The deploy's dump leaves out the statistics salt
The pre-deploy mongodump kept InteractionSalt, the day's salt that the owner decided must be destroyed at each rollup: a dump kept seven deploys long let the day's actor hashes be reversed. It is excluded now, and the deploy refuses a dump that still names it (mongorestore's dry run lists every collection). The dumps already on the box still hold old salts; removing them waits for the owner. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
6f240828cf
commit
8492f24064
2 files changed
+10
-2
No files matched your search
@@ -57,10 +57,17 @@ jobs:
|
||||
echo "SNAPSHOT=$BACKUPS/site-$STAMP" >> "$GITHUB_ENV"
|
||||
ls -1dt "$BACKUPS"/site-* 2>/dev/null | tail -n +4 | xargs -r rm -rf || true
|
||||
|
||||
# without the statistics salt, which must not outlive its day (owner rule: it is destroyed at each rollup, and a dump
|
||||
# kept for days would let the day's actor hashes be reversed)
|
||||
- name: Dump the database
|
||||
run: |
|
||||
DUMP="$BACKUPS/mongo-$(date +%Y%m%d-%H%M%S).archive.gz"
|
||||
mongodump --quiet --uri "$MONGO_URI" --db "$MONGO_DB" --gzip --archive="$DUMP"
|
||||
mongodump --quiet --uri "$MONGO_URI" --db "$MONGO_DB" --excludeCollection=InteractionSalt --gzip --archive="$DUMP"
|
||||
if mongorestore --gzip --archive="$DUMP" --dryRun -v 2>&1 | grep -q "InteractionSalt"; then
|
||||
rm -f "$DUMP"
|
||||
echo "::error::the dump holds the statistics salt"
|
||||
exit 1
|
||||
fi
|
||||
echo "::notice::database dumped to $DUMP ($(du -h "$DUMP" | cut -f1))"
|
||||
ls -1t "$BACKUPS"/mongo-*.archive.gz 2>/dev/null | tail -n +8 | xargs -r rm -f || true
|
||||
|
||||
|
||||
Reference in new issue
Block a user