backup-drill: restore and verify Kanidm on the scratch VM #458
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#458
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The weekly drill (
ansible/roles/backup-drill/templates/restore-on-scratch.sh.j2) restores Postgres, Forgejo data and the restic storage, then runsforgejo doctor. It never toucheskanidm-backup.json. The weekly verify only gzip-parses it.Kanidm is the sole identity provider for Forgejo, the portal and Grafana. A
kanidmd database restorethat breaks on an image bump is found on the day it is needed.Add a Kanidm restore step to the drill script: start a one-shot Kanidm container against the restored dump (the server must be stopped for
database restore, so use the one-shotpodman runpattern the runbook uses fordomain rename), then probe/statusand count persons and groups. Fail the drill if either is zero. Emit the counts as drill metrics.Related: #157, #161.
Epic: bitborg/bitborg-docs#107