mirror of
https://github.com/fscotto/infra.git
synced 2026-10-07 07:19:50 +00:00
Enable HEIC previews and document Nextcloud recovery
This commit is contained in:
@@ -391,8 +391,11 @@ the actual service result and pool scan were independently verified.
|
|||||||
On 2026-10-04 Borg archive `atlas-20261004T095255Z` succeeded; its new bundle was
|
On 2026-10-04 Borg archive `atlas-20261004T095255Z` succeeded; its new bundle was
|
||||||
extracted from Hetzner and restored in isolation with checksums, accounts, Famiglia
|
extracted from Hetzner and restored in isolation with checksums, accounts, Famiglia
|
||||||
permissions and authenticated DAV verified. No production database was replaced.
|
permissions and authenticated DAV verified. No production database was replaced.
|
||||||
- [ ] Validate a new USB version and restore its consistent Nextcloud bundle after
|
- [x] Validate a new USB version and restore its consistent Nextcloud bundle. On
|
||||||
operator connection/unlock. Dependency installation alone is not restore evidence.
|
2026-10-04 USB version `20261004T101101Z-3420114` completed successfully; bundle
|
||||||
|
`20261004T100959Z-3415600` was read-only extracted, checksum-verified and restored
|
||||||
|
in isolation. Accounts, Famiglia permissions and authenticated DAV passed. The
|
||||||
|
test copy/containers were removed, LUKS closed and the pool remained healthy.
|
||||||
- [ ] Complete Nextcloud desktop/mobile editing and synchronization acceptance before family import.
|
- [ ] Complete Nextcloud desktop/mobile editing and synchronization acceptance before family import.
|
||||||
iCloud migration and future Uranus transfer remain separate operations, not playbook flags.
|
iCloud migration and future Uranus transfer remain separate operations, not playbook flags.
|
||||||
- [x] Move Gitea canonical HTTPS and SSH hostname to `git.fscotto.co` on
|
- [x] Move Gitea canonical HTTPS and SSH hostname to `git.fscotto.co` on
|
||||||
|
|||||||
@@ -11,6 +11,20 @@ $CONFIG = [
|
|||||||
'skeletondirectory' => '',
|
'skeletondirectory' => '',
|
||||||
'maintenance_window_start' => 1,
|
'maintenance_window_start' => 1,
|
||||||
'default_phone_region' => 'IT',
|
'default_phone_region' => 'IT',
|
||||||
|
// Preserve the standard providers and add Apple HEIC/HEIF previews.
|
||||||
|
'enabledPreviewProviders' => [
|
||||||
|
'OC\\Preview\\PNG',
|
||||||
|
'OC\\Preview\\JPEG',
|
||||||
|
'OC\\Preview\\GIF',
|
||||||
|
'OC\\Preview\\BMP',
|
||||||
|
'OC\\Preview\\XBitmap',
|
||||||
|
'OC\\Preview\\Krita',
|
||||||
|
'OC\\Preview\\WebP',
|
||||||
|
'OC\\Preview\\MarkDown',
|
||||||
|
'OC\\Preview\\TXT',
|
||||||
|
'OC\\Preview\\OpenDocument',
|
||||||
|
'OC\\Preview\\HEIC',
|
||||||
|
],
|
||||||
'twofactor_enforced' => false,
|
'twofactor_enforced' => false,
|
||||||
'onlyoffice' => [
|
'onlyoffice' => [
|
||||||
'DocumentServerUrl' => 'https://{{ atlas_onlyoffice_domain }}/',
|
'DocumentServerUrl' => 'https://{{ atlas_onlyoffice_domain }}/',
|
||||||
|
|||||||
@@ -3,9 +3,9 @@
|
|||||||
Status: the empty stack was deployed on 2026-10-03, explicitly before the first
|
Status: the empty stack was deployed on 2026-10-03, explicitly before the first
|
||||||
scrub. The operator configured DNS/NPM and authorized public cutover; public TLS,
|
scrub. The operator configured DNS/NPM and authorized public cutover; public TLS,
|
||||||
DAV and cross-user file checks passed. The first scrub and a manual consistent
|
DAV and cross-user file checks passed. The first scrub and a manual consistent
|
||||||
backup/isolated restore passed on 2026-10-04. Client editing/sync acceptance and
|
backup/isolated restore passed on 2026-10-04. Client editing/sync acceptance
|
||||||
USB recovery validation remain open before family data. Recurring backup integration
|
remains open before family data. Recurring backup integration and recovery from
|
||||||
and recovery from a new Borg archive passed. iCloud import remains a
|
new Borg and offline USB versions passed. iCloud import remains a
|
||||||
separate operation. See `docs/atlas-nextcloud.md` for observed runtime state.
|
separate operation. See `docs/atlas-nextcloud.md` for observed runtime state.
|
||||||
|
|
||||||
## Confirmed requirements
|
## Confirmed requirements
|
||||||
@@ -97,9 +97,7 @@ acceptance tests; the app is not treated as proof of server-side compatibility.
|
|||||||
|
|
||||||
1. Validate desktop Office editing/saving, calendar/contact synchronization and
|
1. Validate desktop Office editing/saving, calendar/contact synchronization and
|
||||||
mobile ONLYOFFICE app integration; public empty-stack cutover is verified.
|
mobile ONLYOFFICE app integration; public empty-stack cutover is verified.
|
||||||
2. Complete recovery from a new offline USB version; recurring preparation and
|
2. Plan the deferred iCloud migration when explicitly requested.
|
||||||
encrypted Borg recovery have passed.
|
|
||||||
3. Plan the deferred iCloud migration when explicitly requested.
|
|
||||||
|
|
||||||
## Primary references
|
## Primary references
|
||||||
|
|
||||||
|
|||||||
@@ -121,6 +121,28 @@ A third preparation published `20261004T100212Z-3366172`; exactly two managed
|
|||||||
versions remained, with the oldest version pruned only after publication. Source
|
versions remained, with the oldest version pruned only after publication. Source
|
||||||
snapshots and persistent interruption markers were absent after success.
|
snapshots and persistent interruption markers were absent after success.
|
||||||
|
|
||||||
A new UUID-bound USB version and recovery of its consistent Nextcloud bundle
|
## Offline USB recovery, 2026-10-04
|
||||||
remain to be verified after the operator connects/unlocks the configured disk.
|
|
||||||
Do not mark USB recovery complete merely because the dependency was installed.
|
The operator unlocked the UUID-bound disk. Starting the USB job required fresh
|
||||||
|
bundle `20261004T100959Z-3415600` before the pool snapshot. USB version
|
||||||
|
`20261004T101101Z-3420114` passed its full checksum comparison and publication;
|
||||||
|
the service finished successfully at 18:41:29 Europe/Rome. Its recursive temporary
|
||||||
|
source snapshot was removed and LUKS closed.
|
||||||
|
|
||||||
|
After a second operator unlock, the published USB version was mounted read-only
|
||||||
|
with ext4 journal replay disabled. The consistent bundle was SHA-256 verified on
|
||||||
|
USB and again after extraction into a private temporary directory. A fresh
|
||||||
|
network-none pod restored PostgreSQL globals/database, application and files with
|
||||||
|
the recorded image digests, using a separate database and cache. Nextcloud 33.0.9
|
||||||
|
reported installed, maintenance off and no database upgrade required. All three
|
||||||
|
accounts, Famiglia permissions and authenticated DAV PROPFIND (HTTP 207) for
|
||||||
|
admin, fabio and chiara passed. No external network, published ports or live bind
|
||||||
|
mounts were present.
|
||||||
|
|
||||||
|
The USB was unmounted and LUKS closed. The test pod, extracted copy and path marker
|
||||||
|
were removed. No USB source snapshot remained; the pool was healthy and all live
|
||||||
|
Nextcloud, PostgreSQL, Redis, ONLYOFFICE and cron units were active. Production
|
||||||
|
data was not replaced. This is application recovery evidence for the current
|
||||||
|
small stack, not production-size RPO/RTO, client resynchronization or recovery of
|
||||||
|
unsaved ONLYOFFICE editing sessions. Client acceptance remains required before
|
||||||
|
family import.
|
||||||
|
|||||||
@@ -176,6 +176,14 @@ run of the recurring job, not a normal deployment side effect. The preparation
|
|||||||
unit is not enabled as a boot backup; only interrupted-job recovery is enabled.
|
unit is not enabled as a boot backup; only interrupted-job recovery is enabled.
|
||||||
Do not stop a Borg/USB job, break its lock or unmount its source snapshot to run a test.
|
Do not stop a Borg/USB job, break its lock or unmount its source snapshot to run a test.
|
||||||
|
|
||||||
|
On 2026-10-04, both a new encrypted Borg archive and USB version
|
||||||
|
`20261004T101101Z-3420114` were independently extracted and their consistent
|
||||||
|
Nextcloud bundles restored in isolated containers. Checksums, account recovery,
|
||||||
|
Famiglia permissions and authenticated DAV passed. Temporary restore resources
|
||||||
|
were removed; USB was safely unmounted and LUKS closed. See
|
||||||
|
`docs/atlas-nextcloud-recovery-test.md` for exact evidence and limitations.
|
||||||
|
Desktop/mobile editing and synchronization acceptance remains open before import.
|
||||||
|
|
||||||
|
|
||||||
## Existing Archive storage (no import or duplicate originals)
|
## Existing Archive storage (no import or duplicate originals)
|
||||||
|
|
||||||
@@ -241,3 +249,32 @@ On 2026-10-04 the targeted deployment restarted only ONLYOFFICE. Nginx syntax an
|
|||||||
Nextcloud's document-server check passed. Public root, welcome and example
|
Nextcloud's document-server check passed. Public root, welcome and example
|
||||||
requests returned 404; `/healthcheck` remained 200. This check does not replace
|
requests returned 404; `/healthcheck` remained 200. This check does not replace
|
||||||
an authenticated browser edit/save test.
|
an authenticated browser edit/save test.
|
||||||
|
|
||||||
|
|
||||||
|
### Photos source-filter diagnosis — 2026-10-06
|
||||||
|
|
||||||
|
A recursive scan of `fabio/files/Foto iCloud` completed without errors:
|
||||||
|
1,615 folders and 11,699 files, already indexed. Authenticated DAV SEARCH returned
|
||||||
|
200 nested media results (the requested limit) for the sole `/Foto iCloud`
|
||||||
|
scope, both with and without date ordering, but zero results when the empty
|
||||||
|
`/Photos` scope was combined with it. The observed issue is the combined-source
|
||||||
|
search, not lack of recursive indexing.
|
||||||
|
|
||||||
|
The user preference `photosSourceFolders` was changed directly from
|
||||||
|
`["/Photos","/Foto iCloud"]` to `["/Foto iCloud"]`, after verifying no indexed
|
||||||
|
media under the personal Photos directory. No original files were moved or
|
||||||
|
modified, and no permanent one-time repair task was added to Ansible.
|
||||||
|
The diagnostic app password was revoked. Browser display confirmation remains
|
||||||
|
with the operator; this check does not establish mobile-gallery behavior.
|
||||||
|
|
||||||
|
|
||||||
|
### HEIC previews — 2026-10-06
|
||||||
|
|
||||||
|
The managed configuration include preserves the standard preview providers and
|
||||||
|
adds `OC\Preview\HEIC` for Apple HEIC/HEIF images. The pinned app image
|
||||||
|
already provides Imagick with HEIC/HEIF decoding. Ansible deployment succeeded;
|
||||||
|
a real indexed HEIC generated a 512×512 preview successfully, and the original
|
||||||
|
file SHA-256 was unchanged. Nextcloud, ONLYOFFICE and cron remained active.
|
||||||
|
No bulk conversion or full-library preview generation was performed.
|
||||||
|
New previews are generated on demand; browser/mobile display remains an
|
||||||
|
operator acceptance check.
|
||||||
|
|||||||
Reference in New Issue
Block a user