feat(config): gitignored config.local.yaml overlay, incident #5, backup tooling #26
Reference in New Issue
Block a user
Delete Branch "feat/config-local-overlay"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Three related pieces of work from one session.
1.
config/config.local.yamloverlay (Plan 8)Deployment-specific values lived as uncommitted modifications to a tracked
file. That arrangement failed six times in one session -- three agent
tree-cleanings, two
git commit -amsweeps needing history rewrites, and oneordinary
git switch. The last one is the point: once a value is correctlyabsent from git, every checkout wipes it. The arrangement was the bug.
load_confignow deep-merges an optional gitignoredconfig/config.local.yamlover the base file before validation. Merge rules: absent overlay means
identical behaviour, mappings deep-merge key by key, lists replace wholesale,
and the merged result is validated once so
extra="forbid"still catches atypo in the overlay.
Allowlisted admin scalar writes now target the overlay, so
config/config.yamlstops being dirty in normal operation.
2. Incident #5
git clean -fdxdestroyed the database, API key and venv. Full write-up indocs/incidents.md, including why the ignored files in this repo are thedeployment.
3. Backup tooling
llm-router-backup.timer-- hourlysqlite3 .backupsnapshots, keeps 24,integrity-checked before rotating.
llm-router-offsite.timer-- 6-hourly push to a private repo..envisexcluded by construction.
deploy/workstation-backup.sh-- tarball with an embeddedRESTORE.md.Verification
config/config.yamlbyte-identical after a portal edit, with the overlaycarrying the change -- pinned by
test_config_POST_preserves_comments_and_changes_value.git restoreof the base file --test_overlay_survives_git_restore_of_base.local_energy.tariff_usd_per_kwhaloneleaves
meter,sample_interval_secondsandgrid_intensity_g_per_kwhintact.Known gap, deliberately not fixed here
Profile CRUD still writes to
config/config.yamlrather than the overlay(
src/admin.py:670documents it). It predates the overlay decision. Trackedas a follow-up rather than widened into this PR.