A backup is restored at boot, and never undoes a protective act

PrivaPub admin restore <id> (and soon the administrator's page) checks the backup (same host, a format and newest
migration this build reads, every hash) and writes restore.json; the running service sees it within seconds and stops,
and the next start restores it in MaintenanceGate, before migrations, indexes and hosted services: a pre-restore backup
taken once, every collection dropped and imported raw with its indexes, the media the live directory lacks brought
back, then the protective merge from the pre-restore backup. Followers and follows are the live ones; blocks, mutes,
domain blocks, reserved names, tombstones, reports, filters and OAuth applications are the union; deletions win;
accounts made since become tombstones and local posts made since answer 410; every session ends.

Each attempt redoes everything; one refused before any change is abandoned and recorded, one failed midway exits 1 for
systemd to retry, and after three it exits 75, which the unit no longer restarts. Commands wait (exit 75) while a
restore is pending. RestoreRecord tells what happened (admin restore --status).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-07 11:55:17 +02:00
1 parent 12bb75809f
commit fba57318fa
13 files changed
+1050 -11

No files matched your search

+10 -1
View File
@@ -71,6 +71,7 @@ try
.Configure<PrivaPub.Infrastructure.Backup.BackupOptions>(builder.Configuration.GetSection("Backups"))
.AddSingleton<PrivaPub.Infrastructure.Backup.Backups>()
.AddHostedService<PrivaPub.Infrastructure.Backup.BackupScheduler>()
.AddHostedService<PrivaPub.Infrastructure.Backup.RestoreWatcher>()
.PrivaPubMiddlewareConfiguration();
}
catch (Exception ex)
@@ -107,9 +108,17 @@ try
throw;
}
// A restore asked for runs here, before migrations, indexes and every hosted service; a command waits for it.
var gate = await PrivaPub.Infrastructure.Backup.MaintenanceGate.Enter(app.Services, args is ["admin", .. var asked] ? asked : default, CancellationToken.None);
if (gate is { } stop)
{
Environment.ExitCode = stop;
return;
}
// Commands get every service but start nothing: no Kestrel, no hosted services, no media directory. The deploy runs
// them as its own user, which can read the configuration and reach the private mongod but owns no www-data directory.
// Backups are taken before migrations: the deploy's is of the database as the live build left it.
// Backups and restores are asked for before migrations: the deploy's backup is of the database as the live build left it.
if (args is ["admin", .. var command] && AdminCommands.BeforeMigrations(command))
{
using var scope = app.Services.CreateScope();