fix(backup-drill): skip doctor authorized_keys check for rootless built-in SSH (#224) #225

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/224-drill-rootless-authorized-keys in i main 2026-07-27 11:54:16 +00:00
Ägare

Fixes #224 — the third (and expected final) rootless follow-up for the restore drill.

After #220 (restic lock) and #223 (app.ini path), the drill runs the full forgejo doctor suite but [E]-fails on the authorized_keys check: the ADR-0031 built-in SSH server authenticates from the DB, not a host authorized_keys file (stashed to .rootful-legacy/ at migration), so the file is correctly absent. Set SSH_CREATE_AUTHORIZED_KEYS_FILE = false in the drill's scratch app.ini so doctor skips the check — SSH-key restore soundness is already covered by the DB restore (user-row count).

The other 4 doctor checks (paths, DB version, user types, repo HEADs) already pass, so this should give a green drill and clear BackupDrillFailed.

After merge + apply (--tags backup-drill), re-run the drill (reset-failed first if it's rate-limited). Syntax-check, ansible-lint (production), Prettier clean.

Closes #224.

Fixes #224 — the third (and expected final) rootless follow-up for the restore drill. After #220 (restic lock) and #223 (app.ini path), the drill runs the full `forgejo doctor` suite but `[E]`-fails on the authorized_keys check: the ADR-0031 built-in SSH server authenticates from the DB, not a host `authorized_keys` file (stashed to `.rootful-legacy/` at migration), so the file is correctly absent. Set `SSH_CREATE_AUTHORIZED_KEYS_FILE = false` in the drill's scratch app.ini so doctor skips the check — SSH-key restore soundness is already covered by the DB restore (user-row count). The other 4 doctor checks (paths, DB version, user types, repo HEADs) already pass, so this should give a green drill and clear `BackupDrillFailed`. After merge + apply (`--tags backup-drill`), re-run the drill (reset-failed first if it's rate-limited). Syntax-check, ansible-lint (production), Prettier clean. Closes #224.
supernaut lade till 1 incheckning 2026-07-27 09:15:52 +00:00
Third rootless follow-up for the drill (after #220 lock, #223 app.ini path). The drill
now runs the full forgejo doctor suite but [E]-fails on the authorized_keys check: the
ADR-0031 built-in SSH server authenticates from the DB, not a host authorized_keys file
(stashed to .rootful-legacy at migration), so it is correctly absent. Set
SSH_CREATE_AUTHORIZED_KEYS_FILE=false in the drill scratch app.ini so doctor skips it;
SSH-key restore soundness is covered by the DB restore.
supernaut sammanfogade incheckning b3b77f47ed till main 2026-07-27 11:54:16 +00:00
supernaut tog bort grenen fix/224-drill-rootless-authorized-keys 2026-07-27 11:54:16 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!225
Ingen beskrivning angiven.