Evidence: the first full monthly re-test (decision 55) — nextcloud and sonarr re-tested and written; runbook: every app by default, the standing brief
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,11 +1,16 @@
|
||||
# RUNBOOK — the monthly re-test of same-name security fixes (`09` §3 decision 52, R-740)
|
||||
# RUNBOOK — the monthly re-test of same-name security fixes (`09` §3 decisions 52, 54, 55; R-740, R-743)
|
||||
|
||||
**What it does.** An image such as `postgres:18-alpine` or `redis:7-alpine` gets security fixes under the SAME name.
|
||||
A box takes such a fix at night only when the catalog has re-tested the tag at the new digest on both venues and written
|
||||
it as a ladder step. This runbook is that re-test, once a month. **One command does the work**; the steps around it set
|
||||
up the two venues and tear them down.
|
||||
|
||||
**Who runs it:** a person or a CC session, from DooPlex, once a month (the operator decides who presses — STATUS).
|
||||
**Scope (decision 55):** every app with a proven ladder — not only the database and redis lines. The web apps face the
|
||||
internet; the databases do not. `--engines-only` is the narrow switch, not the default.
|
||||
|
||||
**Who runs it (decision 54):** a CC session the operator starts once a month with the standing brief
|
||||
`claude/MONTHLY-security-retest.md` (in the planning project), from DooPlex. STATUS carries "Monthly security re-test:
|
||||
last run <date>, next due <date>" — update it at the end of every run.
|
||||
**Why not a cron job (measured 2026-09-30):** it needs a fresh bench LXC on demo-hp, scratch guest 9202 pointed at the
|
||||
drill catalog, a drill reset (a force-push — the permission check refused it once and the operator allowed it), and pushes
|
||||
to the LIVE catalog. None of that should happen with nobody watching.
|
||||
@@ -14,16 +19,16 @@ to the LIVE catalog. None of that should happen with nobody watching.
|
||||
|
||||
```bash
|
||||
cd /mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu && git pull -q
|
||||
python3 scripts/retest-floating.py --dry-run --engines-only # the ruled start: database and redis lines
|
||||
python3 scripts/retest-floating.py --dry-run # everything, for the record
|
||||
python3 scripts/retest-floating.py --dry-run # every app with a proven ladder (decision 55)
|
||||
```
|
||||
|
||||
`nothing to re-test today` ends the month. Otherwise go on.
|
||||
|
||||
## 2. The bench (LXC 9401 on demo-hp)
|
||||
|
||||
The recipe in `audits/more-night-apps-2026-09-30/bench/B1-bench-create.txt` (60 GB disk — 40 GB filled up on 2026-09-30),
|
||||
swap 0 (the stricter venue, R-733). `retest-floating.py` syncs the catalog's scripts and templates to it itself.
|
||||
The recipe in `audits/rulings-2026-10-01/A/A1-bench-create.txt` (60 GB disk on `nvme-scratch` — 40 GB filled up on
|
||||
2026-09-30), swap 0 (the stricter venue, R-733); `pveam download` the Debian 13 template first if it is gone.
|
||||
`retest-floating.py` syncs the catalog's scripts and templates to it itself (it checks only docker + python3 first, R-749).
|
||||
|
||||
## 3. The box (scratch guest 9202)
|
||||
|
||||
@@ -36,14 +41,19 @@ swap 0 (the stricter venue, R-733). `retest-floating.py` syncs the catalog's scr
|
||||
## 4. The run
|
||||
|
||||
```bash
|
||||
python3 scripts/retest-floating.py --engines-only --push \
|
||||
python3 scripts/retest-floating.py --push \
|
||||
--evidence $SC/evidence --evidence-rel felhom.eu/documentation/audits/retest-<YYYY-MM>
|
||||
```
|
||||
|
||||
Per app: bench (the full method, 10-minute memory watch), box (fresh install at the OLD tested digest, seed, the re-test
|
||||
entry in the drill, the guarded Update, read-back, the running digest must be the NEW one), then the writer, the catalog
|
||||
gates and one commit (pushed with `--push`; the pre-push gates run). A failure stops that app and never the list; the
|
||||
summary names each app DONE or STOPPED with its reason. Copy `$SC/evidence` to `felhom.eu/documentation/audits/retest-<YYYY-MM>/`.
|
||||
summary names each app DONE or STOPPED with its reason. Order: database/redis lines first, then the rest alphabetically
|
||||
(nextcloud — internet-facing, holds data — comes before the linuxserver apps). Copy `$SC/evidence/<date>/*` to
|
||||
`felhom.eu/documentation/audits/retest-<YYYY-MM>/` (the ladder entries cite `retest-<YYYY-MM>/<app>/{bench,box}`).
|
||||
|
||||
**Monthly cost (measured 2026-10-01):** see "What it cost" below. linuxserver images (bookstack, radarr, sonarr,
|
||||
code-server) are rebuilt upstream weekly under the same tag, so most months they come up.
|
||||
|
||||
## 5. Teardown (three layers, stated)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user