Releases: MaXiMo000/firedrill
Release list
firedrill v0.4.0
firedrill 0.4.0
What's Changed
- firedrill 0.4.0: drill a live database, s3:// URLs, extension images, plain-SQL error fix by @MaXiMo000 in #5
Full Changelog: v0.3.0...v0.4.0
firedrill v0.3.0
firedrill 0.3.0: plain SQL dumps
What's Changed
- Plain SQL dumps (.sql, .sql.gz) with truncation caught (0.3.0) by @MaXiMo000 in #4
Full Changelog: v0.2.1...v0.3.0
firedrill v0.2.1
v0.2.1
What's Changed
- A materialized view can exist and answer nothing by @MaXiMo000 in #1
- A fetch nobody checked reported as ok by @MaXiMo000 in #2
- Phase 1 fixes: 0.2.1 by @MaXiMo000 in #3
New Contributors
- @MaXiMo000 made their first contribution in #1
Full Changelog: v0.2.0...v0.2.1
firedrill v0.2.0
A backup you have not restored is not a backup.
firedrill restores a PostgreSQL backup into a disposable, version-matched
container and proves the result is usable — schema, row counts, your own smoke
queries, sequences and collation — inside a stated recovery-time budget. It
fails your build the day a backup stops being restorable, not the day you need
it.
The rule the whole tool is built on: a verification that could not run never
reports as passing. A rung that could not run reports NOT RUN, never a tick.
-
Directory and tar dumps (
-Fd,-Ft). Directory format is what large
databases are actually dumped in, because it is the onepg_restorecan
parallelise — so the tool aimed at hours-long restores could not previously
read the format those people use. All three restorable formats carry a
PGDMPheader, so the major version still comes out of the artefact itself
with no PostgreSQL client on the host. -
PostgreSQL 13 through 18, tested end to end. 13 and 14 were entirely
broken before:datcollversionarrived in 15, and selecting a column that
does not exist failed the whole snapshot query, so--write-reference
wrote nothing and every structure check returned unreadable. -
Structure checks that cover more than tables. Views, materialised views,
routines with identity arguments, triggers, RLS policies, whether row
security is enabled, enum/domain/composite types, andNOT VALID
constraints. Measured before this: a database that lost its view, function,
trigger, RLS policy and enum type restored green with exit 0. -
Point-in-time recovery —
firedrill pitr --base DIR --wal DIR --target TS
— with the boundary assertion that makes it worth anything: the row written
before the target must exist and the row written after must not. Either half
alone is satisfiable by a restore that is simply wrong. -
A recovery target could inject
postgresql.conf, including
archive_command— command execution inside the container. Targets are now
constrained to a timestamp's one legitimate shape. -
Sequences wired by a column
DEFAULTrather thanOWNED BYwere never
checked at all. pagila links all thirteen of its sequences that way, so the
flagshipSEQUENCE_BEHINDcheck examined nothing and reported "0 sequences". -
The step that reads the backup could not read the backup:
pg_dump -Fd
writes mode 700 and-Fcis commonly 600, owned by whoever ran it, and the
container's postgres uid is a different one. -
The version was declared twice and the two drifted, so the wheel was 0.1.1
and--versionsaid 0.1.0.
pip install firedrill # or firedrill[s3]- uses: MaXiMo000/firedrill@v0
with:
config: firedrill.yml
rto: 45m
history: firedrill-history.jsonAlso ghcr.io/maximo000/firedrill:0.2.0, with build provenance attestation.
Docs: https://maximo000.github.io/firedrill/
Full Changelog: v0.1.1...v0.2.0
v0.1.1
v0.1.0
Full Changelog: https://github.com/MaXiMo000/firedrill/commits/v0.1.0