284 Commits
Author SHA1 Message Date
Paul Makles 7a04d36482 fix: explicitly mark keepLast as an integer (#632) 2026-09-09 10:45:45 +00:00
Paul Makles 037745c682 feat: use restic proxy in orchestrator when available (#631) 2026-09-09 11:02:19 +01:00
Devin Buhl b03e7d1c93 ci: use official mise action and lock tools for linux/macos x64/arm64 (#624)
Signed-off-by: Devin Buhl <devin@buhl.casa>
2026-09-03 09:36:36 -04:00
Paul Makles 312062e33c feat: standalone app login & work around Zitadel race condition (#556) 2026-09-03 13:35:35 +01:00
Paul Makles f31f9be024 feat: destructive actions - delete repos & disable write-only (#607) 2026-09-03 13:02:52 +01:00
Paul Makles 76d48c26b4 feat: restic proxy (#611)
* feat(restic proxy): initial commit

* feat(restic proxy): working impl.

* fix(restic proxy): use repoId as grant key

* fix(restic proxy): handle http errors for meta

* fix(restic proxy): close http response body

* fix(restic proxy): use path not encoded path

* fix(restic proxy): unset RawPath

* docs(restic proxy): notes for later work

* fix(restic proxy): timeout on meta requests

* fix(restic proxy): concurrent minting

* fix(restic proxy): don't nil error

* fix(restic proxy): robust claims/exp check

* docs(restic proxy): document next work

* fix(restic proxy): respect log level

* chore(restic proxy): set default log level to info

* fix(restic proxy): permit temporary failures

* refactor(restic proxy): remove exit dead code

* chore: mise config

* feat(restic proxy): configurable well known URL

* chore(restic proxy): use real Exp

* refactor(restic proxy): use username as repoId

* fix(restic proxy): check repositoryId is set

* test(restic proxy): generate tests

* feat(restic proxy): publish Dockerfile

* feat(standalone app): include restic-proxy binary

* refactor(restic proxy): allow configuring api & meta URLs
test: generate accompanying tests

* chore: set config_roots

* test: drop comments from generated tests

* docs(restic proxy): add to USER_MANUAL

* fix(restic proxy): remint grant if auth token changes

* chore(restic proxy): update mise.toml

* refactor(restic proxy): differentiate session token w. 'token'
feat(restic proxy): denial cache
test(restic proxy): update generated tests for deny cache

* chore: remove `restic-proxy:check` from `check` dependencies (covered by
lint)
2026-09-02 16:37:31 +01:00
Andy Molenda b9d60c667f feat(monk): count scrub completions and track omap bytes (#617)
Backlog size and age answer how far behind the cluster is; nothing answered how fast it drains. Ceph exports no per-PG completion counter, and the old dashboard approximated pace from OSD scrub read-byte counters, which mixed raw bytes with logical ones and counted a re-scrub of the same PG as progress.

monk now diffs each PG's stamp against the previous refresh and counts the PGs and bytes that actually completed a scrub. A PG missing from either side is skipped rather than counted, so pool deletion and PG splits do not register as completions, and the first refresh after start has no predecessor so the counters simply begin at zero.

These are counters, so they dedup differently from the gauges: rate first, then `max by (cluster, pool_id)`. Taking `max` across instances before `rate` would read an instance restart as a jump, because the five instances start at different times and each counts independently. The README carries that rule and the time-to-clear query.

Also tracks omap apart from data bytes. `stat_sum.num_bytes` excludes omap, so `prod-z1.rgw.buckets.index` reports zero bytes while holding 164 GB across 524M keys on spice: every one of its PGs could go overdue without moving byte-weighted coverage. Existing metrics keep their meaning and `ceph_scrub_pool_bytes` still matches `ceph_pool_stored`; the omap figures are additive.

- `main` <!-- branch-stack -->
  - \#617 :point\_left:
2026-09-01 14:33:22 -07:00
immich-push-o-matic[bot] cf3795a196 chore(main): release 0.38.0 (#538) 2026-09-01 07:00:32 -04:00
Paul Makles a08e47ff8a fix: align migrations to actual schema & correct migrations task (#608) 2026-09-01 11:41:17 +01:00
Antoine Lecompte 7750b71620 fix(futo-backups-bot): ignore interactions from other guilds (#602) 2026-08-31 15:42:57 -07:00
Antoine Lecompte bb0cd74bee feat(columbo): give the agent fixed fleet-health probes and a bigger tool budget (#600) 2026-08-31 16:10:02 -04:00
Antoine Lecompte 8e9cd64c16 feat(columbo): retry model calls with per-attempt deadlines (#598) 2026-08-31 11:28:12 -07:00
Andy Molenda 16d9c700ce fix(monk): harden failure paths, exec handling, and the metric contract (#592)
* fix(monk): harden failure paths, exec handling, and the metric contract

* fix(monk): log collection state transitions, not every failing refresh

* fix(monk): correct exec cancellation, waitdelay scope, and log levels
2026-08-31 06:26:57 -07:00
Antoine Lecompte ce32472f89 fix(michael): log the resolved route plus op and blob_type on access lines (#597) 2026-08-31 08:38:17 -04:00
Antoine Lecompte 500107b5ce feat(columbo): triage-refusal staff notes + per-user telemetry catalog (#596) 2026-08-31 08:38:05 -04:00
Andy Molenda 919398b0c9 feat(monk): add monk, a measured ceph scrub-backlog exporter (#587)
* feat(monk): add monk, a measured ceph scrub-backlog exporter

* fix(monk): harden collection failure paths

* docs(monk): defer the deploy role reference to its follow-up PR

* fix(monk): emit the age distribution as a real histogram and document operational contracts

* feat(monk): read overdue targets from the cluster instead of flags

* ci(monk): register the monk image build filter

* chore(monk): cut comments the types already carry
2026-08-28 14:55:11 -07:00
Andy Molenda e2a7f657a8 test(yucca-admin-api): expect discordLink in the single-user response (#590) 2026-08-28 13:11:29 -07:00
Antoine Lecompte b3aa57dc5d feat(columbo): per-investigation audit log, tool-error recovery, pipe-aware log scoping (#586) 2026-08-28 13:57:28 -04:00
Antoine Lecompte 88267dc1f7 feat(columbo): add columbo (#585) 2026-08-28 13:26:11 -04:00
Antoine Lecompte 7988ac3487 fix(futo-backups-bot): fall back to a generic agent name when the profile read is forbidden (#584) 2026-08-27 12:51:41 -07:00
Antoine Lecompte 4e56080e0b feat(futo-backups-bot): bidirectional freshdesk sync for support tickets (#577) 2026-08-27 13:09:21 -04:00
Antoine Lecompte 121987ff79 feat(yucca-api): discord ticket to freshdesk mapping table and internal endpoints (#576) 2026-08-27 13:09:20 -04:00
Antoine Lecompte b726229b14 feat(yucca-admin-api): manage and cancel discord beta-invite drops via yuctl (#575) 2026-08-26 20:15:05 +01:00
Antoine Lecompte cca37e0200 refactor(futo-backups-bot): centralize user-facing copy in messages.ts (#574) 2026-08-26 14:18:07 -04:00
Antoine Lecompte 003cb71435 fix(futo-backups-bot): mention the everyone role as a literal @everyone (#573) 2026-08-26 13:54:37 -04:00
Antoine Lecompte 9abf625652 feat(futo-backups-bot): /beta-invite with personal links, claim batches, and optional role mention (#571) 2026-08-26 13:41:04 -04:00
Antoine Lecompte 6a37d2674a feat(web): discord beta-invite redemption on the invite page (#570) 2026-08-26 13:41:04 -04:00
Antoine Lecompte 85f3a59b2a feat(yucca-api): discord closed-beta invite claims and nonced redemption (#569) 2026-08-26 13:41:03 -04:00
Antoine Lecompte f7e60f0d41 feat(futo-backups-bot): /claim-backups-role grants the customer role (#567) 2026-08-26 09:58:48 -04:00
Antoine Lecompte 2172679a36 feat(futo-backups-bot): /staff-notes links the paired staff thread (#566) 2026-08-26 08:55:33 -04:00
Antoine Lecompte 4442740ad9 feat(futo-backups-bot): sync the stored discord username from interactions (#563) 2026-08-26 08:54:35 -04:00
Antoine Lecompte 3167a48583 feat(yucca-admin-api): manage discord links via admin-api and yuctl (#562) 2026-08-26 08:54:22 -04:00
Antoine Lecompte 290e3d7a65 feat(futo-backups-bot): allow up to three open tickets per user (#561) 2026-08-26 12:31:52 +00:00
Antoine Lecompte 5eaf0f349d feat(futo-backups-bot): grafana per-user link in staff notes (#560) 2026-08-26 12:26:07 +00:00
Antoine Lecompte eb89c13118 fix(admin): wire-in the admin-api like prod (#559) 2026-08-26 12:20:09 +00:00
Antoine Lecompte e61dabe7e3 fix(futo-backups-bot): avoid the privileged thread-member listing (#557) 2026-08-26 08:13:36 -04:00
Antoine Lecompte 717ab17e18 fix(futo-backups-bot): pull staff into the staff-notes thread (#558) 2026-08-26 08:06:06 -04:00
Antoine Lecompte bed87ba085 fix(futo-backups-bot): dedupe the support sticky and survive pin failures (#551) 2026-08-25 19:35:29 +00:00
Antoine Lecompte f1bd9cf33e fix(futo-backups-bot): survive missing applications.commands scope (#550) 2026-08-25 18:55:21 +00:00
Antoine Lecompte 5ad08e27d7 feat(infra): deploy futo-backups-bot (#545) 2026-08-25 14:24:51 -04:00
Antoine Lecompte 474879f399 feat(futo-backups-bot): discord support bot (#544) 2026-08-25 14:24:50 -04:00
Antoine Lecompte 93d90e3ecf feat(web): discord link confirmation page (#543) 2026-08-25 14:24:50 -04:00
Antoine Lecompte 7f61914cd8 feat(yucca-api): discord account linking (#542) 2026-08-25 14:24:50 -04:00
immich-push-o-matic[bot] db235b2b58 chore(main): release 0.37.1 (#536) 2026-08-24 09:27:06 -04:00
Antoine Lecompte dd12594761 fix(migrations): re-date again (#535) 2026-08-24 09:25:52 -04:00
immich-push-o-matic[bot] cbb6d5d966 chore(main): release 0.37.0 (#533) 2026-08-24 12:58:50 +00:00
Antoine Lecompte 30166e0733 feat(yucca-admin-api): send invite emails from the allowlist flow (#492) 2026-08-24 06:44:59 -04:00
Antoine Lecompte 1d92b4b0c1 feat(emails): mailpit + mock-postmark local dev stack (#491) 2026-08-24 06:44:59 -04:00
Antoine Lecompte 2fc89b105b feat(common): postmark-backed email repository (#490) 2026-08-24 06:44:59 -04:00
Antoine Lecompte 54c880229b feat(emails): svelte invite email template rendered with the web theme (#489) 2026-08-24 06:44:58 -04:00