feat(deploy-backup): verify database backup restores - #365
Draft
Adamskiee wants to merge 5 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
Closes #338.
Adds scheduled restore verification for the newest finalized SAPOT MariaDB backup. Each run inspects the dump, restores it into disposable isolated storage, validates schema and row counts, publishes sanitized state, and removes run-scoped resources.
What changed
--dry-run,--status, cleanup handling, and thedb-backup-restoredoctor checkImpact
Operators gain evidence that the newest backup is restorable, separate from the existing backup freshness check. The manual production restore procedure and backup artifact format remain unchanged.
Validation
deploy/scripts/tests/run-tests.sh(19 Bash tests and 3 Python tests)bash -n deploy/scripts/verify-db-backup.shbash -n deploy/scripts/doctor.shpython3 -m py_compile deploy/scripts/lib/dump-inspector.py deploy/scripts/lib/verification-state.pysystemd-analyze verify deployment-scripts/sapot-db-backup.service deployment-scripts/sapot-db-backup.timer deployment-scripts/sapot-db-backup-verify.service deployment-scripts/sapot-db-backup-verify.timergit diff --checksystemd-analyzealso reported the host unrelated missingnix-daemon.socketand noted thatRuntimeMaxSecis ignored for a oneshot service.