Files
misc-scripts/CHANGELOG.md
T
admin c9d5ed575c gitea-image-prune.sh: keep the newest 20 and every version in use; refuse when the in-use list is unreadable (Felhom 09 decision 62, R-750)
Protected whatever --keep says: the controller floor, the vouched golden, the vouched agent and min_agent (the hub's
Configuration page), every image of ours the vouched golden baked (its bake.log), the hub manifest's image. The dry-run
prints each kept version and why. tests/test-prune-plan.sh pins it without network (red-proofed). No --apply was run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 13:05:31 +02:00

62 lines
3.7 KiB
Markdown

# Changelog — misc-scripts
All notable changes to the operator helper scripts. Newest on top.
## 2026-10-01
### Changed — `gitea-image-prune.sh`: the retention rule (Felhom `09` §3 decision 62, R-750)
- A prune keeps the newest **20** versions (`--keep` defaults to 20) **plus every version in use**: the controller
floor, the vouched golden, the vouched agent and its `min_agent` (the hub's operator Configuration page, `HUB_PW`),
every image of ours the vouched golden baked (its `bake.log` in `felhom.eu`), and the hub image `manifests/hub.yaml`
runs. The dry-run prints each kept version and why. **An unreadable in-use list refuses the prune (exit 3).**
- `tests/test-prune-plan.sh` (no network: test seams `PRUNE_TEST_VERSIONS`, `PRUNE_TEST_PROTECT`): an in-use version
older than the newest 20 stays; red-proof: without the in-use list it is deleted, and with the check removed from
`is_protected` the test fails.
- The "cron-friendly" and "set-and-forget Gitea rule" advice removed: nothing schedules a prune; `--apply` is a person's act.
- Recorded: the 2026-08-22 16:02 UTC run (`--all --keep 7 --apply`, HM-024) predates this rule — it is why the oldest
`felhom-controller` left is 0.213.0.
## 2026-06-17 (later)
### Changed — `gitea-image-prune.sh`
- Credential auto-discovery: when `GITEA_TOKEN`/`--token-file` are not set and the
script runs inside a Gitea-host clone, it reuses git's stored credential — the
token embedded in the remote URL, else a configured credential helper
(`git credential fill`, never prompting). Lets you run it from a configured
clone with no token. Startup banner reports the credential source + user.
- Auth now uses HTTP Basic (`user:token`) when a username is known (so both API
tokens and the embedded-URL/helper credential work), falling back to the
`Authorization: token` header for a bare `GITEA_TOKEN`. Live-verified both paths
(env token; git credential helper as `kisfenyo`).
## 2026-06-17
### Added — `gitea-image-prune.sh`
- New operator CLI to inspect and prune old container images in the self-hosted
Gitea registry (`gitea.dooplex.hu`, owner `admin`) and reclaim disk on the
Longhorn-backed packages PVC. Pure `curl` + `jq`; interactive menu + scriptable
flags. Safe **dry-run default**.
- Modes: `list` (per-tag upload date + apparent image size, newest-first,
shared-layer caveat), `prune` (`--keep N` or `--older-than DAYS`; always
protects `^latest$` + `--protect` regexes), `reclaim` (delete orphaned manifest
versions + trigger/await the `cleanup_packages` GC cron). `--measure` does
best-effort before/after `du` via `kubectl`.
- Implements the **three-step reclaim mechanism proven live** on Gitea 1.26.2:
deleting a tag frees only the index pointer; the orphaned `sha256:` manifest
versions must also be deleted (default `cleanup_packages` does not remove
untagged manifests); the cron then GCs the unreferenced blobs. Orphan detection
is fail-closed.
- Safety: orders by upload date (never parses mixed `v`/bare tags), checks every
HTTP status, never echoes/logs the token, audit log per run, typed confirmation
on `--apply` (stricter for `--all`).
- Token via `GITEA_TOKEN`/`--token-file`. Minimal scopes documented in README:
`read:package` (list), `write:package` (delete), `read:admin` (cron list),
`write:admin` (cron trigger).
- README section added documenting usage, scopes, the reclaim caveat, the live
verification result, and the native cleanup-rule recommendation.
### Changed — Gitea instance (operational, not a script change)
- Added `[cron.cleanup_packages] RUN_AT_START = true` to Gitea's `app.ini`
(on the data PVC) so the package GC also runs on every Gitea restart. Enables
reclaim without a `write:admin` token. Backup at `app.ini.bak.prune-spike`.