feat(esh-ml1): restic backup of augaman's gallery; augaman v0.1.2

esh-ml1 is outside vzdump, so augaman's face gallery reaches backup only
through restic. New playbooks/esh-ml1-restic.yaml installs restic 0.14.0 (the
same Debian package as the other ESH hosts) and resticprofile 0.33.1 (pinned,
sha256-checked). It uploads configs/restic/esh-ml1/ and schedules a daily
0100 PT backup plus a Sunday 0500 PT check to rest-server-ana. The CT runs UTC,
so both schedules name the zone explicitly.

pre-backup.sh is fail-closed: it runs augaman's own backup CLI, and any failure,
including a stopped container, aborts the run. Tested with a stub docker that
exits 1: the run returned 1, and neither the snapshot count nor last-success
moved. The restore was verified at identity level against augaman-dev's
public-domain canary (snapshot fd3061a1: the restored copy's digest over
identities and samples matches the live gallery). That meets the operator gate
for real enrollments.

The repository URL is read through repository-file rather than restic.env.
resticprofile schedule copies env-file values into world-readable systemd
units, which publishes the rest-server password on the env-file hosts
(observed on esh-docker-vm). This is recorded in the backups runbook under
Known gaps, and the playbook verifies no generated unit contains the URL.

esh-ml1 is added to the freshness check's expected ana-side repos and to the
runbook tables.

augaman moves to v0.1.2 (dependency layer keyed on the lock without the
project; per-crop embedding). pytest -m gpu tests/vision passes 3/3 on the
card, and the canary survived the container recreate.
This commit is contained in:
vh
2026-09-27 00:06:33 -07:00
parent c26f7c94e4
commit d8f59a15d9
10 changed files with 347 additions and 18 deletions
+1 -1
View File
@@ -6,7 +6,7 @@
# compose.yaml. Do not add an env_file.
# Built locally on esh-ml1 from the release tag (see README "Building").
IMAGE=augaman:0.1.1
IMAGE=augaman:0.1.2
PORT=8040
HOST_IP=10.0.50.80
+17 -6
View File
@@ -26,8 +26,13 @@ CLI, which writes `gallery.db` (mode 0600) into `BACKUP_DIR` =
restore has been verified (the restored copy reports the same identities), only
public-domain test fixtures may be enrolled. No household faces.**
Backup status: **NOT WIRED** as of the first deploy (2026-09-26). esh-ml1 has no
restic yet.
Backup status (2026-09-27): **WIRED AND RESTORE-VERIFIED, so the gate is met.**
restic runs daily at 0100 PT to rest-server-ana, with a fail-closed pre-backup
hook ([`configs/restic/esh-ml1/`](../../configs/restic/esh-ml1/README.md)). The
restore was verified against augaman-dev's public-domain canary identity (1
identity, 3 samples): the copy restored from snapshot `fd3061a1` matched the
live gallery (identities, samples and embeddings, by digest), and
`integrity_check` returned ok.
```bash
docker exec augaman python -m augaman.gallery.backup --db /data/gallery.db --dest /backup/gallery.db
@@ -47,11 +52,17 @@ cd /opt/docker/src/augaman-vX.Y.Z && docker build -t augaman:X.Y.Z .
```
The build fetches the two pinned models and SHA-256-checks them; a mismatch fails
the build. v0.1.0 built in under 2 minutes cold; first deployed version is v0.1.1 (tightly-cropped-face detector fix).
the build. v0.1.0 built in under 2 minutes cold; v0.1.1 was the first version
deployed (2026-09-26), then v0.1.2 (2026-09-27).
⚠ **Disk:** the build took the rootfs from 66% to 80% (image ~5 GB plus build
cache). Beszel alerts at 85%. After a rebuild, remove the old image and run
`docker builder prune` once the new version is verified.
⚠ **Disk:** a build that has to install the third-party packages takes ~8–11 GB
transiently (image ~5 GB plus the ~3 GB uv download cache). Beszel alerts at 85%.
Before v0.1.2, every version bump re-installed them, and the v0.1.1 build hit 90%.
From v0.1.2 the packages install from a layer keyed on `uv export
--no-emit-project`, so a bump that changes no dependency reuses that layer. Keep
the layer cache (`docker builder prune --filter type=exec.cachemount` drops only
the download cache); a full `docker builder prune` forces the next build to
re-install everything.
## Startup is fail-closed on CUDA