Repository navigation
v0.6.0
The first release published by CI, and the first image whose provenance can be recovered from the image itself.
Fixed
The delete phase died on its first batch with SESSION_IS_LOCKED (ClickHouse error 373), after the objects were already removed from S3.
connect_to_ch() built a single clickhouse_connect client, which the driver gives an auto-generated session_id, and ClickHouse permits one query at a time per session. do_use() holds that session for the entire anti-join while consuming query_row_block_stream, and insert() issues its own DESCRIBE TABLE before writing — a second concurrent query on the held session. The job exited non-zero with up to --deletebatchsize objects deleted and no tombstone recorded, so a resumed run could not tell they were done.
Tombstone writes now go to a second client built in the same call.
The defect was not new; it existed in every build back to the original single-client design and had simply never fired. Every earlier delete that reclaimed data ran with --order-by-objpath, which sorts the whole result server-side before streaming, and against ClickHouse 25.x. The first run without global ordering — the documented default for Kubernetes Jobs — hit it 78 minutes in, on the first block the anti-join produced.
Added
USETOTAL is now settable from the Kubernetes Job template. --usetotal already existed on the command line and, via env_prefix="S3GC", in the environment, but the renderer never emitted it — so the only delete available to an operator deploying with the renderer was unbounded.
Bound the first delete against a newly published image or an unfamiliar cluster to a few thousand objects: it exercises anti-join, S3 deletion and tombstone write-back end to end in minutes. The key is optional and renders no variable when empty, since S3GC_USETOTAL is parsed as an integer. Existing environment files render unchanged.
Release process
Two defects had to be fixed to publish anything at all, recorded because neither is visible from the code:
- The workflow triggers on
tags: ['v*.*.*'], while the repository's tags werev0.5,v_0.1andv_0.2. None can match, so the publish job had never run for a release. ghcr.io/altinity/s3gcalready existed from manual pushes. A GHCR package created by a user push is not linked to its repository, soGITHUB_TOKENwas refused withdenied: permission_denied: write_packageuntil the package's Manage Actions access granted the repository the Write role. A renamed or new package will need that grant again.
Image
ghcr.io/altinity/s3gc:0.6.0
ghcr.io/altinity/s3gc@sha256:9579513319ce35aee21b646a28f83273802b87b03f1f182af9c0566854f80273
Multi-arch linux/amd64 + linux/arm64, carrying org.opencontainers.image.revision. Pin the digest in deployments — render.py rejects any image that is not digest-pinned.