Restore drill doctor fails on rootless authorized_keys check (built-in SSH server, no authorized_keys file) #224
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#224
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Symptom
BackupDrillFailedpersists after #220 (lock) and #223 (app.ini path) are applied. The drill now completes the restic restore + writes the app.ini + bootsforgejo doctor, which runs the full default suite — but check [4] fails:forgejo doctoritself exits 0; the drill's strict[E]-grep (restore-on-scratch.sh) treats the[E]as a failure.Root cause — false positive for the ADR-0031 built-in SSH server
The doctor's
authorized-keyscheck verifies the host OpenSSHauthorized_keysfile against the DB — a concept from the rootful host-OpenSSH-delegation model (ADR 0006). Since the ADR-0031 rootless cutover (#91), git-SSH is served by Forgejo's built-in server, which authenticates from the DB, not anauthorized_keysfile (the migration stashed the old OpenSSHgit/dir into.rootful-legacy/). So the file is correctly absent, and the restored SSH keys live in the DB — which the drill already verifies ("restored user rows: 10").Prod's app.ini sets
START_SSH_SERVER = true, but the drill's minimal scratch app.ini sets no SSH options, so doctor runs the check with the rootful assumption.Fix
Set
SSH_CREATE_AUTHORIZED_KEYS_FILE = false(built-in-server model) in the drill's scratch app.ini[server]block, so doctor's authorized-keys check skips. SSH-key restore soundness is already covered by the DB restore.Third rootless follow-up for the drill (after #219/#220 lock, #222/#223 app.ini). The other 4 doctor checks (paths, DB version, user types, repo HEADs) all pass — this should complete the drill and clear the alert.
Refs #91 (ADR 0031).