feat: rollback — schema-downgrade guard + config snapshot/restore - #25
Merged
vsutra-admin merged 1 commit intoJun 21, 2026
Merged
Conversation
…t/restore
openspecimen role (upgrade backup phase):
- Adds <backup>/config/ subdirectory containing openspecimen.properties,
setenv.sh, and context.xml as they were at deploy time
- Adds <backup>/.release marker snapshot (previously missing — rollback's
marker-restore step was a no-op against backups created before this fix)
rollback.yml:
- Pre-stop safety check: queries DATABASECHANGELOG for rows where
DATEEXECUTED > backup_mtime. If new Liquibase migrations exist since the
backup, halts with operator-friendly diagnostics naming the live release,
backup release, mtime, and changeset count. Provides the exact SELECT to
list offending changesets and three remediation paths.
- Override: -e allow_downgrade=true (emits a warning, then proceeds)
- Restores openspecimen.properties / setenv.sh / context.xml from
<backup>/config/ in addition to WAR/plugins/lib. No separate site.yml
run needed for config rollback.
- Header comment + usage examples updated
docs/DEPLOY-UPGRADE.md:
- Restoration scope table extended (config snapshot, marker restore)
- New 'Schema-downgrade safeguard' section with example failure output and
the three remediation paths documented in the playbook error message
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two safety/usability extensions to the rollback flow:
Schema-incompatible downgrade detection. Before stopping the service, query Liquibase
DATABASECHANGELOGfor rows withDATEEXECUTED > backup_mtime. If any new migrations exist, halt with full diagnostics (live release, backup release, count, list-changesets query, three remediation paths). Override:-e allow_downgrade=true.Config snapshot / restore. Upgrade backup now also snapshots
openspecimen.properties,setenv.sh, andcontext.xmlinto<backup>/config/, plus the previous.releasemarker. Rollback restores all of these — no separate site.yml run needed for config rollback.Closes the rollback design gaps raised in #30.