controller v0.69.0: remove dead infra-backup stubs + unused restic-password report field

Controller half of Phase-1 Infra Backup retirement (hub v0.12.0;
SPIKE-infra-backup-2026-06-15). Pure dead-code removal, no behaviour change.

- Remove Pusher.PushInfraBackup (caller-less; hub endpoint gone).
- Remove Notifier.NotifyBackupCompleted / backup_completed event (caller-less
  since slice 8C; hub deadline check now reads agent host-report PBS snapshots).
- Remove report.BackupReport.ResticPassword — builder never sets it post-8C
  (confirmed in source + live), but it historically leaked the restic password
  into the hub's plaintext reports store.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-16 11:11:56 +02:00
parent 3793c73c5d
commit 9f59bc2146
5 changed files with 36 additions and 57 deletions
+2 -49
View File
@@ -142,55 +142,8 @@ func (p *Pusher) GetStatus() PushStatus {
return p.status
}
// PushInfraBackup sends the infrastructure backup payload to the Hub.
// Uses the same retry logic as Push.
func (p *Pusher) PushInfraBackup(data []byte) error {
if !p.enabled {
return nil
}
url := p.hubURL + "/api/v1/infra-backup"
if p.debug {
p.logger.Printf("[DEBUG] [report] PushInfraBackup: url=%s payload=%d bytes", url, len(data))
}
var lastErr error
for attempt := 0; attempt < 3; attempt++ {
if attempt > 0 {
time.Sleep(5 * time.Second)
}
req, err := http.NewRequest(http.MethodPost, url, bytes.NewReader(data))
if err != nil {
lastErr = err
continue
}
req.Header.Set("Content-Type", "application/json")
if p.apiKey != "" {
req.Header.Set("Authorization", "Bearer "+p.apiKey)
}
resp, err := p.httpClient.Do(req)
if err != nil {
lastErr = err
continue
}
io.Copy(io.Discard, resp.Body)
resp.Body.Close()
if resp.StatusCode >= 200 && resp.StatusCode < 300 {
p.logger.Printf("[INFO] [report] Infra backup pushed to Hub (%d bytes)", len(data))
return nil
}
lastErr = fmt.Errorf("HTTP %d", resp.StatusCode)
if p.debug {
p.logger.Printf("[DEBUG] [report] PushInfraBackup: attempt %d failed — HTTP %d", attempt+1, resp.StatusCode)
}
}
p.logger.Printf("[WARN] [report] InfraBackup push failed: %v", lastErr)
return fmt.Errorf("infra backup push failed after 3 attempts: %w", lastErr)
}
// (PushInfraBackup removed 2026-06-16 — the infra-backup mechanism was retired hub-side.
// It was dead since slice 8C, had no callers, and pushed plaintext secrets to the hub.)
// PushOnce sends a single report regardless of the enabled flag.
// Used for one-time notifications (e.g., reporting-disabled on startup).
+2 -1
View File
@@ -82,7 +82,8 @@ type BackupReport struct {
RepoSizeMB int64 `json:"repo_size_mb"`
LastIntegrityCheck *time.Time `json:"last_integrity_check,omitempty"`
IntegrityOK bool `json:"integrity_ok"`
ResticPassword string `json:"restic_password,omitempty"`
// (ResticPassword removed 2026-06-16 — the live builder never set it post-slice-8C;
// historically it leaked the restic password into the hub's plaintext report store.)
}
// HealthReport holds the aggregated health status.