snapshot.sh backs up one hardcoded database and still reports ok #108
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#108
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
deploy/ops/snapshot.shbacks up exactly one database, by name, and sayssnapshot okregardless of what else is on the box.Line 107:
Add any stateful service to the ops box and the snapshot still succeeds while
containing nothing of it.
deploy/UPGRADES.mdmakes that exit code the gate forevery ops upgrade — "no copy, no upgrade" — so the gate would be passing on a
copy that is missing the thing being upgraded.
This surfaced while designing a feedback board for the ops box. It is worth
fixing regardless of whether that board is ever built, which is why it is filed
on its own rather than inside it.
Today the box happens to have one stateful service, so nothing is lost right now.
The failure is that adding the second is silent.
What to do
A completeness assertion. The script already enumerates services for the
manifest at line 87:
Have it also fail when a declared service is in neither a
BACKED_UPnor aSTATELESSlist. Adding a service then forces a deliberate choice instead of asilent omission.
Then cross-check the lists from a test — the idiom this repository already uses
twice.
inventory.mjskeepsHOST_FILESidentical toinstall-deployer.sh'sCHECKED_FILESwith a test that reads the file, for the stated reason that twocheckers disagreeing about what healthy means is how the ops box stayed
unswept;
console.test.tsdoes the same forUPGRADEABLEagainstparsePins.deploy/test/snapshot.test.ts: readsnapshot.shanddeploy/ops/docker-compose.yml,assert every declared service is accounted for in one list or the other.
Verification
Mutation-check it, in both directions. Feed a compose fixture containing an
unlisted service and confirm the test fails; then confirm it passes on the
real file. A test that has never failed proves nothing, and that is the whole
point of this issue.
Moved to the Vikunja board as NEC-84: https://projectron.nerchure.com/tasks/84