Snapshot system
Snapshots are PostgreSQL custom-format dumps published as GitHub Release assets by xbit18/icvdb-snapshots.
Discovery and validation
- Request the configured latest-release API URL.
- Select the first asset whose name ends in
.dump. - Require the asset metadata to contain a
sha256:digest. - Download the asset and verify SHA256.
- Run
pg_restore --listbefore attempting a restore. - Restore into
icv_db_candidatewith restore errors treated as fatal. - Connect to the candidate and require user tables.
The installed release tag is written atomically to /data/state/snapshot-version only after a successful switch and final validation.
SNAPSHOT_LATEST_URL can point discovery at another compatible GitHub-style release response. The implementation expects tag_name, a .dump asset, browser_download_url, and a GitHub asset digest.
