fix(backup-drill): skip doctor authorized_keys check for rootless built-in SSH (#224) #225
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!225
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/224-drill-rootless-authorized-keys"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Fixes #224 — the third (and expected final) rootless follow-up for the restore drill.
After #220 (restic lock) and #223 (app.ini path), the drill runs the full
forgejo doctorsuite but[E]-fails on the authorized_keys check: the ADR-0031 built-in SSH server authenticates from the DB, not a hostauthorized_keysfile (stashed to.rootful-legacy/at migration), so the file is correctly absent. SetSSH_CREATE_AUTHORIZED_KEYS_FILE = falsein the drill's scratch app.ini so doctor skips the check — SSH-key restore soundness is already covered by the DB restore (user-row count).The other 4 doctor checks (paths, DB version, user types, repo HEADs) already pass, so this should give a green drill and clear
BackupDrillFailed.After merge + apply (
--tags backup-drill), re-run the drill (reset-failed first if it's rate-limited). Syntax-check, ansible-lint (production), Prettier clean.Closes #224.