Files
sysmig/README.md
T
wan 5d1f641c61 add per-migration status case (read-only drift check), integrate into sysmig status
status convention: print one line, exit 0 OK / 1 DRIFT / 2 unknown (e.g.
needs root). sysmig status now shows [applied ✓/✗/?] per migration and
exits 1 on drift. DB checks fall back to peer auth when non-root.
2026-08-31 16:46:21 +09:00

60 lines
2.5 KiB
Markdown

# sysmig
Lightweight tool that manages host state in DB-migration (Flyway) style.
Started for a 1GB VM (`ocrt-postgres`), but deployable to any machine
via cloud-init.
## Usage
```bash
sudo bash /opt/sysmig/sysmig up # apply all pending migrations (idempotent)
sudo bash /opt/sysmig/sysmig down # roll back the last migration
sudo bash /opt/sysmig/sysmig down all # roll back everything (reverse order)
bash /opt/sysmig/sysmig status # history + drift check (exit 1 on drift)
```
- Migrations: `migrations/NNN-name.sh`, receiving `up`/`down`/`status` as `$1`
- Applied history: `/var/lib/sysmig/applied` - applied entries never re-run
- On failure the run aborts at that step; earlier steps stay applied
- `status` runs each applied migration's read-only drift check (exit 1 on
drift); DB checks need root, otherwise shown as `?`
## Adding a new migration
1. Create `migrations/NNN-name.sh` (number higher than existing; leave gaps)
2. Implement `up`, `down` and `status` cases - up/down must actually work;
`status` is a read-only check (exit 0 OK / 1 DRIFT / 2 unknown)
3. Commit & push, then on the server: `git pull && sudo bash sysmig/sysmig up`
## cloud-init integration
```yaml
#cloud-config
runcmd:
- [ git, clone, <REPO_URL>, /opt/sysmig ]
- [ bash, /opt/sysmig/sysmig, up ]
```
For a private repo you need an auth strategy:
- **deploy key** (existing machines): register a read-only key on the repo
- **fleet rollout**: make the repo public, or embed a read-only token in
the https URL
## Current migrations
| # | name | effect |
|----|----------------------------|-----------------------------------------------|
| 001 | create-swap | 2GB swap + fstab + vm.swappiness=10 |
| 002 | disable-networkd-dispatcher| reclaim ~27MB RAM |
| 003 | purge-exim4 | reclaim ~21MB RAM (package removed) |
| 004 | purge-haveged | reclaim ~8MB RAM (package removed) |
| 005 | mount-pgdata | /dev/sdb (20G) -> /var/lib/postgresql, fstab |
| 006 | install-postgres | PG 18 via PGDG repo, cluster on the disk |
| 007 | postgres-admin-role | iwanhae OS user -> PG superuser (peer auth) |
| 008 | create-db-iwanhae | database `iwanhae` owned by admin role |
## Roadmap
- `010-tune-postgres` - 1GB tuning (shared_buffers=128MB, work_mem=4MB,
max_connections=30, ...)