Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 812a2d1699 | |||
| b93a06d237 |
@@ -126,13 +126,17 @@ The procedure to issue a release is as follows:
|
|||||||
claude --permission-mode default '/draft-release v0.7.0'
|
claude --permission-mode default '/draft-release v0.7.0'
|
||||||
```
|
```
|
||||||
This command will verify that artifacts are ready, create the draft release, and upload all artifacts.
|
This command will verify that artifacts are ready, create the draft release, and upload all artifacts.
|
||||||
* Review the draft release on GitHub, then publish.
|
* Review the draft release on GitHub, then publish,
|
||||||
|
with the box checked to create a GitHub "Discussion" for the release.
|
||||||
|
* Immediately after hitting publish.
|
||||||
|
* Update the release on GitHub to link to the discussion.
|
||||||
|
* Update `docs/changelog.rst` to link to the GitHub release.
|
||||||
|
* Update `docs/_templates/versions.html` to link to the GitHub release.
|
||||||
|
* Announce release in the zrepl Matrix channel & other socials as applicable.
|
||||||
|
Link to the GitHub release as the entrypoint.
|
||||||
|
* After a couple of days
|
||||||
* Add the .rpm and .deb files to the official zrepl repos.
|
* Add the .rpm and .deb files to the official zrepl repos.
|
||||||
* Code for management of these repos: https://github.com/zrepl/package-repo-ops (private repo at this time)
|
* Code for management of these repos: https://github.com/zrepl/package-repo-ops (private repo at this time)
|
||||||
* Update docs version list:
|
|
||||||
* Update `docs/_templates/versions.html` with the new release.
|
|
||||||
* Verify the link to `zrepl-noarch.tar` in the GitHub release works.
|
|
||||||
* Merge to `master` (docs auto-publish).
|
|
||||||
|
|
||||||
#### Patch releases, Go toolchain updates, APT/RPM Package rebuilds
|
#### Patch releases, Go toolchain updates, APT/RPM Package rebuilds
|
||||||
|
|
||||||
|
|||||||
Vendored
+1
@@ -7,6 +7,7 @@
|
|||||||
<div class="rst-other-versions">
|
<div class="rst-other-versions">
|
||||||
<dl>
|
<dl>
|
||||||
<dt>Releases</dt>
|
<dt>Releases</dt>
|
||||||
|
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.7.0">v0.7.0</a></dd>
|
||||||
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.6.1">v0.6.1</a></dd>
|
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.6.1">v0.6.1</a></dd>
|
||||||
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.5.0">v0.5.0</a></dd>
|
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.5.0">v0.5.0</a></dd>
|
||||||
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.4.0">v0.4.0</a></dd>
|
<dd><a href="https://github.com/zrepl/zrepl/releases/tag/v0.4.0">v0.4.0</a></dd>
|
||||||
|
|||||||
@@ -16,6 +16,8 @@ Changelog
|
|||||||
0.7.0
|
0.7.0
|
||||||
-----
|
-----
|
||||||
|
|
||||||
|
`GitHub Release <https://github.com/zrepl/zrepl/releases/tag/v0.7.0>`_
|
||||||
|
|
||||||
* |feature| Config file inclusion using ``include`` directive.
|
* |feature| Config file inclusion using ``include`` directive.
|
||||||
This allows distributing zrepl job definitions across multiple YAML files in a ``conf.d`` style directory.
|
This allows distributing zrepl job definitions across multiple YAML files in a ``conf.d`` style directory.
|
||||||
(:commit:`4d6583e`, thanks, `@ZeyadTamimi <https://github.com/zeyadtamimi>`_).
|
(:commit:`4d6583e`, thanks, `@ZeyadTamimi <https://github.com/zeyadtamimi>`_).
|
||||||
|
|||||||
@@ -3,56 +3,10 @@
|
|||||||
User Privileges
|
User Privileges
|
||||||
---------------
|
---------------
|
||||||
|
|
||||||
zrepl can run as an unprivileged user with `ZFS delegation <https://www.freebsd.org/doc/handbook/zfs-zfs-allow.html>`_.
|
It is possible to run zrepl as an unprivileged user in combination with
|
||||||
**Help us document working setups on this page** by opening a PR!
|
`ZFS delegation <https://www.freebsd.org/doc/handbook/zfs-zfs-allow.html>`_.
|
||||||
|
Also, there is the possibility to run it in a jail on FreeBSD by delegating a dataset to the jail.
|
||||||
|
|
||||||
.. NOTE::
|
.. TIP::
|
||||||
|
|
||||||
Keep in mind that ``zfs send``/``recv`` was never designed with
|
Note: check out the :ref:`installation-freebsd-jail-with-iocage` for FreeBSD jail setup instructions.
|
||||||
untrusted input in mind. An attacker controlling the send-recv stream could probably crash the
|
|
||||||
receive-side kernel, exploit bugs to get code execution, or induce stateful damage to the receive-side pool.
|
|
||||||
|
|
||||||
|
|
||||||
Known Working Setups
|
|
||||||
^^^^^^^^^^^^^^^^^^^^
|
|
||||||
|
|
||||||
.. list-table::
|
|
||||||
:header-rows: 1
|
|
||||||
:widths: 15 40 20
|
|
||||||
|
|
||||||
* - OS
|
|
||||||
- Use Case
|
|
||||||
- Last Tested Version
|
|
||||||
* - Linux
|
|
||||||
- sink job (receiving)
|
|
||||||
- v0.7.0
|
|
||||||
|
|
||||||
.. _installation-user-privileges-my-example-setup:
|
|
||||||
|
|
||||||
My Example Setup
|
|
||||||
^^^^^^^^^^^^^^^^
|
|
||||||
|
|
||||||
I'm on Linux (Ubuntu ...) and run ``zrepl daemon`` as an unprivileged user, using a custom systemd unit file.
|
|
||||||
|
|
||||||
:: code-block:: bash
|
|
||||||
...
|
|
||||||
[Service]
|
|
||||||
User=zrepl
|
|
||||||
Group=zrepl
|
|
||||||
...
|
|
||||||
|
|
||||||
I set up the ZFS persmissions as follows:
|
|
||||||
|
|
||||||
.. code-block:: bash
|
|
||||||
|
|
||||||
# receiving side root filesystem
|
|
||||||
zfs allow -u zrepl bookmark,create,destroy,hold,mount,mountpoint,receive,refreservation,userprop backuppool/zrepl
|
|
||||||
# sending side
|
|
||||||
zfs allow -u zrepl bookmark,destroy,hold,send,userprop prodpool
|
|
||||||
|
|
||||||
**Notes:**
|
|
||||||
|
|
||||||
* ``snapshot`` is NOT needed for receiving (only for pruning operations)
|
|
||||||
* ``refreservation`` avoids non-sparse volume issues on receiving side
|
|
||||||
* Add ``snapshot`` if your jobs perform sender or receiver-side pruning
|
|
||||||
* Encryption and other features may require additional permissions
|
|
||||||
|
|||||||
@@ -39,7 +39,7 @@ require (
|
|||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
filippo.io/edwards25519 v1.1.0 // indirect
|
filippo.io/edwards25519 v1.1.1 // indirect
|
||||||
github.com/felixge/fgprof v0.9.5 // indirect
|
github.com/felixge/fgprof v0.9.5 // indirect
|
||||||
github.com/gabriel-vasile/mimetype v1.4.13 // indirect
|
github.com/gabriel-vasile/mimetype v1.4.13 // indirect
|
||||||
github.com/google/pprof v0.0.0-20260202012954-cb029daf43ef // indirect
|
github.com/google/pprof v0.0.0-20260202012954-cb029daf43ef // indirect
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
filippo.io/edwards25519 v1.1.0 h1:FNf4tywRC1HmFuKW5xopWpigGjJKiJSV0Cqo0cJWDaA=
|
filippo.io/edwards25519 v1.1.1 h1:YpjwWWlNmGIDyXOn8zLzqiD+9TyIlPhGFG96P39uBpw=
|
||||||
filippo.io/edwards25519 v1.1.0/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4=
|
filippo.io/edwards25519 v1.1.1/go.mod h1:BxyFTGdWcka3PhytdK4V28tE5sGfRvvvRV7EaN4VDT4=
|
||||||
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
|
github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM=
|
||||||
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
||||||
github.com/bits-and-blooms/bitset v1.24.4 h1:95H15Og1clikBrKr/DuzMXkQzECs1M6hhoGXLwLQOZE=
|
github.com/bits-and-blooms/bitset v1.24.4 h1:95H15Og1clikBrKr/DuzMXkQzECs1M6hhoGXLwLQOZE=
|
||||||
|
|||||||
Reference in New Issue
Block a user