fix(quota): correct forgejo lfs quota so users can push and tiers hold #21
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!21
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/quota"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What & why
Users in an LFS quota group (i.e. every user — the reconciler assigns one)
could not push or create repositories: Forgejo returned
413"quota exceeded".Root cause was a chain of issues in how the reconciler provisions Forgejo quota,
compounded by two non-obvious Forgejo quota semantics we verified empirically:
lfs, so allthree tiers shared one rule pinned at limit
0→ LFS blocked for everyone.[quota.default]does not apply to users in a group, and any subject agroup's rules don't cover is blocked (0), not unlimited. The groups only
covered
size:git:lfs, so repo/asset storage and repo creation were blocked.size:all=-1ruleunblocks everything but also overrides (defeats) the per-tier LFS cap.
Changes (per commit)
fix(reconciler)give each LFS group its own rule (rule name = group name) andreconcile its limit every run — fixes the shared-rule-at-0 collision.
feat(reconciler)give the free tier a 0.05 GiB LFS allowance (was a hard block).fix(reconciler)attach a sharedbaserule so group members aren't blocked onuncovered subjects (repo/asset storage, repo creation).
docs(forgejo)correct the[quota.default]comment to reflect the real model.fix(reconciler)scopebasetosize:repos:all+size:assets:all(notsize:all) so non-LFS stays unlimited and thesize:git:lfstier cap binds.Resulting model
Each LFS group has:
base(size:repos:all+size:assets:all= -1, unlimitednon-LFS) + a per-tier
size:git:lfsrule (0.05 / 5 / 50 GiB).ensure_groupisnow idempotent and self-healing (PATCHes limits/subjects every run).
Verification
succeed. main will match the deployed host state on merge.
lfs-xlgroup →201(non-LFS unblocked).tests.
Caveat
The LFS tier cap is enforced by the verified rule-combination semantics (LFS is
covered by only the tier rule → its limit binds) plus the non-LFS-works test; it
was not confirmed by an actual over-limit LFS push (impractical to stage).