Project pinned digest-safe retention tool through existing GitOps resources
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
942059a6fe
commit
a12f1169f9
6 changed files with 988 additions and 2 deletions
7
k8s/gitops/platform-source.json
Normal file
7
k8s/gitops/platform-source.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"schema_version": 1,
|
||||
"repository": "coulomb/railiance-platform",
|
||||
"revision": "743def17bec7f32600c8340b8e6b520430b88897",
|
||||
"path": "scripts/forgejo_package_prune.py",
|
||||
"sha256": "fa3d4cc8cdcc14ecce509cf6865c6e4726d722f84814b97d40686d68d6ee5bb1"
|
||||
}
|
||||
|
|
@ -1183,6 +1183,293 @@ data:
|
|||
evidence: []
|
||||
gaps:
|
||||
- "Add explicit ops inventory probes and evidence events."
|
||||
forgejo_package_prune.py: "#!/usr/bin/env python3\n\"\"\"Forgejo package retention\
|
||||
\ prune \u2014 keep newest N versions per package.\"\"\"\n\nfrom __future__ import\
|
||||
\ annotations\n\nimport argparse\nimport json\nimport os\nimport re\nimport shutil\n\
|
||||
import subprocess\nimport sys\nimport time\nimport urllib.error\nimport urllib.parse\n\
|
||||
import urllib.request\nfrom dataclasses import dataclass\nfrom datetime import\
|
||||
\ datetime\nfrom pathlib import Path\nfrom typing import Any\n\nDEFAULT_BASE =\
|
||||
\ \"https://forgejo.coulomb.social\"\nDEFAULT_OWNER = \"coulomb\"\nDEFAULT_TYPES\
|
||||
\ = (\"container\", \"pypi\", \"npm\", \"generic\")\nDEFAULT_MAX_VERSIONS = 3\n\
|
||||
DEFAULT_APPS_ROOT = Path.home() / \"railiance-apps\"\nDEFAULT_FORGEJO_ADMIN_BAO_PATH\
|
||||
\ = \"platform/workloads/forgejo/forgejo-admin\"\nDEFAULT_FORGEJO_ADMIN_BAO_FIELD\
|
||||
\ = \"API_TOKEN\"\nLEGACY_FORGEJO_TOKEN_FILE = Path(\"/tmp/forgejo-tegwick-api-token\"\
|
||||
)\nFORGEJO_IMAGE_RE = re.compile(\n r\"^forgejo\\.coulomb\\.social/(?:coulomb/)?(?P<name>[^:/]+)(?::(?P<tag>[^/\\\
|
||||
s]+))?$\",\n re.IGNORECASE,\n)\n\n\ndef protect_image(image: str, protected:\
|
||||
\ set[tuple[str, str, str]]) -> str | None:\n \"\"\"Digest references conservatively\
|
||||
\ protect all versions of their package.\n\n Package APIs do not prove which\
|
||||
\ tags or child manifests share a live digest.\n Retaining the whole package\
|
||||
\ avoids deleting live/rollback content through an\n alias. The additive inventory\
|
||||
\ intentionally keeps this protection until an\n owner explicitly retires the\
|
||||
\ reference.\n \"\"\"\n ref, separator, digest = image.partition(\"@\")\n\
|
||||
\ match = FORGEJO_IMAGE_RE.fullmatch(ref)\n if not match:\n if image.lower().startswith(\"\
|
||||
forgejo.coulomb.social/\"):\n return \"unrecognized Forgejo image reference\"\
|
||||
\n return None\n name = match.group(\"name\")\n if separator:\n \
|
||||
\ if not re.fullmatch(r\"sha256:[0-9a-f]{64}\", digest):\n return\
|
||||
\ \"invalid Forgejo image digest\"\n protected.add((\"container\", name,\
|
||||
\ \"*\"))\n else:\n protected.add((\"container\", name, match.group(\"\
|
||||
tag\") or \"latest\"))\n return None\n\n\n@dataclass(frozen=True)\nclass VersionRef:\n\
|
||||
\ package_type: str\n name: str\n version: str\n\n def key(self) ->\
|
||||
\ tuple[str, str, str]:\n return (self.package_type, self.name, self.version)\n\
|
||||
\n\n@dataclass(frozen=True)\nclass DeletePlan:\n package_type: str\n name:\
|
||||
\ str\n version: str\n created_at: str\n protected: bool\n reason:\
|
||||
\ str\n\n\ndef _parse_created_at(value: str | None) -> datetime:\n if not value:\n\
|
||||
\ return datetime.min\n try:\n return datetime.fromisoformat(value.replace(\"\
|
||||
Z\", \"+00:00\"))\n except ValueError:\n return datetime.min\n\n\ndef\
|
||||
\ collect_protected_versions(apps_root: Path) -> set[tuple[str, str, str]]:\n\
|
||||
\ protected: set[tuple[str, str, str]] = set()\n if not apps_root.is_dir():\n\
|
||||
\ return protected\n\n patterns = [\n apps_root / \"helm\" /\
|
||||
\ \"*-values.yaml\",\n apps_root / \"charts\" / \"*\" / \"values.yaml\"\
|
||||
,\n ]\n paths: list[Path] = []\n for pattern in patterns:\n paths.extend(sorted(pattern.parent.glob(pattern.name)))\n\
|
||||
\n try:\n import yaml # type: ignore\n except ImportError:\n \
|
||||
\ yaml = None\n\n for path in paths:\n text = path.read_text(encoding=\"\
|
||||
utf-8\")\n if yaml is not None:\n try:\n data\
|
||||
\ = yaml.safe_load(text) or {}\n except Exception:\n \
|
||||
\ data = {}\n image = data.get(\"image\") if isinstance(data, dict)\
|
||||
\ else None\n if isinstance(image, dict):\n repo = str(image.get(\"\
|
||||
repository\") or \"\").strip()\n tag = str(image.get(\"tag\") or\
|
||||
\ \"\").strip()\n if repo and tag:\n match =\
|
||||
\ FORGEJO_IMAGE_RE.match(repo) or FORGEJO_IMAGE_RE.match(\n \
|
||||
\ f\"{repo}:{tag}\"\n )\n if match:\n\
|
||||
\ name = match.group(\"name\")\n \
|
||||
\ protected.add((\"container\", name, tag))\n continue\n\n \
|
||||
\ repo_match = re.search(\n r\"repository:\\s*forgejo\\.coulomb\\.social/coulomb/([^\\\
|
||||
s]+)\",\n text,\n re.IGNORECASE,\n )\n tag_match\
|
||||
\ = re.search(r'^\\s*tag:\\s*\"?([^\"\\s#]+)\"?\\s*$', text, re.MULTILINE)\n \
|
||||
\ if repo_match and tag_match:\n protected.add((\"container\"\
|
||||
, repo_match.group(1), tag_match.group(1)))\n\n return protected\n\n\ndef collect_live_images_from_files(\n\
|
||||
\ paths: list[Path],\n) -> tuple[set[tuple[str, str, str]], list[str]]:\n \
|
||||
\ \"\"\"Protect image tags listed in exported live-image files.\n\n Each\
|
||||
\ file holds one image ref per line (`kubectl get pods ... jsonpath`\n output\
|
||||
\ from another cluster). This closes the multi-cluster gap\n (ACTIVITY-WP-0020-T07):\
|
||||
\ the prune host's kubectl only sees its own\n cluster, so every other production\
|
||||
\ cluster exports its live images to a\n file that is merged here. Unavailable\
|
||||
\ or empty exports produce notes;\n main refuses apply when any requested export\
|
||||
\ cannot provide coverage.\n \"\"\"\n protected: set[tuple[str, str, str]]\
|
||||
\ = set()\n notes: list[str] = []\n for raw_path in paths:\n path\
|
||||
\ = raw_path.expanduser()\n if not path.is_file():\n notes.append(f\"\
|
||||
live-images file missing: {path}\")\n continue\n try:\n \
|
||||
\ lines = path.read_text(encoding=\"utf-8\").splitlines()\n except\
|
||||
\ (OSError, UnicodeError):\n notes.append(f\"live-images file unreadable:\
|
||||
\ {path}\")\n continue\n has_images = False\n for line\
|
||||
\ in lines:\n image = line.strip()\n if not image or image.startswith(\"\
|
||||
#\"):\n continue\n has_images = True\n error\
|
||||
\ = protect_image(image, protected)\n if error:\n notes.append(f\"\
|
||||
{error} in live-images file: {path}\")\n if not has_images:\n \
|
||||
\ notes.append(f\"live-images file empty: {path}\")\n return protected, notes\n\
|
||||
\n\ndef collect_live_cluster_versions(\n *, kubectl: str = \"kubectl\", timeout:\
|
||||
\ float = 60.0\n) -> tuple[set[tuple[str, str, str]], list[str]]:\n \"\"\"\
|
||||
Protect image tags currently running in the cluster (best-effort).\n\n Enumerates\
|
||||
\ all pod container images across namespaces via kubectl and\n protects any\
|
||||
\ `forgejo.coulomb.social/coulomb/<name>:<tag>`. This closes the\n gap where\
|
||||
\ a live deployment pins a tag not declared in Helm values (e.g.\n CI-deployed\
|
||||
\ apps). Failures (no kubectl, no cluster access) return an empty\n set with\
|
||||
\ a note \u2014 pruning a reachable registry must not hard-depend on\n cluster\
|
||||
\ access, but the note surfaces reduced protection coverage.\n \"\"\"\n \
|
||||
\ protected: set[tuple[str, str, str]] = set()\n if shutil.which(kubectl) is\
|
||||
\ None:\n return protected, [\"live-tag protection skipped: kubectl not\
|
||||
\ found\"]\n jsonpath = (\n \"{range .items[*]}\"\n \"{range\
|
||||
\ .spec.containers[*]}{.image}{'\\\\n'}{end}\"\n \"{range .spec.initContainers[*]}{.image}{'\\\
|
||||
\\n'}{end}\"\n \"{end}\"\n )\n try:\n result = subprocess.run(\n\
|
||||
\ [kubectl, \"get\", \"pods\", \"--all-namespaces\", \"-o\", f\"jsonpath={jsonpath}\"\
|
||||
],\n capture_output=True,\n text=True,\n timeout=timeout,\n\
|
||||
\ check=True,\n )\n except Exception as exc: # noqa: BLE001\n\
|
||||
\ return protected, [f\"live-tag protection skipped: kubectl query failed\
|
||||
\ ({exc})\"]\n notes: list[str] = []\n for line in result.stdout.splitlines():\n\
|
||||
\ image = line.strip()\n if not image:\n continue\n \
|
||||
\ error = protect_image(image, protected)\n if error:\n \
|
||||
\ notes.append(error)\n if not result.stdout.strip():\n notes.append(\"\
|
||||
live cluster image inventory empty\")\n return protected, notes\n\n\ndef _api_request(\n\
|
||||
\ method: str,\n url: str,\n token: str,\n *,\n timeout: float\
|
||||
\ = 60.0,\n retries: int = 2,\n) -> Any:\n req = urllib.request.Request(\n\
|
||||
\ url,\n method=method,\n headers={\n \"Authorization\"\
|
||||
: f\"token {token}\",\n \"Accept\": \"application/json\",\n \
|
||||
\ },\n )\n last_exc: Exception | None = None\n for attempt in range(retries\
|
||||
\ + 1):\n try:\n with urllib.request.urlopen(req, timeout=timeout)\
|
||||
\ as resp:\n body = resp.read().decode(\"utf-8\")\n \
|
||||
\ return json.loads(body) if body else None\n except urllib.error.HTTPError:\n\
|
||||
\ raise # 4xx/5xx are real responses \u2014 surface them, do not retry\n\
|
||||
\ except (urllib.error.URLError, TimeoutError, OSError) as exc:\n \
|
||||
\ # Transient: connection reset, read timeout, TLS handshake timeout.\n\
|
||||
\ last_exc = exc\n if attempt < retries:\n \
|
||||
\ time.sleep(2 * (attempt + 1))\n continue\n raise\n\
|
||||
\ if last_exc: # pragma: no cover - defensive\n raise last_exc\n\n\n\
|
||||
def list_packages(\n base_url: str,\n token: str,\n owner: str,\n \
|
||||
\ package_type: str,\n) -> list[dict[str, Any]]:\n owner_q = urllib.parse.quote(owner)\n\
|
||||
\ items: list[dict[str, Any]] = []\n page = 1\n page_size = 50\n while\
|
||||
\ True:\n query = urllib.parse.urlencode(\n {\"limit\": page_size,\
|
||||
\ \"page\": page, \"type\": package_type}\n )\n url = f\"{base_url.rstrip('/')}/api/v1/packages/{owner_q}?{query}\"\
|
||||
\n payload = _api_request(\"GET\", url, token)\n if not isinstance(payload,\
|
||||
\ list):\n raise ValueError(\"invalid package inventory response\"\
|
||||
)\n batch = payload\n if not batch:\n break\n \
|
||||
\ items.extend(batch)\n if len(batch) < page_size:\n break\n\
|
||||
\ page += 1\n return items\n\n\ndef delete_version(\n base_url: str,\n\
|
||||
\ token: str,\n owner: str,\n package_type: str,\n name: str,\n \
|
||||
\ version: str,\n *,\n dry_run: bool,\n) -> None:\n owner_q = urllib.parse.quote(owner)\n\
|
||||
\ type_q = urllib.parse.quote(package_type)\n name_q = urllib.parse.quote(name,\
|
||||
\ safe=\"\")\n version_q = urllib.parse.quote(version, safe=\"\")\n path\
|
||||
\ = f\"/api/v1/packages/{owner_q}/{type_q}/{name_q}/{version_q}\"\n if dry_run:\n\
|
||||
\ return\n url = f\"{base_url.rstrip('/')}{path}\"\n _api_request(\"\
|
||||
DELETE\", url, token)\n\n\ndef build_delete_plans(\n *,\n base_url: str,\n\
|
||||
\ token: str,\n owner: str,\n package_types: list[str],\n max_versions:\
|
||||
\ int,\n protected: set[tuple[str, str, str]],\n) -> tuple[list[DeletePlan],\
|
||||
\ list[str]]:\n plans: list[DeletePlan] = []\n errors: list[str] = []\n\n\
|
||||
\ for package_type in package_types:\n try:\n packages =\
|
||||
\ list_packages(base_url, token, owner, package_type)\n except urllib.error.HTTPError\
|
||||
\ as exc:\n errors.append(f\"list {package_type}: HTTP {exc.code}\"\
|
||||
)\n continue\n except Exception as exc: # noqa: BLE001\n \
|
||||
\ errors.append(f\"list {package_type}: {exc}\")\n continue\n\
|
||||
\n # Forgejo's package list endpoint returns one entry per (name, version).\n\
|
||||
\ # Group by package name; each group is that package's version set \u2014\
|
||||
\ there\n # is no separate per-package \"/versions\" endpoint.\n \
|
||||
\ by_name: dict[str, list[dict[str, Any]]] = {}\n for package in packages:\n\
|
||||
\ name = str(package.get(\"name\") or package.get(\"package_name\"\
|
||||
) or \"\")\n if not name:\n continue\n by_name.setdefault(name,\
|
||||
\ []).append(package)\n\n for name, versions in by_name.items():\n \
|
||||
\ sorted_versions = sorted(\n versions,\n \
|
||||
\ key=lambda item: _parse_created_at(str(item.get(\"created_at\") or \"\")),\n\
|
||||
\ reverse=True,\n )\n keep = {\n \
|
||||
\ str(item.get(\"version\") or \"\")\n for item in sorted_versions[:max_versions]\n\
|
||||
\ if str(item.get(\"version\") or \"\")\n }\n \
|
||||
\ for item in sorted_versions[max_versions:]:\n version =\
|
||||
\ str(item.get(\"version\") or \"\")\n if not version or version\
|
||||
\ in keep:\n continue\n key = (package_type,\
|
||||
\ name, version)\n digest_protected = (package_type, name, \"*\"\
|
||||
) in protected\n is_protected = key in protected or digest_protected\n\
|
||||
\ plans.append(\n DeletePlan(\n \
|
||||
\ package_type=package_type,\n name=name,\n\
|
||||
\ version=version,\n created_at=str(item.get(\"\
|
||||
created_at\") or \"\"),\n protected=is_protected,\n \
|
||||
\ reason=(\"protected_digest_package\" if digest_protected\
|
||||
\ else\n \"protected_production_tag\" if is_protected\
|
||||
\ else\n \"beyond_retention_depth\"),\n \
|
||||
\ )\n )\n return plans, errors\n\n\ndef _read_token_file(path:\
|
||||
\ Path) -> str:\n return path.read_text(encoding=\"utf-8\").strip()\n\n\ndef\
|
||||
\ _truthy_env(name: str) -> bool:\n return os.environ.get(name, \"\").strip().lower()\
|
||||
\ in {\"1\", \"true\", \"yes\", \"on\"}\n\n\ndef _load_token_from_file_env() ->\
|
||||
\ str | None:\n for env_name in (\"FORGEJO_TOKEN_FILE\", \"FORGEJO_ADMIN_TOKEN_FILE\"\
|
||||
):\n raw_path = os.environ.get(env_name, \"\").strip()\n if not\
|
||||
\ raw_path:\n continue\n path = Path(raw_path).expanduser()\n\
|
||||
\ if not path.is_file():\n raise SystemExit(f\"ERROR: {env_name}\
|
||||
\ points to a missing file: {path}\")\n token = _read_token_file(path)\n\
|
||||
\ if token:\n return token\n raise SystemExit(f\"ERROR:\
|
||||
\ {env_name} points to an empty file: {path}\")\n return None\n\n\ndef _load_token_from_openbao()\
|
||||
\ -> tuple[str | None, str | None]:\n bao_bin = os.environ.get(\"FORGEJO_ADMIN_BAO_CLI\"\
|
||||
, \"bao\").strip() or \"bao\"\n bao_path = (\n os.environ.get(\"FORGEJO_ADMIN_BAO_PATH\"\
|
||||
, DEFAULT_FORGEJO_ADMIN_BAO_PATH).strip()\n or DEFAULT_FORGEJO_ADMIN_BAO_PATH\n\
|
||||
\ )\n bao_field = (\n os.environ.get(\"FORGEJO_ADMIN_BAO_FIELD\"\
|
||||
, DEFAULT_FORGEJO_ADMIN_BAO_FIELD).strip()\n or DEFAULT_FORGEJO_ADMIN_BAO_FIELD\n\
|
||||
\ )\n if shutil.which(bao_bin) is None:\n return None, f\"{bao_bin}\
|
||||
\ CLI not found\"\n try:\n result = subprocess.run(\n [bao_bin,\
|
||||
\ \"kv\", \"get\", f\"-field={bao_field}\", bao_path],\n capture_output=True,\n\
|
||||
\ text=True,\n check=True,\n )\n except subprocess.CalledProcessError\
|
||||
\ as exc:\n detail = exc.stderr.strip() or exc.stdout.strip() or f\"exit\
|
||||
\ {exc.returncode}\"\n return None, f\"{bao_bin} kv get failed: {detail}\"\
|
||||
\n except OSError as exc:\n return None, f\"{bao_bin} invocation failed:\
|
||||
\ {exc}\"\n token = result.stdout.strip()\n if not token:\n return\
|
||||
\ None, f\"{bao_bin} kv get returned an empty {bao_field} field\"\n return\
|
||||
\ token, None\n\n\ndef _token_help_message(bao_error: str | None) -> str:\n \
|
||||
\ lines = [\n \"ERROR: Forgejo API token required (read:package + write:package).\"\
|
||||
,\n \" Primary: bao login -method=oidc -path=netkingdom role=forgejo-admin-workload-kv-read\"\
|
||||
,\n f\" Default lane: {DEFAULT_FORGEJO_ADMIN_BAO_PATH} field {DEFAULT_FORGEJO_ADMIN_BAO_FIELD}\"\
|
||||
,\n \" Override lane via FORGEJO_ADMIN_BAO_PATH / FORGEJO_ADMIN_BAO_FIELD\
|
||||
\ if needed.\",\n \" Break-glass: set FORGEJO_TOKEN / FORGEJO_ADMIN_TOKEN,\
|
||||
\ or set FORGEJO_TOKEN_FILE / FORGEJO_ADMIN_TOKEN_FILE.\",\n \" Legacy\
|
||||
\ /tmp fallback stays opt-in only via FORGEJO_ALLOW_LEGACY_FILE_FALLBACK=1.\"\
|
||||
,\n \" See: railiance-platform/docs/forgejo-package-prune.md\",\n ]\n\
|
||||
\ if bao_error:\n lines.insert(3, f\" OpenBao lookup failed: {bao_error}\"\
|
||||
)\n return \"\\n\".join(lines)\n\n\ndef load_token() -> str:\n for env_name\
|
||||
\ in (\"FORGEJO_TOKEN\", \"FORGEJO_ADMIN_TOKEN\"):\n token = os.environ.get(env_name,\
|
||||
\ \"\").strip()\n if token:\n return token\n token = _load_token_from_file_env()\n\
|
||||
\ if token:\n return token\n token, bao_error = _load_token_from_openbao()\n\
|
||||
\ if token:\n return token\n\n if _truthy_env(\"FORGEJO_ALLOW_LEGACY_FILE_FALLBACK\"\
|
||||
):\n if LEGACY_FORGEJO_TOKEN_FILE.is_file():\n token = _read_token_file(LEGACY_FORGEJO_TOKEN_FILE)\n\
|
||||
\ if token:\n return token\n suffix = f\"\
|
||||
legacy file {LEGACY_FORGEJO_TOKEN_FILE} is empty\"\n else:\n \
|
||||
\ suffix = f\"legacy file {LEGACY_FORGEJO_TOKEN_FILE} is missing\"\n bao_error\
|
||||
\ = f\"{bao_error}; {suffix}\" if bao_error else suffix\n\n raise SystemExit(_token_help_message(bao_error))\n\
|
||||
\n\ndef emit_summary(\n *,\n owner: str,\n max_versions: int,\n package_types:\
|
||||
\ list[str],\n protected: set[tuple[str, str, str]],\n plans: list[DeletePlan],\n\
|
||||
\ errors: list[str],\n apply: bool,\n deleted: list[DeletePlan],\n) ->\
|
||||
\ dict[str, Any]:\n would_delete = [p for p in plans if not p.protected]\n\
|
||||
\ skipped_protected = [p for p in plans if p.protected]\n return {\n \
|
||||
\ \"kind\": \"forgejo_package_prune\",\n \"owner\": owner,\n \
|
||||
\ \"max_versions\": max_versions,\n \"package_types\": package_types,\n\
|
||||
\ \"protected_count\": len(protected),\n \"candidate_count\": len(would_delete),\n\
|
||||
\ \"skipped_protected_count\": len(skipped_protected),\n \"deleted_count\"\
|
||||
: len(deleted),\n \"apply\": apply,\n \"would_delete\": [\n \
|
||||
\ {\n \"type\": p.package_type,\n \"name\"\
|
||||
: p.name,\n \"version\": p.version,\n \"created_at\"\
|
||||
: p.created_at,\n }\n for p in would_delete\n ],\n\
|
||||
\ \"skipped_protected\": [\n {\n \"type\": p.package_type,\n\
|
||||
\ \"name\": p.name,\n \"version\": p.version,\n\
|
||||
\ \"reason\": p.reason,\n }\n for p in skipped_protected\n\
|
||||
\ ],\n \"deleted\": [\n {\n \"type\":\
|
||||
\ p.package_type,\n \"name\": p.name,\n \"version\"\
|
||||
: p.version,\n }\n for p in deleted\n ],\n \
|
||||
\ \"errors\": errors,\n }\n\n\ndef main(argv: list[str] | None = None) ->\
|
||||
\ int:\n parser = argparse.ArgumentParser(description=\"Prune old Forgejo package\
|
||||
\ versions\")\n parser.add_argument(\"--owner\", default=DEFAULT_OWNER)\n \
|
||||
\ parser.add_argument(\"--base-url\", default=os.environ.get(\"FORGEJO_BASE_URL\"\
|
||||
, DEFAULT_BASE))\n parser.add_argument(\"--max-versions\", type=int, default=DEFAULT_MAX_VERSIONS)\n\
|
||||
\ parser.add_argument(\n \"--types\",\n default=\",\".join(DEFAULT_TYPES),\n\
|
||||
\ help=\"Comma-separated package types\",\n )\n parser.add_argument(\"\
|
||||
--apps-root\", type=Path, default=DEFAULT_APPS_ROOT)\n parser.add_argument(\"\
|
||||
--apply\", action=\"store_true\")\n parser.add_argument(\"--json\", action=\"\
|
||||
store_true\", help=\"Emit JSON summary on stdout\")\n parser.add_argument(\n\
|
||||
\ \"--no-protect-live\",\n dest=\"protect_live\",\n action=\"\
|
||||
store_false\",\n help=\"Skip protecting image tags currently running in\
|
||||
\ the cluster (kubectl)\",\n )\n parser.set_defaults(protect_live=True)\n\
|
||||
\ parser.add_argument(\n \"--live-images-file\",\n dest=\"live_images_files\"\
|
||||
,\n type=Path,\n action=\"append\",\n default=[],\n \
|
||||
\ help=(\n \"File with one image ref per line, exported from another\
|
||||
\ \"\n \"production cluster; repeatable. Tags matching the Forgejo\
|
||||
\ \"\n \"registry are protected in addition to the local kubectl scan.\"\
|
||||
\n ),\n )\n args = parser.parse_args(argv)\n\n apply = bool(args.apply)\n\
|
||||
\ dry_run = not apply\n package_types = [part.strip() for part in args.types.split(\"\
|
||||
,\") if part.strip()]\n file_live, file_notes = collect_live_images_from_files(args.live_images_files)\n\
|
||||
\ if apply and file_notes:\n for note in file_notes:\n print(f\"\
|
||||
\ ERROR: {note}\", file=sys.stderr)\n print(\"Refusing apply: requested\
|
||||
\ live-image inventory is unavailable or empty\", file=sys.stderr)\n return\
|
||||
\ 2\n token = load_token()\n protected = collect_protected_versions(args.apps_root.expanduser())\n\
|
||||
\ protect_notes: list[str] = []\n if args.protect_live:\n live, protect_notes\
|
||||
\ = collect_live_cluster_versions()\n protected |= live\n print(f\"\
|
||||
Protected live cluster tags: {len(live)}\", file=sys.stderr)\n for note\
|
||||
\ in protect_notes:\n print(f\" WARN: {note}\", file=sys.stderr)\n\
|
||||
\ if args.live_images_files:\n protected |= file_live\n protect_notes.extend(file_notes)\n\
|
||||
\ print(f\"Protected exported live tags: {len(file_live)}\", file=sys.stderr)\n\
|
||||
\ for note in file_notes:\n print(f\" WARN: {note}\", file=sys.stderr)\n\
|
||||
\n print(f\"Forgejo package prune \u2014 owner={args.owner} keep={args.max_versions}\"\
|
||||
, file=sys.stderr)\n print(f\"Protected production tags: {len(protected)}\"\
|
||||
, file=sys.stderr)\n\n plans, errors = build_delete_plans(\n base_url=args.base_url,\n\
|
||||
\ token=token,\n owner=args.owner,\n package_types=package_types,\n\
|
||||
\ max_versions=max(1, args.max_versions),\n protected=protected,\n\
|
||||
\ )\n\n # Never partially prune after an incomplete package or requested\
|
||||
\ cluster scan.\n if apply and (errors or protect_notes):\n print(\"\
|
||||
Refusing apply: incomplete inventory/protection coverage\", file=sys.stderr)\n\
|
||||
\ return 2\n\n deleted: list[DeletePlan] = []\n for plan in plans:\n\
|
||||
\ if plan.protected:\n print(\n f\" skip protected\
|
||||
\ {plan.package_type}/{plan.name}:{plan.version}\",\n file=sys.stderr,\n\
|
||||
\ )\n continue\n if dry_run:\n print(\n\
|
||||
\ f\" would delete {plan.package_type}/{plan.name}:{plan.version}\"\
|
||||
,\n file=sys.stderr,\n )\n continue\n \
|
||||
\ try:\n delete_version(\n args.base_url,\n \
|
||||
\ token,\n args.owner,\n plan.package_type,\n\
|
||||
\ plan.name,\n plan.version,\n dry_run=False,\n\
|
||||
\ )\n deleted.append(plan)\n print(\n \
|
||||
\ f\" deleted {plan.package_type}/{plan.name}:{plan.version}\"\
|
||||
,\n file=sys.stderr,\n )\n except urllib.error.HTTPError\
|
||||
\ as exc:\n errors.append(f\"delete {plan.package_type}/{plan.name}:{plan.version}:\
|
||||
\ HTTP {exc.code}\")\n except Exception as exc: # noqa: BLE001\n \
|
||||
\ errors.append(f\"delete {plan.package_type}/{plan.name}:{plan.version}:\
|
||||
\ {exc}\")\n\n summary = emit_summary(\n owner=args.owner,\n \
|
||||
\ max_versions=args.max_versions,\n package_types=package_types,\n \
|
||||
\ protected=protected,\n plans=plans,\n errors=errors,\n \
|
||||
\ apply=apply,\n deleted=deleted,\n )\n summary[\"live_protection\"\
|
||||
] = args.protect_live\n summary[\"protection_notes\"] = protect_notes\n\n \
|
||||
\ if args.json or not sys.stdout.isatty():\n print(json.dumps(summary,\
|
||||
\ indent=2))\n else:\n print(json.dumps(summary, indent=2))\n\n return\
|
||||
\ 1 if errors else 0\n\n\nif __name__ == \"__main__\":\n raise SystemExit(main())\n"
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: actcore-ops-service-inventory
|
||||
|
|
@ -1343,6 +1630,7 @@ spec:
|
|||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
activity-core/retention-sha256: fa3d4cc8cdcc14ecce509cf6865c6e4726d722f84814b97d40686d68d6ee5bb1
|
||||
kubectl.kubernetes.io/restartedAt: '2026-09-05T20:48:57+02:00'
|
||||
labels:
|
||||
app.kubernetes.io/name: actcore-worker
|
||||
|
|
@ -1397,6 +1685,10 @@ spec:
|
|||
- mountPath: /var/custodian/runtime/prompts
|
||||
name: custodian-runtime
|
||||
readOnly: true
|
||||
- mountPath: /opt/railiance-platform/scripts/forgejo_package_prune.py
|
||||
name: ops-service-inventory
|
||||
subPath: forgejo_package_prune.py
|
||||
readOnly: true
|
||||
- mountPath: /opt/railiance-platform
|
||||
name: railiance-platform
|
||||
readOnly: true
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue