The deploy's dump leaves out the statistics salt
The pre-deploy mongodump kept InteractionSalt, the day's salt that the owner decided must be destroyed at each rollup: a dump kept seven deploys long let the day's actor hashes be reversed. It is excluded now, and the deploy refuses a dump that still names it (mongorestore's dry run lists every collection). The dumps already on the box still hold old salts; removing them waits for the owner. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
6f240828cf
commit
8492f24064
2 files changed
+10
-2
No files matched your search
@@ -779,7 +779,8 @@ the owner's GoToSocial account.**
|
||||
## Deploy
|
||||
|
||||
- **CI/CD:** push to `master` runs `build.yml` (build + tests) on the instance-wide `build` runner. A `v*` tag runs
|
||||
`deploy.yml`: tests, self-contained linux-x64 publish, snapshot and `mongodump` to `/var/backups/privapub.thepra.dev`,
|
||||
`deploy.yml`: tests, self-contained linux-x64 publish, snapshot and `mongodump` to `/var/backups/privapub.thepra.dev`
|
||||
(never the statistics salt: `InteractionSalt` is excluded and the dump is checked for it),
|
||||
stop → rsync → start, a `127.0.0.1:6970/build.json` health loop with rollback, then public checks (actor, NodeInfo,
|
||||
Swagger 404, inbox junk 400, unsigned 401) and `tools/smoke/mastodon-api.sh` (app registration, client credentials,
|
||||
discovery, instance, public timeline). Then it checks that what production should be running is running:
|
||||
|
||||
Reference in new issue
Block a user