diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index 716c77d..c10982a 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -57,10 +57,17 @@ jobs: echo "SNAPSHOT=$BACKUPS/site-$STAMP" >> "$GITHUB_ENV" ls -1dt "$BACKUPS"/site-* 2>/dev/null | tail -n +4 | xargs -r rm -rf || true + # without the statistics salt, which must not outlive its day (owner rule: it is destroyed at each rollup, and a dump + # kept for days would let the day's actor hashes be reversed) - name: Dump the database run: | DUMP="$BACKUPS/mongo-$(date +%Y%m%d-%H%M%S).archive.gz" - mongodump --quiet --uri "$MONGO_URI" --db "$MONGO_DB" --gzip --archive="$DUMP" + mongodump --quiet --uri "$MONGO_URI" --db "$MONGO_DB" --excludeCollection=InteractionSalt --gzip --archive="$DUMP" + if mongorestore --gzip --archive="$DUMP" --dryRun -v 2>&1 | grep -q "InteractionSalt"; then + rm -f "$DUMP" + echo "::error::the dump holds the statistics salt" + exit 1 + fi echo "::notice::database dumped to $DUMP ($(du -h "$DUMP" | cut -f1))" ls -1t "$BACKUPS"/mongo-*.archive.gz 2>/dev/null | tail -n +8 | xargs -r rm -f || true diff --git a/CLAUDE.md b/CLAUDE.md index aa0b71f..8af9316 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -779,7 +779,8 @@ the owner's GoToSocial account.** ## Deploy - **CI/CD:** push to `master` runs `build.yml` (build + tests) on the instance-wide `build` runner. A `v*` tag runs - `deploy.yml`: tests, self-contained linux-x64 publish, snapshot and `mongodump` to `/var/backups/privapub.thepra.dev`, + `deploy.yml`: tests, self-contained linux-x64 publish, snapshot and `mongodump` to `/var/backups/privapub.thepra.dev` + (never the statistics salt: `InteractionSalt` is excluded and the dump is checked for it), stop → rsync → start, a `127.0.0.1:6970/build.json` health loop with rollback, then public checks (actor, NodeInfo, Swagger 404, inbox junk 400, unsigned 401) and `tools/smoke/mastodon-api.sh` (app registration, client credentials, discovery, instance, public timeline). Then it checks that what production should be running is running: