feat(forgejo): enable the #188 storage cutover + fix the storage chown #194

Sammanfogat
supernaut sammanfogade 3 incheckningar från feat/188-cutover in i main 2026-07-21 22:10:11 +00:00
Ägare

Reconciles main with the applied prod state (#188 cutover): forgejo_external_storage_enabled=true + lfs_volume_id (the tofu-provisioned ceph volume), and the non-recursive storage chown fix (a recursive podman-unshare chown trips on ext4's root-owned lost+found; Forgejo creates+owns its own subdirs anyway).

Applied + verified on prod: /srv/gitborg-lfs mounted, [storage] PATH=/srv/storage live, Forgejo healthy (/api/healthz 200) on the pinned 16.0.0 image, all storage backends (lfs/packages/attachments/avatars/…) initialised on the new volume. Repos + Postgres stay on ceph-ssd.

Reconciles main with the applied prod state (#188 cutover): `forgejo_external_storage_enabled=true` + `lfs_volume_id` (the tofu-provisioned ceph volume), and the non-recursive storage chown fix (a recursive podman-unshare chown trips on ext4's root-owned `lost+found`; Forgejo creates+owns its own subdirs anyway). **Applied + verified on prod:** /srv/gitborg-lfs mounted, `[storage] PATH=/srv/storage` live, Forgejo healthy (`/api/healthz` 200) on the pinned 16.0.0 image, all storage backends (lfs/packages/attachments/avatars/…) initialised on the new volume. Repos + Postgres stay on ceph-ssd.
supernaut lade till 1 incheckning 2026-07-21 21:08:47 +00:00
feat(forgejo): enable the #188 storage cutover + fix the storage chown
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m38s
2ef359dc6b
Activate the external [storage] split on prod: forgejo_external_storage_enabled=true + lfs_volume_id set from the tofu-provisioned ceph volume. Fix: chown the storage mountpoint NON-recursively — Forgejo creates+owns its own lfs/packages/attachments subdirs, and a recursive podman-unshare chown trips on ext4's root-owned lost+found. Applied + verified on prod: /srv/gitborg-lfs mounted, [storage] live, Forgejo healthy (200) on the pinned image, all storage backends initialised on the new volume.
supernaut lade till 1 incheckning 2026-07-21 21:16:12 +00:00
refactor(vault): move OpenStack resource IDs out of the public repo (#188)
Väntande kontroller
ci / ci (pull_request) Has started running
448eb88dd6
Cinder volume IDs (data/backup/lfs) + the CI-runner network ID are identifiers, not secrets, but they're internal infra detail that doesn't belong in a public repo. Move them into Ansible Vault (vault_*) and reference them from group_vars; the by-serial mount + all consumers are unchanged. No behaviour change.
supernaut lade till 1 incheckning 2026-07-21 21:17:59 +00:00
docs(tofu): drop hardcoded Bahnhof catalog UUIDs from tfvars.example (#188)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m29s
28b43bd025
Keep the catalog name + how to look the ID up (openstack image/network list) instead of pinning a UUID in the example. Completes the plaintext-ID cleanup.
supernaut sammanfogade incheckning 3ab8554147 till main 2026-07-21 22:10:11 +00:00
supernaut tog bort grenen feat/188-cutover 2026-07-21 22:10:11 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!194
Ingen beskrivning angiven.