Add per-workload capture of host-bind data volumes as downloadable tar.gz archives: a new internal/volsnap engine (enumerate host-bind volumes via the computeMounts merge, archive with archive/tar+gzip skipping symlinks/special files, per-workload retention + startup orphan cleanup), a volume_snapshots table + store CRUD, admin-gated API (list/snapshotable/create/download/delete), and a Snapshots panel on /apps/[id] that shows coverage and which volumes are skipped (and why). Scope: image-source apps, host-bind scopes (absolute/stage/project); Docker named volumes, tmpfs, and instance scope are surfaced as not-yet-supported. Restore is a separate later phase. Download/FilePath are containment-checked; create returns a typed no-data error (400) vs generic 500. Covered by archiver unit tests + full API e2e.
This commit is contained in:
@@ -19,6 +19,7 @@ import (
|
||||
"github.com/alexei/tinyforge/internal/proxy"
|
||||
"github.com/alexei/tinyforge/internal/stale"
|
||||
"github.com/alexei/tinyforge/internal/store"
|
||||
"github.com/alexei/tinyforge/internal/volsnap"
|
||||
"github.com/alexei/tinyforge/internal/webhook"
|
||||
"github.com/alexei/tinyforge/internal/workload/plugin"
|
||||
)
|
||||
@@ -56,6 +57,7 @@ type Server struct {
|
||||
onDNSProviderChanged DNSProviderChangedFunc
|
||||
|
||||
backupEngine *backup.Engine
|
||||
snapshotEngine *volsnap.Engine
|
||||
sseGate *sseGate
|
||||
logScanReloader LogScanReloader
|
||||
dbPath string
|
||||
@@ -119,6 +121,11 @@ func (s *Server) SetBackupEngine(engine *backup.Engine) {
|
||||
s.backupEngine = engine
|
||||
}
|
||||
|
||||
// SetSnapshotEngine sets the volume-snapshot engine on the server.
|
||||
func (s *Server) SetSnapshotEngine(engine *volsnap.Engine) {
|
||||
s.snapshotEngine = engine
|
||||
}
|
||||
|
||||
// SetDBPath sets the database file path (needed for restore).
|
||||
func (s *Server) SetDBPath(path string) {
|
||||
s.dbPath = path
|
||||
@@ -329,6 +336,13 @@ func (s *Server) Router() chi.Router {
|
||||
r.With(auth.AdminOnly).Post("/start", s.startPluginWorkload)
|
||||
r.With(auth.AdminOnly).Delete("/", s.deletePluginWorkload)
|
||||
|
||||
// Volume snapshots (admin-only). Capture/list a workload's
|
||||
// host-bind data volumes; {sid}-scoped download/delete live
|
||||
// in the global admin group alongside backups.
|
||||
r.With(auth.AdminOnly).Get("/snapshots", s.listWorkloadSnapshots)
|
||||
r.With(auth.AdminOnly).Get("/snapshotable", s.getWorkloadSnapshotable)
|
||||
r.With(auth.AdminOnly).Post("/snapshots", s.createWorkloadSnapshot)
|
||||
|
||||
// Runtime view: per-source persisted state + storage usage.
|
||||
// Read-only; safe for any authenticated user.
|
||||
r.Get("/runtime-state", s.getWorkloadRuntimeState)
|
||||
@@ -519,6 +533,11 @@ func (s *Server) Router() chi.Router {
|
||||
r.Get("/backups/{id}/download", s.downloadBackup)
|
||||
r.Delete("/backups/{id}", s.deleteBackup)
|
||||
r.Post("/backups/{id}/restore", s.restoreBackup)
|
||||
|
||||
// Volume-snapshot download/delete (workload-scoped capture +
|
||||
// list live under /workloads/{id}/snapshots).
|
||||
r.Get("/snapshots/{sid}/download", s.downloadSnapshot)
|
||||
r.Delete("/snapshots/{sid}", s.deleteSnapshot)
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
@@ -0,0 +1,177 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
|
||||
"github.com/alexei/tinyforge/internal/store"
|
||||
"github.com/alexei/tinyforge/internal/volsnap"
|
||||
)
|
||||
|
||||
// listWorkloadSnapshots handles GET /api/workloads/{id}/snapshots.
|
||||
func (s *Server) listWorkloadSnapshots(w http.ResponseWriter, r *http.Request) {
|
||||
if s.snapshotEngine == nil {
|
||||
respondError(w, http.StatusServiceUnavailable, "snapshot engine not initialized")
|
||||
return
|
||||
}
|
||||
id := chi.URLParam(r, "id")
|
||||
snaps, err := s.snapshotEngine.List(id)
|
||||
if err != nil {
|
||||
slog.Error("snapshots: list", "workload", id, "error", err)
|
||||
respondError(w, http.StatusInternalServerError, "internal server error")
|
||||
return
|
||||
}
|
||||
respondJSON(w, http.StatusOK, snaps)
|
||||
}
|
||||
|
||||
// snapshotableVolume is the sanitized view of a volume in the snapshotable
|
||||
// response — it omits the resolved host path so internal layout is not leaked.
|
||||
type snapshotableVolume struct {
|
||||
Target string `json:"target"`
|
||||
Scope string `json:"scope"`
|
||||
Source string `json:"source"`
|
||||
}
|
||||
|
||||
// getWorkloadSnapshotable handles GET /api/workloads/{id}/snapshotable. It
|
||||
// tells the UI which volumes can be snapshotted and which are skipped (and
|
||||
// why), so users are never misled about coverage.
|
||||
func (s *Server) getWorkloadSnapshotable(w http.ResponseWriter, r *http.Request) {
|
||||
if s.snapshotEngine == nil {
|
||||
respondError(w, http.StatusServiceUnavailable, "snapshot engine not initialized")
|
||||
return
|
||||
}
|
||||
id := chi.URLParam(r, "id")
|
||||
workload, err := s.store.GetWorkloadByID(id)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusNotFound, "workload not found")
|
||||
return
|
||||
}
|
||||
settings, err := s.store.GetSettings()
|
||||
if err != nil {
|
||||
respondError(w, http.StatusInternalServerError, "internal server error")
|
||||
return
|
||||
}
|
||||
refs, skipped, err := volsnap.SnapshotableVolumes(s.store, workload, settings)
|
||||
if err != nil {
|
||||
slog.Error("snapshots: enumerate", "workload", id, "error", err)
|
||||
respondError(w, http.StatusInternalServerError, "internal server error")
|
||||
return
|
||||
}
|
||||
|
||||
volumes := make([]snapshotableVolume, 0, len(refs))
|
||||
for _, ref := range refs {
|
||||
volumes = append(volumes, snapshotableVolume{Target: ref.Target, Scope: ref.Scope, Source: ref.Source})
|
||||
}
|
||||
if skipped == nil {
|
||||
skipped = []volsnap.SkippedVolume{}
|
||||
}
|
||||
respondJSON(w, http.StatusOK, map[string]any{
|
||||
"volumes": volumes,
|
||||
"skipped": skipped,
|
||||
})
|
||||
}
|
||||
|
||||
// createWorkloadSnapshot handles POST /api/workloads/{id}/snapshots.
|
||||
func (s *Server) createWorkloadSnapshot(w http.ResponseWriter, r *http.Request) {
|
||||
if s.snapshotEngine == nil {
|
||||
respondError(w, http.StatusServiceUnavailable, "snapshot engine not initialized")
|
||||
return
|
||||
}
|
||||
id := chi.URLParam(r, "id")
|
||||
workload, err := s.store.GetWorkloadByID(id)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusNotFound, "workload not found")
|
||||
return
|
||||
}
|
||||
settings, err := s.store.GetSettings()
|
||||
if err != nil {
|
||||
respondError(w, http.StatusInternalServerError, "internal server error")
|
||||
return
|
||||
}
|
||||
|
||||
var body struct {
|
||||
Label string `json:"label"`
|
||||
}
|
||||
if r.ContentLength != 0 {
|
||||
if err := json.NewDecoder(io.LimitReader(r.Body, 1<<20)).Decode(&body); err != nil && !errors.Is(err, io.EOF) {
|
||||
respondError(w, http.StatusBadRequest, "invalid JSON body")
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
snap, err := s.snapshotEngine.Create(workload, settings, body.Label)
|
||||
if err != nil {
|
||||
// "no snapshottable volume data" is client-actionable (400, safe to
|
||||
// echo). Any other error is server-side: log the detail, return a
|
||||
// generic 500 so internal paths / DB text never reach the client.
|
||||
if errors.Is(err, volsnap.ErrNoSnapshotData) {
|
||||
respondError(w, http.StatusBadRequest, err.Error())
|
||||
return
|
||||
}
|
||||
slog.Error("snapshots: create", "workload", id, "error", err)
|
||||
respondError(w, http.StatusInternalServerError, "internal server error")
|
||||
return
|
||||
}
|
||||
respondJSON(w, http.StatusCreated, snap)
|
||||
}
|
||||
|
||||
// deleteSnapshot handles DELETE /api/snapshots/{sid}.
|
||||
func (s *Server) deleteSnapshot(w http.ResponseWriter, r *http.Request) {
|
||||
if s.snapshotEngine == nil {
|
||||
respondError(w, http.StatusServiceUnavailable, "snapshot engine not initialized")
|
||||
return
|
||||
}
|
||||
sid := chi.URLParam(r, "sid")
|
||||
if err := s.snapshotEngine.Delete(sid); err != nil {
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
respondError(w, http.StatusNotFound, "snapshot not found")
|
||||
return
|
||||
}
|
||||
respondError(w, http.StatusInternalServerError, "failed to delete snapshot")
|
||||
return
|
||||
}
|
||||
respondJSON(w, http.StatusOK, map[string]string{"status": "deleted"})
|
||||
}
|
||||
|
||||
// downloadSnapshot handles GET /api/snapshots/{sid}/download, streaming the
|
||||
// tar.gz archive. The resolved path is containment-checked against the
|
||||
// snapshot directory.
|
||||
func (s *Server) downloadSnapshot(w http.ResponseWriter, r *http.Request) {
|
||||
if s.snapshotEngine == nil {
|
||||
respondError(w, http.StatusServiceUnavailable, "snapshot engine not initialized")
|
||||
return
|
||||
}
|
||||
sid := chi.URLParam(r, "sid")
|
||||
snap, err := s.snapshotEngine.Get(sid)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusNotFound, "snapshot not found")
|
||||
return
|
||||
}
|
||||
path, err := s.snapshotEngine.FilePath(snap)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusForbidden, "access denied")
|
||||
return
|
||||
}
|
||||
f, err := os.Open(path)
|
||||
if err != nil {
|
||||
respondError(w, http.StatusNotFound, "snapshot file not found on disk")
|
||||
return
|
||||
}
|
||||
defer f.Close()
|
||||
stat, err := f.Stat()
|
||||
if err != nil {
|
||||
respondError(w, http.StatusInternalServerError, "failed to read snapshot file")
|
||||
return
|
||||
}
|
||||
name := filepath.Base(snap.Filename)
|
||||
w.Header().Set("Content-Type", "application/gzip")
|
||||
w.Header().Set("Content-Disposition", "attachment; filename=\""+name+"\"")
|
||||
http.ServeContent(w, r, name, stat.ModTime(), f)
|
||||
}
|
||||
@@ -0,0 +1,178 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"github.com/alexei/tinyforge/internal/auth"
|
||||
"github.com/alexei/tinyforge/internal/store"
|
||||
"github.com/alexei/tinyforge/internal/volsnap"
|
||||
"github.com/alexei/tinyforge/internal/webhook"
|
||||
)
|
||||
|
||||
// newSnapshotEnv builds an API test env with the volume-snapshot engine wired
|
||||
// (the shared newAPITestEnv does not wire it). dataDir holds the snapshot
|
||||
// archives; baseVol is where host-bind volume directories resolve.
|
||||
func newSnapshotEnv(t *testing.T) (*apiTestEnv, string) {
|
||||
t.Helper()
|
||||
st, err := store.New(":memory:")
|
||||
if err != nil {
|
||||
t.Fatalf("create store: %v", err)
|
||||
}
|
||||
t.Cleanup(func() { st.Close() })
|
||||
|
||||
encKey := [32]byte{1, 2, 3, 4, 5, 6, 7, 8, 9, 10}
|
||||
dispatcher := &fakeAPIDispatcher{}
|
||||
wh := webhook.NewHandler(st)
|
||||
wh.SetPluginDispatcher(dispatcher)
|
||||
srv := NewServer(st, nil, nil, nil, dispatcher, nil, wh, nil, encKey)
|
||||
|
||||
snapEng, err := volsnap.New(st, t.TempDir())
|
||||
if err != nil {
|
||||
t.Fatalf("snapshot engine: %v", err)
|
||||
}
|
||||
srv.SetSnapshotEngine(snapEng)
|
||||
|
||||
httpsrv := httptest.NewServer(srv.Router())
|
||||
t.Cleanup(httpsrv.Close)
|
||||
|
||||
la := auth.NewLocalAuth(encKey)
|
||||
tok, err := la.GenerateToken(auth.Claims{UserID: "u-admin", Username: "admin", Role: "admin"})
|
||||
if err != nil {
|
||||
t.Fatalf("mint token: %v", err)
|
||||
}
|
||||
|
||||
baseVol := t.TempDir()
|
||||
settings, _ := st.GetSettings()
|
||||
settings.BaseVolumePath = baseVol
|
||||
if err := st.UpdateSettings(settings); err != nil {
|
||||
t.Fatalf("update settings: %v", err)
|
||||
}
|
||||
|
||||
return &apiTestEnv{srv: httpsrv, store: st, dispatcher: dispatcher, adminToken: tok.Token, encKey: encKey}, baseVol
|
||||
}
|
||||
|
||||
func TestVolumeSnapshots_EndToEnd(t *testing.T) {
|
||||
e, baseVol := newSnapshotEnv(t)
|
||||
|
||||
w, err := e.store.CreateWorkload(store.Workload{
|
||||
Name: "data-app",
|
||||
Kind: "project",
|
||||
SourceKind: "image",
|
||||
SourceConfig: `{"image":"registry.example.com/owner/app","port":8080}`,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("create workload: %v", err)
|
||||
}
|
||||
if _, err := e.store.SetWorkloadVolume(store.WorkloadVolume{
|
||||
WorkloadID: w.ID, Target: "/data", Source: "data", Scope: "project",
|
||||
}); err != nil {
|
||||
t.Fatalf("set volume: %v", err)
|
||||
}
|
||||
|
||||
// Materialize the resolved host-bind dir with a file so there is data to
|
||||
// capture. Layout mirrors ResolveWorkloadPath for project scope:
|
||||
// <baseVol>/<name>-<id8>/<source>.
|
||||
id8 := w.ID
|
||||
if len(id8) > 8 {
|
||||
id8 = id8[:8]
|
||||
}
|
||||
hostDir := filepath.Join(baseVol, "data-app-"+id8, "data")
|
||||
if err := os.MkdirAll(hostDir, 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(filepath.Join(hostDir, "payload.txt"), []byte("important"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
// snapshotable lists the one host-bind volume.
|
||||
resp := e.do(t, http.MethodGet, "/api/workloads/"+w.ID+"/snapshotable", nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
t.Fatalf("snapshotable status = %d", resp.StatusCode)
|
||||
}
|
||||
var snapable struct {
|
||||
Volumes []map[string]string `json:"volumes"`
|
||||
Skipped []map[string]string `json:"skipped"`
|
||||
}
|
||||
decodeEnvelope(t, resp, &snapable)
|
||||
if len(snapable.Volumes) != 1 || snapable.Volumes[0]["target"] != "/data" {
|
||||
t.Fatalf("expected 1 snapshotable volume /data, got %+v", snapable)
|
||||
}
|
||||
|
||||
// Create a snapshot.
|
||||
resp = e.do(t, http.MethodPost, "/api/workloads/"+w.ID+"/snapshots", map[string]string{"label": "before upgrade"})
|
||||
if resp.StatusCode != http.StatusCreated {
|
||||
t.Fatalf("create snapshot status = %d", resp.StatusCode)
|
||||
}
|
||||
var snap store.VolumeSnapshot
|
||||
decodeEnvelope(t, resp, &snap)
|
||||
if snap.ID == "" || snap.SizeBytes == 0 || snap.Label != "before upgrade" {
|
||||
t.Fatalf("unexpected snapshot: %+v", snap)
|
||||
}
|
||||
|
||||
// It appears in the list.
|
||||
resp = e.do(t, http.MethodGet, "/api/workloads/"+w.ID+"/snapshots", nil)
|
||||
var list []store.VolumeSnapshot
|
||||
decodeEnvelope(t, resp, &list)
|
||||
if len(list) != 1 || list[0].ID != snap.ID {
|
||||
t.Fatalf("expected 1 snapshot in list, got %+v", list)
|
||||
}
|
||||
|
||||
// Download streams a non-empty gzip archive (not the JSON envelope).
|
||||
resp = e.do(t, http.MethodGet, "/api/snapshots/"+snap.ID+"/download", nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
t.Fatalf("download status = %d", resp.StatusCode)
|
||||
}
|
||||
if ct := resp.Header.Get("Content-Type"); ct != "application/gzip" {
|
||||
t.Errorf("download content-type = %q, want application/gzip", ct)
|
||||
}
|
||||
data, _ := io.ReadAll(resp.Body)
|
||||
resp.Body.Close()
|
||||
if len(data) == 0 {
|
||||
t.Error("download body is empty")
|
||||
}
|
||||
|
||||
// Delete removes it.
|
||||
resp = e.do(t, http.MethodDelete, "/api/snapshots/"+snap.ID, nil)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
t.Fatalf("delete status = %d", resp.StatusCode)
|
||||
}
|
||||
resp = e.do(t, http.MethodGet, "/api/workloads/"+w.ID+"/snapshots", nil)
|
||||
var after []store.VolumeSnapshot
|
||||
decodeEnvelope(t, resp, &after)
|
||||
if len(after) != 0 {
|
||||
t.Fatalf("expected 0 snapshots after delete, got %d", len(after))
|
||||
}
|
||||
}
|
||||
|
||||
func TestCreateSnapshot_NoVolumeData_Returns400(t *testing.T) {
|
||||
e, _ := newSnapshotEnv(t)
|
||||
w, err := e.store.CreateWorkload(store.Workload{
|
||||
Name: "no-vol-app",
|
||||
Kind: "project",
|
||||
SourceKind: "image",
|
||||
SourceConfig: `{"image":"x","port":80}`,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("create workload: %v", err)
|
||||
}
|
||||
resp := e.do(t, http.MethodPost, "/api/workloads/"+w.ID+"/snapshots", nil)
|
||||
if resp.StatusCode != http.StatusBadRequest {
|
||||
t.Fatalf("expected 400 for an app with no snapshottable volumes, got %d", resp.StatusCode)
|
||||
}
|
||||
resp.Body.Close()
|
||||
}
|
||||
|
||||
func TestSnapshotEndpoints_RequireWorkload(t *testing.T) {
|
||||
e, _ := newSnapshotEnv(t)
|
||||
// snapshotable on an unknown workload → 404.
|
||||
resp := e.do(t, http.MethodGet, "/api/workloads/does-not-exist/snapshotable", nil)
|
||||
if resp.StatusCode != http.StatusNotFound {
|
||||
t.Fatalf("snapshotable unknown workload = %d, want 404", resp.StatusCode)
|
||||
}
|
||||
resp.Body.Close()
|
||||
}
|
||||
Reference in New Issue
Block a user