HH-441: harden durable storage and recovery (#92)

* HH-441: harden durable storage and recovery

* HH-441: clear recovery review blockers

* HH-441: enforce offsite backup failure domain

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-22 02:16:02 +08:00
committed by GitHub
co-authored by rogee
parent 77c91662d2
commit 6d6d80dd86
20 changed files with 966 additions and 202 deletions
+15
View File
@@ -43,6 +43,10 @@ func main() {
fmt.Println("Migrations applied successfully (up)")
case "down":
if err := rejectDestructiveProductionMigration(env, -1); err != nil {
fmt.Fprintf(os.Stderr, "Error: %v\n", err)
os.Exit(1)
}
if err := database.RollbackMigrations(dbURL, migrationsPath); err != nil {
fmt.Fprintf(os.Stderr, "Error running migrations down: %v\n", err)
os.Exit(1)
@@ -89,6 +93,10 @@ func main() {
fmt.Fprintf(os.Stderr, "Error: invalid step count '%s': %v\n", os.Args[2], err)
os.Exit(1)
}
if err := rejectDestructiveProductionMigration(env, steps); err != nil {
fmt.Fprintf(os.Stderr, "Error: %v\n", err)
os.Exit(1)
}
if err := database.MigrateSteps(dbURL, migrationsPath, steps); err != nil {
fmt.Fprintf(os.Stderr, "Error running %d migration steps: %v\n", steps, err)
os.Exit(1)
@@ -102,6 +110,13 @@ func main() {
}
}
func rejectDestructiveProductionMigration(env string, steps int) error {
if env == "production" && steps < 0 {
return fmt.Errorf("destructive schema down is disabled in production; roll back the application image or restore a backup")
}
return nil
}
func printUsage() {
fmt.Println("Usage: migrate <command> [args]")
fmt.Println("")
+5
View File
@@ -218,3 +218,8 @@ func TestCurrentVersion(t *testing.T) {
assert.Equal(t, uint(3), version)
assert.False(t, dirty)
}
func TestRejectDestructiveProductionMigration(t *testing.T) {
require.Error(t, rejectDestructiveProductionMigration("production", -1))
require.NoError(t, rejectDestructiveProductionMigration("production", 1))
require.NoError(t, rejectDestructiveProductionMigration("development", -1))
}