v0.6.0-rc1: slice 6 Phase A — backup + the self-restore-test (local target)
The guest-level backup layer + the journaled self-restore-test (restore→boot→verify→ teardown) that closes "a backup you haven't restored isn't a backup". All benign (reuses the slice-4 classifier/gate/journal; no new destructive class/crypto). Local target only; PBS = Phase B. Restore to a NEW guest only. Backups crash-consistent. - proxmox: DestroyLXC, VzdumpOptions.Notes (notes-template), LatestBackupVolID. - reconcile: Engine.RunRestoreTest (journal Scratch entry BEFORE mutation; net link-down pre-boot; defer teardown always; benign gated destroy) + Recover extended to reap a leaked scratch guest (Scratch flag, special-cased before the UPID path; idempotent). - internal/backup: runner (vzdump + archive resolve + bulk-gap = backup!=1) + cadence scheduler (4th daemon goroutine, default 24h) + in-memory report store. - hub: Backup/RestoreTest filled; collector seams; cross-repo golden byte-identical + bidirectional key-set tests; hub handler logs a FAILED restore-test prominently. - config BackupConfig (band 990000-990009 default); --selftest=backup / restore-test. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -61,10 +61,14 @@ type VzdumpOptions struct {
|
||||
Storage string // a storage whose content includes "backup" (e.g. "local") — NOT local-lvm
|
||||
Mode BackupMode // ModeStop | ModeSnapshot
|
||||
Compress string // "zstd" (default), "lzo", "gzip", or "" for none
|
||||
// Notes is the PVE `notes-template` for the backup (a template string PVE expands,
|
||||
// e.g. with {{guestname}}/{{node}}). Optional.
|
||||
Notes string
|
||||
}
|
||||
|
||||
// Vzdump starts a backup via POST /nodes/{node}/vzdump. Returns the UPID. An
|
||||
// agent-initiated vzdump is crash-consistent only for an LXC (no fsfreeze).
|
||||
// agent-initiated vzdump is crash-consistent only for an LXC (no fsfreeze) —
|
||||
// app-consistency needs the controller to quiesce first (slice 8).
|
||||
func (c *Client) Vzdump(ctx context.Context, opts VzdumpOptions) (string, error) {
|
||||
if opts.VMID == 0 || opts.Storage == "" || opts.Mode == "" {
|
||||
return "", fmt.Errorf("proxmox: Vzdump needs vmid, storage and mode")
|
||||
@@ -77,9 +81,28 @@ func (c *Client) Vzdump(ctx context.Context, opts VzdumpOptions) (string, error)
|
||||
opts.Compress = "zstd"
|
||||
}
|
||||
v.Set("compress", opts.Compress)
|
||||
if opts.Notes != "" {
|
||||
v.Set("notes-template", opts.Notes) // PVE 9.x param name (verified on demo)
|
||||
}
|
||||
return c.dataString(ctx, http.MethodPost, "/nodes/"+c.node+"/vzdump", v)
|
||||
}
|
||||
|
||||
// DestroyLXC destroys a guest via DELETE /nodes/{node}/lxc/{vmid}. Returns the UPID.
|
||||
// `purge=1` also drops the guest from jobs/HA; `destroy-unreferenced-disks=1` reaps any
|
||||
// orphaned volumes. This is the scratch-guest teardown primitive (slice 6); it is
|
||||
// destructive-class and the caller MUST route it through the reversibility gate
|
||||
// (benign only by agent-internal scratch/same-txn provenance — see reconcile.Classify).
|
||||
func (c *Client) DestroyLXC(ctx context.Context, vmid int) (string, error) {
|
||||
if vmid == 0 {
|
||||
return "", fmt.Errorf("proxmox: DestroyLXC needs a vmid")
|
||||
}
|
||||
v := url.Values{}
|
||||
v.Set("purge", "1")
|
||||
v.Set("destroy-unreferenced-disks", "1")
|
||||
path := fmt.Sprintf("/nodes/%s/lxc/%d", c.node, vmid)
|
||||
return c.dataString(ctx, http.MethodDelete, path, v)
|
||||
}
|
||||
|
||||
// Snapshot creates an LXC snapshot via POST /nodes/{node}/lxc/{vmid}/snapshot.
|
||||
// A running, unprivileged LXC can be snapshotted on LVM-thin with no stop
|
||||
// (phase1-2 §1.6) — this is the snapshot-before-change primitive.
|
||||
|
||||
Reference in New Issue
Block a user