Files
felhom.eu/documentation/audits/lockouts-2026-10-01/C/C1-registry-read.txt
T

42 lines
3.1 KiB
Plaintext

# Part C — what removed the old controller versions from the registry (R-750). READ ONLY. 2026-10-01T09:01:40Z
## 1. Gitea's package cleanup rules — NONE
Gitea 1.26.2 (API /version). Database gitea on the shared CNPG (postgresql-2), one READ ONLY transaction:
SELECT ... FROM package_cleanup_rule; -> (0 rows)
app.ini (the pod's, regenerated at every pod start; secrets filtered out of this read):
[packages] ENABLED = true
[cron.cleanup_packages] ENABLED = true, RUN_AT_START = true
— that cron runs the cleanup RULES (none) and Gitea's own expired-data clean-up; it deletes no tagged version by itself.
The admin cron API answered 403 (the available token has no write:admin) — same as HM-024 recorded.
## 2. What the database shows (READ ONLY)
package first remaining version versions
felhom-act-runner 2026-08-02 3
felhom-agent 2026-08-03 20
felhom-controller 2026-08-12 288 (tags + digest manifests)
felhom-golden 2026-08-22 21
felhom-hub 2026-08-08 90
felhom-samba 2026-07-18 6
package_version ids run 17..4201; the felhom-controller package itself is id 2 (it existed long before 08-12).
## 3. The cause — a MANUAL run of a DooPlex script, recorded in homelab-manifests (HM-024, CHANGELOG 2026-08-23)
"gitea-image-prune.sh --all --keep 7 --apply --reclaim reported success overnight and freed nothing visible"
— then the generic fix: felhom-golden 22 -> 3 versions; /data 14.8 G -> 4.4 G; Longhorn actualSize 46.5 -> 7.0 GB.
~/git/misc-scripts/gitea-image-prune.sh history:
7739c83 2026-08-23 13:47:58 +0200 gitea-image-prune.sh: add --type, so generic packages are prunable
5b4d8ec 2026-06-17 09:28:55 +0200 gitea-image-prune.sh: auto-discover credentials from git
761dc38 2026-06-17 09:16:07 +0200 Add gitea-image-prune.sh: inspect/prune Gitea container images + reclaim disk
Its own usage text: "./gitea-image-prune.sh --all --keep 7 --apply --yes --reclaim # containers"
"./gitea-image-prune.sh --type generic --all --keep 3 --apply --yes --reclaim"
--keep 7 per CONTAINER package on 2026-08-22/23 leaves felhom-controller's oldest at 0.213.0 (2026-08-12) — matches.
The record names WHY: "build-felhom-{hub,controller}.sh push :<version> AND :latest on every build ... the Gitea
Longhorn PVC keeps filling."
## 4. Will it remove more? Only when someone runs it again — nothing schedules it
kisfenyo crontab: one unrelated line (jarrs.eu backup sync); root crontab: empty; systemd timers: none matching;
/etc/cron.d, cron.daily: none; cluster CronJobs: authentik-shm-cleaner, crashloop-restarter, renovate,
postgresql-backup, longhorn backup-daily/weekly — none touches packages.
If run again as its usage text says: felhom-controller would keep 7 releases (about one day of releases today), and
"--type generic --all --keep 3" would cut felhom-agent to 3 versions — HM-024 itself refused that sweep ("felhom-agent's
retention was not a decision anyone had made"). Nothing in the script protects the VOUCHED agent or golden.