ROADMAP: media, backups and archives deployed (v1.23.0, decePub v1.5.0)
Build / Build (push) Successful in 7m41s
Build / Build (push) Successful in 7m41s
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
4eda3da75d
commit
6fc2d001b2
1 file changed
+6
-4
+6
-4
@@ -300,7 +300,7 @@ restore system (JSON mostly, plus the files).
|
|||||||
| Protection | **Plain archives, protected by file permissions** (`/var/lib/privapub/backups`, 2770, files 0640). No encryption. |
|
| Protection | **Plain archives, protected by file permissions** (`/var/lib/privapub/backups`, 2770, files 0640). No encryption. |
|
||||||
| Consistency | **Production's mongod becomes a one-member replica set** (`rs0`), so a backup reads every collection at one instant. `setup.sh` converts it, which needs a planned restart of mongod. |
|
| Consistency | **Production's mongod becomes a one-member replica set** (`rs0`), so a backup reads every collection at one instant. `setup.sh` converts it, which needs a planned restart of mongod. |
|
||||||
|
|
||||||
**Done 2026-10-07 (committed, not deployed):**
|
**Done and deployed 2026-10-07 (v1.23.0, decePub v1.5.0):**
|
||||||
- media: files live exactly as long as something holds them (trash with a day's grace, janitor), finite focal points,
|
- media: files live exactly as long as something holds them (trash with a day's grace, janitor), finite focal points,
|
||||||
pictures checked before they are decoded, audio and video bounded and processed off the request, a bounded media
|
pictures checked before they are decoded, audio and video bounded and processed off the request, a bounded media
|
||||||
proxy, scheduled posts' media reserved, profile pictures as rows with `DELETE`, edits that reach the post, storage
|
proxy, scheduled posts' media reserved, profile pictures as rows with `DELETE`, edits that reach the post, storage
|
||||||
@@ -310,9 +310,11 @@ restore system (JSON mostly, plus the files).
|
|||||||
- a persona's archive, exported and imported (`tools/pasture/scenarios/persona-archive.sh` imports a real Mastodon
|
- a persona's archive, exported and imported (`tools/pasture/scenarios/persona-archive.sh` imports a real Mastodon
|
||||||
archive: 156 posts, nothing delivered).
|
archive: 156 posts, nothing delivered).
|
||||||
|
|
||||||
**At the next deploy, in this order:** `setup.sh` (the replica set, the backups directory, the runner in www-data's
|
**Deployed 2026-10-07, in this order:** `setup.sh` (production's mongod is now the replica set `rs0`; the backups
|
||||||
group, the nginx locations), the deploy, `PrivaPub admin media audit` and, once its report is read, `--fix`; and the
|
directory; the nginx locations), then v1.23.0, whose own pre-deploy backup was verified whole, then decePub v1.5.0.
|
||||||
owner's word on deleting the old pre-deploy dumps, which hold statistics salts.
|
`PrivaPub admin media audit` found no media on production, so there was nothing to fix. The seven pre-deploy mongodumps,
|
||||||
|
which held statistics salts, were deleted (owner's go-ahead); a salt-free dump taken just before the replica-set
|
||||||
|
conversion is kept in `/var/backups/privapub.thepra.dev/`.
|
||||||
|
|
||||||
## Libraries (researched; no maintained .NET ActivityPub library exists, so Letterbook and Iceshrimp.NET both wrote their own)
|
## Libraries (researched; no maintained .NET ActivityPub library exists, so Letterbook and Iceshrimp.NET both wrote their own)
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user