docs(apsuflow): separate host data migration
This commit is contained in:
@@ -96,7 +96,13 @@ supply them with `--admin-token` and `--agent-token`. Pass
|
||||
`--allow-secret-env` and `--acknowledge-recovery-risk` when the reviewed
|
||||
migration declaration requires those same explicit apply acknowledgments.
|
||||
Commit as root only after review; it quiesces persisted services and reapplies
|
||||
the exact declarations through public controls. Retain its rollback
|
||||
the exact declarations through public controls. If the reviewed declaration
|
||||
changes an existing writable host-volume source, do not add data movement to
|
||||
`host migrate` and do not weaken apply's path-change refusal. First retire the
|
||||
old workloads explicitly with public `apply --prune`, prove zero desired/live
|
||||
containers, verify an operator-owned application backup off-host, perform the
|
||||
reviewed host-data move with its own rollback boundary, and only then run
|
||||
unchanged `host migrate` and reapply the exact declaration. Retain its rollback
|
||||
directory until the split services, exact declaration reapply, and
|
||||
application-level data checks pass. Never recursively chown workload data or
|
||||
repair migration through SQLite, OCI, CNI, firewall, or namespace mutation.
|
||||
|
||||
Reference in New Issue
Block a user