Skip to content

firedrill v0.2.0

Choose a tag to compare

@github-actions github-actions released this 25 Aug 18:47
· 14 commits to main since this release

A backup you have not restored is not a backup.

firedrill restores a PostgreSQL backup into a disposable, version-matched
container and proves the result is usable — schema, row counts, your own smoke
queries, sequences and collation — inside a stated recovery-time budget. It
fails your build the day a backup stops being restorable, not the day you need
it.

The rule the whole tool is built on: a verification that could not run never
reports as passing.
A rung that could not run reports NOT RUN, never a tick.

  • Directory and tar dumps (-Fd, -Ft). Directory format is what large
    databases are actually dumped in, because it is the one pg_restore can
    parallelise — so the tool aimed at hours-long restores could not previously
    read the format those people use. All three restorable formats carry a
    PGDMP header, so the major version still comes out of the artefact itself
    with no PostgreSQL client on the host.

  • PostgreSQL 13 through 18, tested end to end. 13 and 14 were entirely
    broken before: datcollversion arrived in 15, and selecting a column that
    does not exist failed the whole snapshot query, so --write-reference
    wrote nothing and every structure check returned unreadable.

  • Structure checks that cover more than tables. Views, materialised views,
    routines with identity arguments, triggers, RLS policies, whether row
    security is enabled, enum/domain/composite types, and NOT VALID
    constraints. Measured before this: a database that lost its view, function,
    trigger, RLS policy and enum type restored green with exit 0.

  • Point-in-time recovery — firedrill pitr --base DIR --wal DIR --target TS
    — with the boundary assertion that makes it worth anything: the row written
    before the target must exist and the row written after must not. Either half
    alone is satisfiable by a restore that is simply wrong.

  • A recovery target could inject postgresql.conf, including
    archive_command — command execution inside the container. Targets are now
    constrained to a timestamp's one legitimate shape.

  • Sequences wired by a column DEFAULT rather than OWNED BY were never
    checked at all. pagila links all thirteen of its sequences that way, so the
    flagship SEQUENCE_BEHIND check examined nothing and reported "0 sequences".

  • The step that reads the backup could not read the backup: pg_dump -Fd
    writes mode 700 and -Fc is commonly 600, owned by whoever ran it, and the
    container's postgres uid is a different one.

  • The version was declared twice and the two drifted, so the wheel was 0.1.1
    and --version said 0.1.0.

pip install firedrill          # or firedrill[s3]
- uses: MaXiMo000/firedrill@v0
  with:
    config: firedrill.yml
    rto: 45m
    history: firedrill-history.json

Also ghcr.io/maximo000/firedrill:0.2.0, with build provenance attestation.

Docs: https://maximo000.github.io/firedrill/


Full Changelog: v0.1.1...v0.2.0