authentik: disarm the automatic rollback before the version jump (#0051)
The release carried upgrade remediation with three retries and no strategy. The Flux CRD is explicit: the strategy defaults to rollback, remediation runs between each attempt, and the last failure is remediated as well whenever retries exceed zero. A failing upgrade would therefore have rolled Helm back to the old version up to four times, against a database Django had already migrated forward — the migration inconsistency Authentik's own documentation warns about, triggered by this line. Here the way back is a database restore, not a version rollback, so an automatic rollback cannot help and can only deepen the damage. It goes back to three once the jump is done; outside a migration window the remediation is right. Nothing else changes: the chart version, the values and the install remediation are untouched.
This commit is contained in:
@@ -18,7 +18,17 @@ spec:
|
||||
retries: 3
|
||||
upgrade:
|
||||
remediation:
|
||||
retries: 3
|
||||
# ⚠️ Waehrend des Authentik-Sprungs 2026.2.3 -> 2026.5.6 -> 2026.8.0 auf 0.
|
||||
# Die Flux-CRD sagt: strategy defaults to 'rollback', Remediation laeuft
|
||||
# ZWISCHEN jedem Versuch, und remediateLastFailure ist bei retries>0
|
||||
# ebenfalls scharf. Ein misslingendes Upgrade wuerde damit bis zu viermal
|
||||
# auf die alte Fassung zurueckgerollt - gegen eine Datenbank, die Django
|
||||
# schon nach vorne migriert hat. Genau der Zustand 'migration inconsistency',
|
||||
# vor dem Authentiks Anleitung warnt, ausgeloest von dieser Zeile.
|
||||
# Der Rueckweg ist hier eine Datenbank-Wiederherstellung, keine
|
||||
# Fassungsruecknahme (management #0051).
|
||||
# NACH dem Sprung zurueck auf 3 - im Normalbetrieb ist die Behebung richtig.
|
||||
retries: 0
|
||||
valuesFrom:
|
||||
- kind: Secret
|
||||
name: authentik-credentials
|
||||
|
||||
Reference in New Issue
Block a user