mirror of
https://github.com/anand34577/ferrum.git
synced 2026-09-19 00:55:11 +00:00
542a9b2eb5
- internal/api/drift.go: per-guest config/firewall baseline capture + diff, fleet-wide drift summary - internal/poller/lifecycle.go + internal/api/lifecycle.go: snapshot retention sweep (tag or fleet default, dry-run until explicitly enforced) and orphaned-disk detection (report-only, surfaced as alerts) - Migrations renumbered 00029/00030 to avoid colliding with 00026-00028 already on this branch
23 lines
1.2 KiB
SQL
23 lines
1.2 KiB
SQL
-- +goose Up
|
|
-- Config drift detection: an admin-captured snapshot of a guest's config +
|
|
-- firewall rules, compared against the live values on demand (GET .../drift)
|
|
-- to flag changes made outside this app (or by another admin) since the
|
|
-- baseline was taken. One baseline per (connection, guest) — capturing again
|
|
-- overwrites the previous snapshot rather than keeping history.
|
|
CREATE TABLE config_baselines (
|
|
id TEXT PRIMARY KEY,
|
|
connection_id TEXT NOT NULL REFERENCES connections(id) ON DELETE CASCADE,
|
|
guest_type TEXT NOT NULL, -- 'qemu' | 'lxc'
|
|
node TEXT NOT NULL, -- node the guest lived on when captured; informational only, not part of identity (guests migrate)
|
|
vmid INTEGER NOT NULL,
|
|
name TEXT NOT NULL,
|
|
snapshot_json TEXT NOT NULL, -- pve.GuestConfig, JSON-encoded
|
|
firewall_snapshot_json TEXT NOT NULL, -- []pve.FirewallRule, JSON-encoded
|
|
created_by TEXT REFERENCES users(id) ON DELETE SET NULL,
|
|
created_at TEXT NOT NULL,
|
|
UNIQUE (connection_id, guest_type, vmid)
|
|
);
|
|
|
|
-- +goose Down
|
|
DROP TABLE config_baselines;
|