
|
||||||
printf '%s\n%s\n' "$prblock" "$wrblock" > "$fnfile"
|
printf '%s\n%s\n%s\n' "$prblock" "$pablock" "$wrblock" > "$fnfile"
|
||||||
|
|
||||||
rdir="$(mktemp -d)"
|
rdir="$(mktemp -d)"
|
||||||
cat > "$rdir/felis.host.toml" <<'TOML'
|
cat > "$rdir/felis.host.toml" <<'TOML'
|
||||||
@@ -751,6 +752,11 @@ trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2"
|
|||||||
[registry.s3]
|
[registry.s3]
|
||||||
endpoint = "https://s3.example"
|
endpoint = "https://s3.example"
|
||||||
region = "us-east-1"
|
region = "us-east-1"
|
||||||
|
|
||||||
|
[archive]
|
||||||
|
store = "tarLocal"
|
||||||
|
local_path = "/stale/path"
|
||||||
|
retention = "30d"
|
||||||
TOML
|
TOML
|
||||||
|
|
||||||
run_write() { # out-file
|
run_write() { # out-file
|
||||||
@@ -772,8 +778,11 @@ expect "a re-run carries the build-lane executor mirrors" \
|
|||||||
expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out"
|
expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out"
|
||||||
expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out"
|
expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out"
|
||||||
expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out"
|
expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out"
|
||||||
|
expect "a re-run carries the archive retention window" 'retention = "30d"' "$out"
|
||||||
|
expect "the archive mount stays installer-owned" 'local_path = "/a"' "$out"
|
||||||
case "$out" in
|
case "$out" in
|
||||||
*stale.invalid* | *stale-ns*) echo "FAIL: stale installer-owned registry values survived the re-run"; fails=$((fails + 1)) ;;
|
*stale.invalid* | *stale-ns* | *stale/path*)
|
||||||
|
echo "FAIL: stale installer-owned values survived the re-run"; fails=$((fails + 1)) ;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
cp "$rdir/out.toml" "$rdir/felis.host.toml"
|
cp "$rdir/out.toml" "$rdir/felis.host.toml"
|
||||||
|
|||||||
Reference in new issue
Block a user