mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-04 07:57:54 +00:00
32a7d53b2b
* feat: add RBAC viewer accounts, atomic deployments, and fleet-wide backups (Pro) Introduces three Pro-tier features: - RBAC: Multi-user system with admin/viewer roles, user management UI, automatic migration from single-admin credentials, viewer restrictions across the entire UI (read-only editor, hidden action buttons) - Atomic Deployments: Pre-deploy file backup to .sencho-backup/, automatic rollback on health probe failure, manual rollback button, health probes added to stack updates, webhook-triggered deploys use atomic rollback - Fleet-Wide Backups: Point-in-time snapshots of compose files across all nodes (local + remote), stored centrally in SQLite, per-stack restore with optional redeploy, graceful handling of offline nodes * fix(settings): use correct ProGate prop name in UsersSection * fix(settings): remove unused isPro prop from UsersSection * fix(auth): fetch user info after login and setup so isAdmin is set correctly * feat(pricing): revise pricing strategy and enforce variant-based seat limits Raise Personal Pro from $49/yr to $69/yr with 3 viewer seats (up from 1). Add $15/mo billing option for Team Pro. Mark lifetime pricing as a 90-day early-adopter offer. Store Lemon Squeezy variant_name on activation/validation and enforce seat limits server-side per variant. * feat(licensing): add Lemon Squeezy checkout, webhook, and billing portal integration Server-side checkout URL generation (POST /api/checkout) with admin email pre-fill and instance_id custom data. HMAC-SHA256 verified webhook endpoint (POST /api/webhooks/lemonsqueezy) handling order, subscription, and payment lifecycle events for automatic license activation. Customer billing portal link stored from webhook events and exposed via GET /api/billing/portal. In-app checkout buttons in Settings with manual license key fallback. * fix(licensing): exempt Lemon Squeezy webhook from auth middleware The catch-all auth middleware on /api/* was blocking the public webhook endpoint. Added /webhooks/lemonsqueezy to the exemption list alongside /auth/* and /webhooks/:id/trigger. * feat(pricing): update pricing to final live rates Personal Pro: $7.99/month, $69.99/year, $249 lifetime. Team Pro: $49.99/month, $499.99/year, $1,499 lifetime. Added personal_monthly checkout variant across backend, frontend, and website. * refactor(licensing): remove server-side checkout/webhook for self-hosted model Sencho is self-hosted — each user runs their own instance, so there is no central server to receive webhooks or hold the store API key. Replaced in-app checkout buttons with a "View Pricing" redirect to sencho.io and kept manual license key activation as the primary flow. - Delete LemonSqueezyService (checkout, webhook, HMAC verification) - Remove POST /api/checkout, GET /api/billing/portal, POST /api/webhooks/lemonsqueezy - Remove raw body parser and auth exemption for webhook route - Remove all LEMONSQUEEZY_* env vars from .env.example - Replace checkout buttons in SettingsModal with single "View Pricing" button - Simplify LicenseContext checkout to open sencho.io pricing page - Update licensing docs to reflect website-based purchase flow * chore: normalize em-dashes to hyphens across codebase (linter) * chore: remove accidentally tracked directories from index
85 lines
3.2 KiB
Plaintext
85 lines
3.2 KiB
Plaintext
---
|
|
title: Fleet-Wide Backups
|
|
description: Snapshot compose files across all nodes for disaster recovery and auditing.
|
|
---
|
|
|
|
<Note>
|
|
Fleet-Wide Backups require a Sencho Pro license. The feature is available to Pro admins in the Fleet View.
|
|
</Note>
|
|
|
|
Create point-in-time snapshots of every `compose.yaml` and `.env` file across your entire fleet - local and remote nodes alike. Snapshots are stored centrally in Sencho's database and can be browsed, previewed, and restored at any time.
|
|
|
|
## Creating a snapshot
|
|
|
|
1. Navigate to **Fleet View** and select the **Snapshots** tab
|
|
2. Click **Create Snapshot**
|
|
3. Optionally enter a description (e.g. "Before v2 migration")
|
|
4. Click **Create** - Sencho captures files from every reachable node
|
|
|
|
During creation, Sencho connects to each node in parallel:
|
|
- **Local nodes** - reads files directly from the compose directory
|
|
- **Remote nodes** - fetches files via the Distributed API proxy using the node's API token
|
|
|
|
If a remote node is offline or unreachable, it is **skipped gracefully**. The snapshot is still created with data from all reachable nodes, and skipped nodes are recorded with the reason for the failure.
|
|
|
|
## Browsing snapshots
|
|
|
|
The snapshot list shows:
|
|
- **Date** - when the snapshot was taken
|
|
- **Description** - your optional label
|
|
- **Scope** - how many nodes and stacks were captured
|
|
- **Warnings** - an indicator if any nodes were skipped
|
|
|
|
Click **View** to open the detail view, which presents a collapsible tree:
|
|
|
|
```
|
|
Node A (local)
|
|
├── traefik/
|
|
│ ├── compose.yaml
|
|
│ └── .env
|
|
└── postgres/
|
|
└── compose.yaml
|
|
Node B (remote)
|
|
└── grafana/
|
|
├── compose.yaml
|
|
└── .env
|
|
```
|
|
|
|
Expand any file to preview its contents inline.
|
|
|
|
## Restoring from a snapshot
|
|
|
|
Admins can restore individual stacks from any snapshot:
|
|
|
|
1. Open a snapshot's detail view
|
|
2. Find the stack you want to restore
|
|
3. Click **Restore**
|
|
4. Optionally check **Redeploy stack after restore** to immediately apply the restored configuration
|
|
5. Confirm the action
|
|
|
|
Sencho writes the snapshot's files back to the target node:
|
|
- **Local nodes** - files are written directly, and the current files are backed up first (creating a rollback point via the atomic deployment system)
|
|
- **Remote nodes** - files are pushed via the Distributed API proxy
|
|
|
|
<Warning>
|
|
Restoring overwrites the current compose and environment files on the target node. If atomic deployments are enabled, the current files are backed up before restoration.
|
|
</Warning>
|
|
|
|
## Deleting snapshots
|
|
|
|
Admins can delete snapshots from the list view. Deleting a snapshot permanently removes all captured file data from the database. This action cannot be undone.
|
|
|
|
## Access control
|
|
|
|
| Action | Admin | Viewer |
|
|
|--------|-------|--------|
|
|
| View snapshot list | Yes | Yes |
|
|
| Browse snapshot contents | Yes | Yes |
|
|
| Create snapshot | Yes | No |
|
|
| Restore from snapshot | Yes | No |
|
|
| Delete snapshot | Yes | No |
|
|
|
|
## Storage
|
|
|
|
Snapshots are stored in Sencho's SQLite database. Compose files are typically small (under 10 KB each), so even hundreds of snapshots consume minimal disk space. For very large fleets, consider periodically deleting old snapshots to keep the database lean.
|