forgejo role: forgejo_work_path default is stale after the rootless migration (ADR 0031) #207

Stängd
öppnade 2026-07-22 13:50:59 +00:00 av supernaut · 1 kommentar
Ägare

Found while building the ADR 0031 phase-2 rehearsal tooling (#91).

Problem

roles/forgejo/defaults/main.yml still defaults forgejo_work_path to /data/gitea (the rootful image layout). On the -rootless image the work dir is /var/lib/gitea — app.ini.j2 already hardcodes WORK_PATH = /var/lib/gitea, and there is no group_vars override.

As a result, the role's code-search index reclaim task (roles/forgejo/tasks/main.yml, the rm -rf {{ forgejo_work_path }}/indexers run that fires when the repo indexer is disabled) targets /data/gitea/indexers, which does not exist in the rootless container. The reclaim becomes a silent no-op — it can no longer delete a leftover index directory under the real work path.

Impact

Low right now: code search (zoekt) is disabled, so there is no index to reclaim. But once the rootless cutover lands (ADR 0031) this default is wrong, and if code search is re-enabled/disabled later the reclaim would not free the index bytes.

Fix

Key forgejo_work_path off the rootless layout (/var/lib/gitea), or derive it from the same source app.ini's WORK_PATH uses, so the reclaim path is correct post-cutover.

Found while building the ADR 0031 phase-2 rehearsal tooling (#91). ## Problem `roles/forgejo/defaults/main.yml` still defaults `forgejo_work_path` to `/data/gitea` (the rootful image layout). On the `-rootless` image the work dir is `/var/lib/gitea` — `app.ini.j2` already hardcodes `WORK_PATH = /var/lib/gitea`, and there is no group_vars override. As a result, the role's code-search index reclaim task (`roles/forgejo/tasks/main.yml`, the `rm -rf {{ forgejo_work_path }}/indexers` run that fires when the repo indexer is disabled) targets `/data/gitea/indexers`, which does not exist in the rootless container. The reclaim becomes a silent no-op — it can no longer delete a leftover index directory under the real work path. ## Impact Low right now: code search (zoekt) is disabled, so there is no index to reclaim. But once the rootless cutover lands (ADR 0031) this default is wrong, and if code search is re-enabled/disabled later the reclaim would not free the index bytes. ## Fix Key `forgejo_work_path` off the rootless layout (`/var/lib/gitea`), or derive it from the same source app.ini's `WORK_PATH` uses, so the reclaim path is correct post-cutover.
Upphovsperson
Ägare

Fixed on feat/91-git-ssh-rootless (PR #118, commit db5e647): forgejo_work_path default → /var/lib/gitea, matching the rootless WORK_PATH in app.ini, so the index-reclaim targets /var/lib/gitea/indexers correctly.

Kept scoped to the rootless branch rather than a separate main PR: on main (rootful) the current /data/gitea default is still correct, so there's nothing to change there. The Closes #207 in the commit auto-closes this once #118 merges at the ADR 0031 cutover.

Fixed on `feat/91-git-ssh-rootless` (PR #118, commit db5e647): `forgejo_work_path` default → `/var/lib/gitea`, matching the rootless `WORK_PATH` in app.ini, so the index-reclaim targets `/var/lib/gitea/indexers` correctly. Kept scoped to the rootless branch rather than a separate main PR: on `main` (rootful) the current `/data/gitea` default is still correct, so there's nothing to change there. The `Closes #207` in the commit auto-closes this once #118 merges at the ADR 0031 cutover.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#207
Ingen beskrivning angiven.