|
All checks were successful
CD / Build and push images (push) Successful in 3m51s
CI / Lint, typecheck, test (push) Successful in 4m5s
CD / Deploy to Test (push) Successful in 11s
CI / Build container images (push) Has been skipped
CD / Smoke tests against Test (push) Successful in 1m11s
CD / Promote to Int (push) Successful in 12s
CI / Auth e2e pack (push) Successful in 5m52s
CI / Import/export fidelity gate (push) Successful in 47s
The operator-level extra beside the admin-configured Nextcloud target (#103), unblocked now that the ONE→BASEL tunnel is stable again. - sidecar: optional mirror step (mirror.ts) driven purely by env — BACKUP_MIRROR_TARGET (rsync-over-ssh), BACKUP_MIRROR_SSH_KEY (private key on the secrets volume, never in image or repo), BACKUP_MIRROR_SSH_PORT. Runs after the prune of every successful run, so --delete aligns the remote retention with the local one (the newest-complete-set guarantee carries over). Only set files travel (db-*.dump, files-*.tar.gz); status files and bundles stay local. Host key pinned via accept-new into .mirror_known_hosts on the backups volume; fixed remote modes (dirs 750, files 640, symbolic --chmod — octal needs rsync ≥ 3, macOS dev machines ship 2.6.9). rsync + openssh-client added to the sidecar image. - status: additive `mirror` block in status.json (outcome, transferred count, lastSuccessAt carried across failures) — shown on the admin backup card; failures alert via a new backupMirrorFailed mail (de+en) while the local run still counts as succeeded. - deploy/backup-basel.md: complete BASEL-side walkthrough — dedicated user dorfteich-backup with a /home/ home and a bash login shell, explicitly avoiding the Debian backup-user (UID 34) pitfalls (nologin shell rejects rsync sessions, /var/backups home), key placement through the api container onto the secrets volume, .env values, on-demand verification. - tests: rsync-arg/stats-parsing units plus an integration suite against the real rsync binary (local target; skips where rsync is absent) — transfer, idempotent re-run (0 files), retention alignment, failure path carrying lastSuccessAt. Verified live against the real BASEL host from a native sidecar run: initial transfer, host-key pinning, retention alignment after a local prune, idempotency, and the failure path (surfaced in status.json while the local run stayed green). BASEL side provisioned per the doc. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1 |
||
|---|---|---|
| .. | ||
| editor-schema | ||
| permissions | ||
| admin-users.ts | ||
| api-error.ts | ||
| api-tokens.ts | ||
| auth.test.ts | ||
| auth.ts | ||
| backup-set.ts | ||
| backup-status.ts | ||
| collab-token.test.ts | ||
| collab-token.ts | ||
| comments.ts | ||
| conversion.ts | ||
| env.test.ts | ||
| env.ts | ||
| files.ts | ||
| fonts.test.ts | ||
| fonts.ts | ||
| health.test.ts | ||
| health.ts | ||
| i18n-tools.test.ts | ||
| i18n-tools.ts | ||
| index.ts | ||
| labels.test.ts | ||
| labels.ts | ||
| legal.ts | ||
| links.ts | ||
| members.ts | ||
| notifications.ts | ||
| pages.ts | ||
| plugins.ts | ||
| ponds.ts | ||
| public-api.ts | ||
| quotas.ts | ||
| search.test.ts | ||
| search.ts | ||
| secret-store.ts | ||
| setup.ts | ||
| system.ts | ||
| text-diff.test.ts | ||
| text-diff.ts | ||
| token-crypto.ts | ||
| watches.ts | ||
| webdav.test.ts | ||
| webdav.ts | ||