Enable HEIC previews and document Nextcloud recovery

This commit is contained in:
Fabio Scotto di Santolo
2026-10-06 20:05:42 +02:00
parent bb67c406da
commit 7db322039e
5 changed files with 85 additions and 11 deletions

View File

@@ -391,8 +391,11 @@ the actual service result and pool scan were independently verified.
On 2026-10-04 Borg archive `atlas-20261004T095255Z` succeeded; its new bundle was
extracted from Hetzner and restored in isolation with checksums, accounts, Famiglia
permissions and authenticated DAV verified. No production database was replaced.
- [ ] Validate a new USB version and restore its consistent Nextcloud bundle after
operator connection/unlock. Dependency installation alone is not restore evidence.
- [x] Validate a new USB version and restore its consistent Nextcloud bundle. On
2026-10-04 USB version `20261004T101101Z-3420114` completed successfully; bundle
`20261004T100959Z-3415600` was read-only extracted, checksum-verified and restored
in isolation. Accounts, Famiglia permissions and authenticated DAV passed. The
test copy/containers were removed, LUKS closed and the pool remained healthy.
- [ ] Complete Nextcloud desktop/mobile editing and synchronization acceptance before family import.
iCloud migration and future Uranus transfer remain separate operations, not playbook flags.
- [x] Move Gitea canonical HTTPS and SSH hostname to `git.fscotto.co` on

View File

@@ -11,6 +11,20 @@ $CONFIG = [
'skeletondirectory' => '',
'maintenance_window_start' => 1,
'default_phone_region' => 'IT',
// Preserve the standard providers and add Apple HEIC/HEIF previews.
'enabledPreviewProviders' => [
'OC\\Preview\\PNG',
'OC\\Preview\\JPEG',
'OC\\Preview\\GIF',
'OC\\Preview\\BMP',
'OC\\Preview\\XBitmap',
'OC\\Preview\\Krita',
'OC\\Preview\\WebP',
'OC\\Preview\\MarkDown',
'OC\\Preview\\TXT',
'OC\\Preview\\OpenDocument',
'OC\\Preview\\HEIC',
],
'twofactor_enforced' => false,
'onlyoffice' => [
'DocumentServerUrl' => 'https://{{ atlas_onlyoffice_domain }}/',

View File

@@ -3,9 +3,9 @@
Status: the empty stack was deployed on 2026-10-03, explicitly before the first
scrub. The operator configured DNS/NPM and authorized public cutover; public TLS,
DAV and cross-user file checks passed. The first scrub and a manual consistent
backup/isolated restore passed on 2026-10-04. Client editing/sync acceptance and
USB recovery validation remain open before family data. Recurring backup integration
and recovery from a new Borg archive passed. iCloud import remains a
backup/isolated restore passed on 2026-10-04. Client editing/sync acceptance
remains open before family data. Recurring backup integration and recovery from
new Borg and offline USB versions passed. iCloud import remains a
separate operation. See `docs/atlas-nextcloud.md` for observed runtime state.
## Confirmed requirements
@@ -97,9 +97,7 @@ acceptance tests; the app is not treated as proof of server-side compatibility.
1. Validate desktop Office editing/saving, calendar/contact synchronization and
mobile ONLYOFFICE app integration; public empty-stack cutover is verified.
2. Complete recovery from a new offline USB version; recurring preparation and
encrypted Borg recovery have passed.
3. Plan the deferred iCloud migration when explicitly requested.
2. Plan the deferred iCloud migration when explicitly requested.
## Primary references

View File

@@ -121,6 +121,28 @@ A third preparation published `20261004T100212Z-3366172`; exactly two managed
versions remained, with the oldest version pruned only after publication. Source
snapshots and persistent interruption markers were absent after success.
A new UUID-bound USB version and recovery of its consistent Nextcloud bundle
remain to be verified after the operator connects/unlocks the configured disk.
Do not mark USB recovery complete merely because the dependency was installed.
## Offline USB recovery, 2026-10-04
The operator unlocked the UUID-bound disk. Starting the USB job required fresh
bundle `20261004T100959Z-3415600` before the pool snapshot. USB version
`20261004T101101Z-3420114` passed its full checksum comparison and publication;
the service finished successfully at 18:41:29 Europe/Rome. Its recursive temporary
source snapshot was removed and LUKS closed.
After a second operator unlock, the published USB version was mounted read-only
with ext4 journal replay disabled. The consistent bundle was SHA-256 verified on
USB and again after extraction into a private temporary directory. A fresh
network-none pod restored PostgreSQL globals/database, application and files with
the recorded image digests, using a separate database and cache. Nextcloud 33.0.9
reported installed, maintenance off and no database upgrade required. All three
accounts, Famiglia permissions and authenticated DAV PROPFIND (HTTP 207) for
admin, fabio and chiara passed. No external network, published ports or live bind
mounts were present.
The USB was unmounted and LUKS closed. The test pod, extracted copy and path marker
were removed. No USB source snapshot remained; the pool was healthy and all live
Nextcloud, PostgreSQL, Redis, ONLYOFFICE and cron units were active. Production
data was not replaced. This is application recovery evidence for the current
small stack, not production-size RPO/RTO, client resynchronization or recovery of
unsaved ONLYOFFICE editing sessions. Client acceptance remains required before
family import.

View File

@@ -176,6 +176,14 @@ run of the recurring job, not a normal deployment side effect. The preparation
unit is not enabled as a boot backup; only interrupted-job recovery is enabled.
Do not stop a Borg/USB job, break its lock or unmount its source snapshot to run a test.
On 2026-10-04, both a new encrypted Borg archive and USB version
`20261004T101101Z-3420114` were independently extracted and their consistent
Nextcloud bundles restored in isolated containers. Checksums, account recovery,
Famiglia permissions and authenticated DAV passed. Temporary restore resources
were removed; USB was safely unmounted and LUKS closed. See
`docs/atlas-nextcloud-recovery-test.md` for exact evidence and limitations.
Desktop/mobile editing and synchronization acceptance remains open before import.
## Existing Archive storage (no import or duplicate originals)
@@ -241,3 +249,32 @@ On 2026-10-04 the targeted deployment restarted only ONLYOFFICE. Nginx syntax an
Nextcloud's document-server check passed. Public root, welcome and example
requests returned 404; `/healthcheck` remained 200. This check does not replace
an authenticated browser edit/save test.
### Photos source-filter diagnosis — 2026-10-06
A recursive scan of `fabio/files/Foto iCloud` completed without errors:
1,615 folders and 11,699 files, already indexed. Authenticated DAV SEARCH returned
200 nested media results (the requested limit) for the sole `/Foto iCloud`
scope, both with and without date ordering, but zero results when the empty
`/Photos` scope was combined with it. The observed issue is the combined-source
search, not lack of recursive indexing.
The user preference `photosSourceFolders` was changed directly from
`["/Photos","/Foto iCloud"]` to `["/Foto iCloud"]`, after verifying no indexed
media under the personal Photos directory. No original files were moved or
modified, and no permanent one-time repair task was added to Ansible.
The diagnostic app password was revoked. Browser display confirmation remains
with the operator; this check does not establish mobile-gallery behavior.
### HEIC previews — 2026-10-06
The managed configuration include preserves the standard preview providers and
adds `OC\Preview\HEIC` for Apple HEIC/HEIF images. The pinned app image
already provides Imagick with HEIC/HEIF decoding. Ansible deployment succeeded;
a real indexed HEIC generated a 512×512 preview successfully, and the original
file SHA-256 was unchanged. Nextcloud, ONLYOFFICE and cron remained active.
No bulk conversion or full-library preview generation was performed.
New previews are generated on demand; browser/mobile display remains an
operator acceptance check.