82c67e32e1
ONE setting (window start W) drives every nightly leg at fixed, never-stored offsets: DB dump at W, tier-2 at W+60m, off-box at W+105m (wrap-safe). Precedence settings > controller.yaml db_dump_schedule > 02:30. - scheduler.UpdateDaily: retime a daily job at runtime (no restart) via a per-job buffered resched chan + a select case in runDailyJob. - new pure package internal/backupwindow (LegTimes/GateWindow/EffectiveWindow). - quiesce disk-tier window gate: scheduled cycles run only inside [W+2h,W+6h) with a safety valve (age>cadence+24h runs regardless); manual TriggerNow never gated. Backend.Due now also returns the backup age (from the agent's own /backup/due). - backup page: Mentési időablak card (time input + derived leg/gate rows); POST /backups/window validates -> saves -> UpdateDaily x3 -> flash. Tests: 5 groups, all red-proofed. Agent/cadence//backup/due untouched.
239 lines
9.5 KiB
Go
239 lines
9.5 KiB
Go
package web
|
||
|
||
import (
|
||
"context"
|
||
"errors"
|
||
"net/http"
|
||
"net/url"
|
||
"strings"
|
||
"time"
|
||
|
||
"gitea.dooplex.hu/admin/felhom-controller/internal/agentapi"
|
||
"gitea.dooplex.hu/admin/felhom-controller/internal/backupwindow"
|
||
"gitea.dooplex.hu/admin/felhom-controller/internal/quiesce"
|
||
"gitea.dooplex.hu/admin/felhom-controller/internal/scheduler"
|
||
)
|
||
|
||
// effectiveBackupWindow resolves the active backup-window start (settings > controller.yaml >
|
||
// "02:30") for this server. Every nightly-leg display and the DB-dump next-run derive from it.
|
||
func (s *Server) effectiveBackupWindow() string {
|
||
return backupwindow.EffectiveWindow(s.settings.GetBackupWindowStart(), s.cfg.Backup.DBDumpSchedule)
|
||
}
|
||
|
||
// backupWindowData injects the customer-configurable-window view onto the Áttekintés page: the
|
||
// effective start, the three derived leg times (DB / helyi másolat / távoli mentés), and the
|
||
// whole-guest gate span [W+2h, W+6h). The offsets are DERIVED here, never stored.
|
||
func (s *Server) backupWindowData(data map[string]interface{}) {
|
||
win := s.effectiveBackupWindow()
|
||
db, tier2, offbox := backupwindow.LegTimes(win)
|
||
from, to := backupwindow.GateWindow(win)
|
||
data["BackupWindow"] = win
|
||
data["BackupLegDB"] = db
|
||
data["BackupLegTier2"] = tier2
|
||
data["BackupLegOffbox"] = offbox
|
||
data["BackupGateFrom"] = from
|
||
data["BackupGateTo"] = to
|
||
}
|
||
|
||
// backupWindowSaveHandler persists a new backup-window start and fans it out to the three daily legs
|
||
// live (no restart) via UpdateDaily. POST /backups/window (behind RequireAuth + CsrfProtect). On an
|
||
// invalid time nothing is stored and the jobs are untouched.
|
||
func (s *Server) backupWindowSaveHandler(w http.ResponseWriter, r *http.Request) {
|
||
_ = r.ParseForm()
|
||
start := strings.TrimSpace(r.FormValue("window_start"))
|
||
if backupwindow.Valid(start) != nil {
|
||
s.backupWindowRedirect(w, r, "", "Érvénytelen időpont. Használja a ÓÓ:PP formátumot (például 02:30).")
|
||
return
|
||
}
|
||
if err := s.settings.SetBackupWindowStart(start); err != nil {
|
||
s.logger.Printf("[ERROR] [web] backup window save failed: %v", err)
|
||
s.backupWindowRedirect(w, r, "", "A mentési időablak mentése nem sikerült.")
|
||
return
|
||
}
|
||
// Fan out to the three daily legs at their fixed offsets — takes effect at the next scheduling
|
||
// pass (no restart). The scheduler wakes each job via its reschedule signal.
|
||
db, tier2, offbox := backupwindow.LegTimes(start)
|
||
if s.scheduler != nil {
|
||
s.scheduler.UpdateDaily("db-dump", db)
|
||
s.scheduler.UpdateDaily("tier2-backup", tier2)
|
||
s.scheduler.UpdateDaily("offbox-backup", offbox)
|
||
}
|
||
// Refresh the cached "next DB dump" so the display updates immediately, not at the next 5m tick.
|
||
if s.backupMgr != nil {
|
||
s.backupMgr.RefreshCache(scheduler.NextDailyRun(db))
|
||
}
|
||
s.logger.Printf("[INFO] [web] backup window set to %s (legs %s/%s/%s)", start, db, tier2, offbox)
|
||
s.backupWindowRedirect(w, r, "Mentési időablak frissítve.", "")
|
||
}
|
||
|
||
// backupWindowRedirect PRG-redirects back to the Áttekintés page with a success or error flash.
|
||
func (s *Server) backupWindowRedirect(w http.ResponseWriter, r *http.Request, flash, flashErr string) {
|
||
dest := "/backups"
|
||
if flashErr != "" {
|
||
dest += "?flash_error=" + url.QueryEscape(flashErr)
|
||
} else if flash != "" {
|
||
dest += "?flash=" + url.QueryEscape(flash)
|
||
}
|
||
http.Redirect(w, r, dest, http.StatusSeeOther)
|
||
}
|
||
|
||
// Whole-guest backup visibility + manual trigger (spec Part 2). The agent owns whole-guest
|
||
// vzdump/PBS backup; the controller is a read-only window onto it (GET /backup/{status,due},
|
||
// /restore-test/status) plus a "Mentés most" trigger that goes through the quiesce loop (the
|
||
// CONTROLLER owns quiescing — stop stacks → POST /backup → resume — so the captured state is
|
||
// app-consistent, not the agent's crash-consistent default). Cadence/retention CONFIG is NOT here
|
||
// (hub-served policy, slice 10).
|
||
|
||
// guestBackupView is the template payload for the "Rendszermentés" section. Times are time.Time so
|
||
// the existing fmtTime/timeAgo funcmap helpers format them; size is int64 for fmtBytes.
|
||
type guestBackupView struct {
|
||
Available bool // agent reachable + a status read succeeded
|
||
Note string // shown when not Available (unprovisioned / unreachable)
|
||
|
||
Phase string // idle | running | snapshotted | done | failed
|
||
Running bool // a backup job is in progress now
|
||
|
||
HasBackup bool
|
||
Success bool
|
||
StartedAt time.Time
|
||
SizeBytes int64
|
||
Target string // human label: "Biztonsági szerver – külön hardver (PBS)" / "Helyi tároló (local)"
|
||
Offsite bool // the whole-guest backup landed on the PBS offsite tier (separate hardware)
|
||
Archive string
|
||
Mode string // snapshot | stop
|
||
StopMode bool // mode == stop → full app downtime during the backup (warn)
|
||
|
||
Due bool
|
||
DueReason string
|
||
AgeHours int64 // age of the newest successful backup, hours (for "X órája")
|
||
|
||
HasRestoreTest bool
|
||
RestorePass bool
|
||
RestoreVerified string
|
||
RestoreTestedAt time.Time
|
||
|
||
CanTrigger bool // a backup trigger (quiesce loop) is wired
|
||
}
|
||
|
||
// loadGuestBackup fetches the agent's whole-guest backup view (best-effort). Returns a view with
|
||
// Available=false (+ a note) when the agent isn't configured/reachable — the page still renders.
|
||
func (s *Server) loadGuestBackup(ctx context.Context) *guestBackupView {
|
||
v := &guestBackupView{CanTrigger: s.backupTrigger != nil}
|
||
client, err := s.agentClient()
|
||
if err != nil {
|
||
v.Note = "A host-ügynök nincs konfigurálva ezen a gépen."
|
||
return v
|
||
}
|
||
st, err := client.BackupStatus(ctx)
|
||
if err != nil {
|
||
v.Note = "A host-ügynök jelenleg nem elérhető."
|
||
return v
|
||
}
|
||
v.Available = true
|
||
v.Phase = st.Phase
|
||
v.Running = st.Phase == agentapi.PhaseRunning || st.Phase == "snapshotted"
|
||
if st.Backup != nil {
|
||
v.HasBackup = true
|
||
v.Success = st.Backup.Success
|
||
v.SizeBytes = st.Backup.SizeBytes
|
||
v.Archive = st.Backup.Archive
|
||
v.Mode = st.Backup.Mode
|
||
v.StopMode = st.Backup.Mode == "stop"
|
||
v.Target = backupTargetLabel(st.Backup)
|
||
v.Offsite = backupIsPBS(st.Backup)
|
||
if t, perr := time.Parse(time.RFC3339, st.Backup.StartedAt); perr == nil {
|
||
v.StartedAt = t
|
||
}
|
||
}
|
||
// Due window (best-effort; a failure just leaves the due fields zero).
|
||
if due, derr := client.BackupDue(ctx); derr == nil {
|
||
v.Due = due.Due
|
||
v.DueReason = due.Reason
|
||
if due.AgeSecs != nil {
|
||
v.AgeHours = *due.AgeSecs / 3600
|
||
}
|
||
}
|
||
// Restore-test (the "verified restorable" trust signal; nil until one runs).
|
||
if rt, rerr := client.RestoreTestStatus(ctx); rerr == nil && rt != nil {
|
||
v.HasRestoreTest = true
|
||
v.RestorePass = rt.Pass
|
||
v.RestoreVerified = rt.Verified
|
||
if t, perr := time.Parse(time.RFC3339, rt.TestedAt); perr == nil {
|
||
v.RestoreTestedAt = t
|
||
}
|
||
}
|
||
return v
|
||
}
|
||
|
||
// backupIsPBS reports whether a whole-guest backup landed on the PBS offsite tier (separate
|
||
// hardware), inferred from the target id / archive volid ("felhom-pbs"/"pbs:" ⇒ PBS).
|
||
func backupIsPBS(b *agentapi.BackupRecord) bool {
|
||
id := strings.ToLower(b.TargetID)
|
||
arc := strings.ToLower(b.Archive)
|
||
return strings.Contains(id, "pbs") || strings.HasPrefix(arc, "felhom-pbs") || strings.Contains(arc, "pbs:")
|
||
}
|
||
|
||
// backupTargetLabel maps the agent's backup target to a customer-facing Hungarian label. The PBS
|
||
// case calls out that the backup is on SEPARATE HARDWARE (real disaster recovery — survives a host
|
||
// disk/hardware failure), which is the whole point of re-pointing the backup offsite.
|
||
func backupTargetLabel(b *agentapi.BackupRecord) string {
|
||
if backupIsPBS(b) {
|
||
return "Biztonsági szerver – külön hardver (PBS)"
|
||
}
|
||
if b.TargetID != "" {
|
||
return "Helyi tároló (" + b.TargetID + ")"
|
||
}
|
||
return "Helyi tároló"
|
||
}
|
||
|
||
// ServeBackupAPI dispatches /api/guest-backup/* (whole-guest manual trigger + status poll). A
|
||
// distinct prefix from apiRouter's app-data /api/backup/{run,status}. Wired behind RequireAuth +
|
||
// CsrfProtect in main.go.
|
||
func (s *Server) ServeBackupAPI(w http.ResponseWriter, r *http.Request) {
|
||
switch {
|
||
case r.URL.Path == "/api/guest-backup/trigger" && r.Method == http.MethodPost:
|
||
s.handleBackupTriggerAPI(w, r)
|
||
case r.URL.Path == "/api/guest-backup/status" && r.Method == http.MethodGet:
|
||
s.handleBackupStatusAPI(w, r)
|
||
default:
|
||
http.NotFound(w, r)
|
||
}
|
||
}
|
||
|
||
// handleBackupTriggerAPI starts an app-consistent whole-guest backup NOW via the quiesce loop. It
|
||
// returns immediately (the backup runs async, minutes); the page polls /api/backup/status.
|
||
func (s *Server) handleBackupTriggerAPI(w http.ResponseWriter, r *http.Request) {
|
||
if s.backupTrigger == nil {
|
||
writeDiskJSON(w, http.StatusServiceUnavailable, false, "a rendszermentés nem érhető el ezen a gépen", nil)
|
||
return
|
||
}
|
||
if err := s.backupTrigger.TriggerNow(); err != nil {
|
||
if errors.Is(err, quiesce.ErrBackupInProgress) {
|
||
writeDiskJSON(w, http.StatusConflict, false, "mentés már folyamatban van", nil)
|
||
return
|
||
}
|
||
s.logger.Printf("[ERROR] [web] backup trigger failed: %v", err)
|
||
writeDiskJSON(w, http.StatusBadGateway, false, err.Error(), nil)
|
||
return
|
||
}
|
||
s.logger.Printf("[INFO] [web] manual whole-guest backup triggered (quiesce loop)")
|
||
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{"started": true})
|
||
}
|
||
|
||
// handleBackupStatusAPI proxies the agent's GET /backup/status for the page's progress poll.
|
||
func (s *Server) handleBackupStatusAPI(w http.ResponseWriter, r *http.Request) {
|
||
client, err := s.agentClient()
|
||
if err != nil {
|
||
writeDiskJSON(w, http.StatusServiceUnavailable, false, err.Error(), nil)
|
||
return
|
||
}
|
||
st, err := client.BackupStatus(r.Context())
|
||
if err != nil {
|
||
writeDiskJSON(w, http.StatusBadGateway, false, err.Error(), nil)
|
||
return
|
||
}
|
||
writeDiskJSON(w, http.StatusOK, true, "", map[string]any{
|
||
"phase": st.Phase, "job_id": st.JobID, "error": st.Error, "backup": st.Backup,
|
||
})
|
||
}
|