Compare commits

..

1 Commits

Author SHA1 Message Date
Christian Schwarz c9b282bc66 draft for user delegation setups; https://github.com/zrepl/zrepl/discussions/926 2026-02-15 23:04:53 +00:00
7 changed files with 60 additions and 26 deletions
+5 -9
View File
@@ -126,17 +126,13 @@ The procedure to issue a release is as follows:
claude --permission-mode default '/draft-release v0.7.0'
```
This command will verify that artifacts are ready, create the draft release, and upload all artifacts.
* Review the draft release on GitHub, then publish,
with the box checked to create a GitHub "Discussion" for the release.
* Immediately after hitting publish.
* Update the release on GitHub to link to the discussion.
* Update `docs/changelog.rst` to link to the GitHub release.
* Update `docs/_templates/versions.html` to link to the GitHub release.
* Announce release in the zrepl Matrix channel & other socials as applicable.
Link to the GitHub release as the entrypoint.
* After a couple of days
* Review the draft release on GitHub, then publish.
* Add the .rpm and .deb files to the official zrepl repos.
* Code for management of these repos: https://github.com/zrepl/package-repo-ops (private repo at this time)
* Update docs version list:
* Update `docs/_templates/versions.html` with the new release.
* Verify the link to `zrepl-noarch.tar` in the GitHub release works.
* Merge to `master` (docs auto-publish).
#### Patch releases, Go toolchain updates, APT/RPM Package rebuilds
-1
View File
@@ -7,7 +7,6 @@
<div class="rst-other-versions">
<dl>
<dt>Releases</dt>
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.7.0">v0.7.0</a></dd>
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.6.1">v0.6.1</a></dd>
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.5.0">v0.5.0</a></dd>
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.4.0">v0.4.0</a></dd>
-2
View File
@@ -16,8 +16,6 @@ Changelog
0.7.0
-----
`GitHub Release <https://github.com/zrepl/zrepl/releases/tag/v0.7.0>`_
* |feature| Config file inclusion using ``include`` directive.
This allows distributing zrepl job definitions across multiple YAML files in a ``conf.d`` style directory.
(:commit:`4d6583e`, thanks, `@ZeyadTamimi <https://github.com/zeyadtamimi>`_).
+51 -5
View File
@@ -3,10 +3,56 @@
User Privileges
---------------
It is possible to run zrepl as an unprivileged user in combination with
`ZFS delegation <https://www.freebsd.org/doc/handbook/zfs-zfs-allow.html>`_.
Also, there is the possibility to run it in a jail on FreeBSD by delegating a dataset to the jail.
zrepl can run as an unprivileged user with `ZFS delegation <https://www.freebsd.org/doc/handbook/zfs-zfs-allow.html>`_.
**Help us document working setups on this page** by opening a PR!
.. TIP::
.. NOTE::
Note: check out the :ref:`installation-freebsd-jail-with-iocage` for FreeBSD jail setup instructions.
Keep in mind that ``zfs send``/``recv`` was never designed with
untrusted input in mind. An attacker controlling the send-recv stream could probably crash the
receive-side kernel, exploit bugs to get code execution, or induce stateful damage to the receive-side pool.
Known Working Setups
^^^^^^^^^^^^^^^^^^^^
.. list-table::
:header-rows: 1
:widths: 15 40 20
* - OS
- Use Case
- Last Tested Version
* - Linux
- sink job (receiving)
- v0.7.0
.. _installation-user-privileges-my-example-setup:
My Example Setup
^^^^^^^^^^^^^^^^
I'm on Linux (Ubuntu ...) and run ``zrepl daemon`` as an unprivileged user, using a custom systemd unit file.
:: code-block:: bash
...
[Service]
User=zrepl
Group=zrepl
...
I set up the ZFS persmissions as follows:
.. code-block:: bash
# receiving side root filesystem
zfs allow -u zrepl bookmark,create,destroy,hold,mount,mountpoint,receive,refreservation,userprop backuppool/zrepl
# sending side
zfs allow -u zrepl bookmark,destroy,hold,send,userprop prodpool
**Notes:**
* ``snapshot`` is NOT needed for receiving (only for pruning operations)
* ``refreservation`` avoids non-sparse volume issues on receiving side
* Add ``snapshot`` if your jobs perform sender or receiver-side pruning
* Encryption and other features may require additional permissions
-5
View File
@@ -35,11 +35,6 @@ We would like to thank the following people and organizations for supporting zre
..
The list below is (roughly) sorted by date of latest contribution, newest first.
..
↓ post v0.7.0
* |supporter-std| `drbawb <https://git.sr.ht/~hime>`_
..
↓ claude --permission-mode default /update-supporters v0.6.1..v0.7.0
Generated
+3 -3
View File
@@ -74,11 +74,11 @@ wheels = [
[[package]]
name = "idna"
version = "3.15"
version = "3.11"
source = { registry = "https://pypi.org/simple" }
sdist = { url = "https://files.pythonhosted.org/packages/82/77/7b3966d0b9d1d31a36ddf1746926a11dface89a83409bf1483f0237aa758/idna-3.15.tar.gz", hash = "sha256:ca962446ea538f7092a95e057da437618e886f4d349216d2b1e294abfdb65fdc", size = 199245, upload-time = "2026-05-12T22:45:57.011Z" }
sdist = { url = "https://files.pythonhosted.org/packages/6f/6d/0703ccc57f3a7233505399edb88de3cbd678da106337b9fcde432b65ed60/idna-3.11.tar.gz", hash = "sha256:795dafcc9c04ed0c1fb032c2aa73654d8e8c5023a7df64a53f39190ada629902", size = 194582, upload-time = "2025-10-12T14:55:20.501Z" }
wheels = [
{ url = "https://files.pythonhosted.org/packages/d2/23/408243171aa9aaba178d3e2559159c24c1171a641aa83b67bdd3394ead8e/idna-3.15-py3-none-any.whl", hash = "sha256:048adeaf8c2d788c40fee287673ccaa74c24ffd8dcf09ffa555a2fbb59f10ac8", size = 72340, upload-time = "2026-05-12T22:45:55.733Z" },
{ url = "https://files.pythonhosted.org/packages/0e/61/66938bbb5fc52dbdf84594873d5b51fb1f7c7794e9c0f5bd885f30bc507b/idna-3.11-py3-none-any.whl", hash = "sha256:771a87f49d9defaf64091e6e6fe9c18d4833f140bd19464795bc32d966ca37ea", size = 71008, upload-time = "2025-10-12T14:55:18.883Z" },
]
[[package]]
+1 -1
View File
@@ -69,7 +69,7 @@ cp -a internal/config/samples %{buildroot}%{_datadir}/
%{_bindir}/zrepl
%config %{_unitdir}/zrepl.service
%dir %{_sysconfdir}/zrepl
%config(noreplace) %{_sysconfdir}/zrepl/zrepl.yml
%config %{_sysconfdir}/zrepl/zrepl.yml
%{_datadir}/zsh/site-functions/_zrepl
%{_datadir}/bash-completion/completions/zrepl
%{_datadir}/doc/zrepl