docs(apsuflow): separate host data migration
This commit is contained in:
@@ -96,7 +96,13 @@ supply them with `--admin-token` and `--agent-token`. Pass
|
|||||||
`--allow-secret-env` and `--acknowledge-recovery-risk` when the reviewed
|
`--allow-secret-env` and `--acknowledge-recovery-risk` when the reviewed
|
||||||
migration declaration requires those same explicit apply acknowledgments.
|
migration declaration requires those same explicit apply acknowledgments.
|
||||||
Commit as root only after review; it quiesces persisted services and reapplies
|
Commit as root only after review; it quiesces persisted services and reapplies
|
||||||
the exact declarations through public controls. Retain its rollback
|
the exact declarations through public controls. If the reviewed declaration
|
||||||
|
changes an existing writable host-volume source, do not add data movement to
|
||||||
|
`host migrate` and do not weaken apply's path-change refusal. First retire the
|
||||||
|
old workloads explicitly with public `apply --prune`, prove zero desired/live
|
||||||
|
containers, verify an operator-owned application backup off-host, perform the
|
||||||
|
reviewed host-data move with its own rollback boundary, and only then run
|
||||||
|
unchanged `host migrate` and reapply the exact declaration. Retain its rollback
|
||||||
directory until the split services, exact declaration reapply, and
|
directory until the split services, exact declaration reapply, and
|
||||||
application-level data checks pass. Never recursively chown workload data or
|
application-level data checks pass. Never recursively chown workload data or
|
||||||
repair migration through SQLite, OCI, CNI, firewall, or namespace mutation.
|
repair migration through SQLite, OCI, CNI, firewall, or namespace mutation.
|
||||||
|
|||||||
Reference in New Issue
Block a user