feat(backup-drill): restore and verify kanidm on the scratch vm #506
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!506
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/drill-kanidm-restore"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
The weekly backup drill now restores the Kanidm backup on the scratch VM and checks it.
kanidm-backup.json(restore reads only plain JSON) and runs a one-shotkanidmd database restorewith the pinned production image./status.bitborg_backup_drill_kanidm_personsandbitborg_backup_drill_kanidm_groups. A failed check fails the drill, soBackupDrillFailedcovers it. No new alert.No admin credential is needed. The image and domain are templated from
kanidm_image,kanidm_image_tagandkanidm_domain.Verified
check-alert-rules.py,smoke-textfile.py,bash -nandpy_compileon the rendered templates.Not verified
The full drill has not run. After merge:
scripts/apply-reconcile.sh, tagsbackup-drill,monitoring.bitborg-backup-drill.service.[restore] METRIC kanidm_persons,[restore] METRIC kanidm_groups,kanidm /status OK, then[drill] restore-drill PASSED.bitborg_backup_drill_last_run_statusis 0.Closes #458