Say what losing the secret key costs, and how to restore without breaking things
The backup page said losing POSTULO_SECRET_KEY "will not lose your data, but it
will log everyone out", which was half of it. Unless POSTULO_FIELD_KEY is set,
that key is what every stored connection credential and the Web Push signing key
are derived from, so losing it leaves the rows in place with passwords and tokens
in them that nothing can read. The configuration page has said so for a while;
the page somebody reads while planning their backups contradicted it.
Restoring was worse. The steps said to restore onto an empty instance and run
nothing else, and then gave a uv run command — so in a container the only route
left was exec into the running web container, with gunicorn and the scheduler live
while the database underneath them is overwritten. There is now a container
section that stops the services first and uses compose run with
POSTULO_SKIP_MIGRATE=1, an explanation of what the new refusal in `restore` can
and cannot see, and an afterwards section covering the key warning and prune_media
for the files an archive never carried and a restore never deletes.
Restoring by hand was missing the step that matters most under WAL: the -wal and
-shm beside the database belong to the file that was there, and leaving them next
to one you have just swapped in means SQLite replays a log written against a
different database. The plugins directory joins the database and the media in
everything here that lists what has to be copied together.
Refs postulo/postulo#234
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Take the pages over from postulo/wiki, which this repository now replaces
Until now this was a copy of postulo/wiki, refreshed by postulo's
scripts/publish-wiki.sh whenever somebody remembered to run it. The last
time was 5 September (postulo@9645ee1). This brings it to postulo@b6cfb8f7:
- the four pages that never arrived: Accessibility, Hardening, Listings
and Reports;
- the seventeen that had changed since;
- the images, which the script never copied because it copied *.md and
nothing else, so Home has shown its logo and its Buy me a coffee button
broken since the day they were added.
Nothing here was lost: every earlier commit is a publish, and the pages
they left matched postulo/wiki at 9645ee1 exactly.
From here pages are written in this repository and nowhere else.
Refs postulo/postulo#169
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>