Files
felhom-controller/REPORT.md
T
2026-06-16 11:16:23 +02:00

3.1 KiB

REPORT — controller v0.69.0: remove dead infra-backup stubs + unused restic-password report field (2026-06-16)

Deployed: controller v0.69.0 on guest 9201 / felhom-pve (bootstrap-managed; healthy, hub-reporting OK). Scope: controller half of Phase-1 Infra Backup retirement (hub v0.12.0). See felhom.eu/documentation/audits/SPIKE-infra-backup-2026-06-15.md. Commit 9f59bc2.

What changed (pure dead-code removal — no behaviour change)

  • Removed report.Pusher.PushInfraBackup (internal/report/pusher.go) — pushed the infra-backup payload to the now-removed hub endpoint POST /api/v1/infra-backup. Dead since slice 8C; no callers.
  • Removed notify.Notifier.NotifyBackupCompleted (internal/notify/notifier.go) and the backup_completed event — caller-less since whole-guest backup moved to the agent in slice 8C. The hub's backup-deadline check now reads the agent host-report's PBS snapshots instead. NotifyBackupFailed and the DB-dump notifiers are untouched and still used.
  • Removed report.BackupReport.ResticPassword (internal/report/types.go, json:"restic_password").

STEP-2 gate — confirmed before removing ResticPassword

The task required proving the live builder leaves ResticPassword empty (else it would be an ongoing restic-password leak to the hub). Confirmed two ways:

  • Source: buildBackupReport (internal/report/builder.go) constructs BackupReport{Enabled:…} + LastDBDump only; the comment at the disk-tier seam states restic/snapshot fields are left zero. No code anywhere assigns BackupReport.ResticPassword.
  • Live data (hub DB, read-only): the latest controller reports (v0.68.3) carry no restic_password field at all. So no ongoing leak — safe to remove.

Flagged (separate, worse historical finding — not in this task's scope): the hub's legacy reports table holds thousands of historical rows with a plaintext restic_password value from old controller versions that DID populate it. The current controller does not, and this removal makes the field structurally unsendable, but the historical rows persist on the hub — a distinct purge/rotation decision for the operator.

Verification

  • go build ./... && go test ./... — green; go vet clean. No residual references to PushInfraBackup / NotifyBackupCompleted / BackupReport.ResticPassword (the config.go ResticPasswordFile is the separate restic-password-file path config, intentionally untouched).
  • Built felhom-controller:0.69.0, deployed to guest 9201 via the bootstrap mechanism (docker pull/etc/felhom-controller-image → restart felhom-controller-bootstrap.service).
  • Live: container Up … (healthy) on 0.69.0; startup clean (no errors/panics); hub connectivity HTTP 200; Hub report pushed successfully (8309 bytes) — confirming the caller-less removal causes no behaviour change and reporting still works.

Out of scope

Credential rotation (operator); the historical reports-table restic_password rows (flagged above); the Komga healthcheck.