Skip to content

feat: automatic scheduled system backups - #279

Closed
liukewia wants to merge 27 commits into
TencentCloud:mainfrom
liukewia:feature/auto-backup-merge-develop
Closed

feat: automatic scheduled system backups#279
liukewia wants to merge 27 commits into
TencentCloud:mainfrom
liukewia:feature/auto-backup-merge-develop

Conversation

@liukewia

@liukewia liukewia commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Add configurable automatic system backups scheduled inside a running octop run process.

  • Persist backup settings in config.json (auto_enabled, schedule, retention_count; default schedule cron:0 4 * * * in server timezone).
  • Register a process-level CronManager system job (octop_auto_backup) that writes octop-auto-backup-*.tar.gz and prunes older auto archives by retention.
  • Expose settings via backup API, CLI (octop backup auto commands), and the Settings → Backup & Restore dashboard UI.
  • Cover config parsing / auto-backup helpers with unit tests; document CLI behavior in docs/cli.md.

Target branch

  • Base is develop (feature / fix — default)
  • Base is main (release/* or hotfix/* only)

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • Refactor / chore
  • Release / hotfix

Test plan

  • make all passes locally
  • Added/updated tests
    • tests/unit/backup/test_auto.py
    • tests/unit/backup/test_store.py
    • tests/unit/test_config.py (backup section)
    • Suggested: uv run pytest tests/unit/backup tests/unit/test_config.py -q
    • Manual: enable auto backup in Settings → Backup & Restore, confirm job schedules and archives appear as octop-auto-backup-*.tar.gz

Checklist

  • Updated CHANGELOG.md (if user-facing)
  • README / docs updated (if needed) — docs/cli.md

github-actions Bot and others added 27 commits August 12, 2026 01:12
…lop-after-manual

chore: sync develop onto main after manual
…reen

testmon decides which files changed via `git ls-files --stage -m` (worktree
vs index). At pre-commit time the changes are already staged, so that
comparison is empty and testmon silently deselects every test — a false
green that makes the fast gate worthless.

Patch testmon's file detection to use `git diff HEAD` (staged + unstaged)
via conftest.py and tests/support/testmon_staged_changes.py, so the gate
actually fires on a commit's changes. No-op when testmon is absent.

Co-Authored-By: Claude <noreply@anthropic.com>
…-fast-gate

fix(precommit): make testmon gate detect staged changes (no false green)
Add is_shared so owners can expose a runtime agent for others to chat with while keeping config writes owner-only.

Co-authored-by: Cursor <cursoragent@cursor.com>
Let owners publish an agent workspace as a reusable template, refresh/unpublish it, and let others install a private fork. Also adds expert color/emoji pickers used by subagents and publish UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
Support admin-configured OIDC with PKCE, one-time login code exchange, and dashboard SSO management/complete flows.

Co-authored-by: Cursor <cursoragent@cursor.com>
Manage catalog download/probe for local ONNX embedding weights beside Ollama, with stable provider identity and optional local-embedding extras.

Co-authored-by: Cursor <cursoragent@cursor.com>
Introduce document indexing, embedding (ONNX/remote), and chat/IM injection with default-open selection in the dashboard composer.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep dashboard update checks consistent across reloads and tighten update store edge cases.

Co-authored-by: Cursor <cursoragent@cursor.com>
… app

Register routers/repos/migrations, OpenAPI tags, i18n/error codes, sidebar routes, and docs for the new platform capabilities.

Co-authored-by: Cursor <cursoragent@cursor.com>
Fall back to known HF cache aliases when optional local-embedding extras are missing, and mock deps availability in embed_texts unit tests so CI without the extra stays green. Also align install body types with nullable runtime fields.

Co-authored-by: Cursor <cursoragent@cursor.com>
Consolidate unreleased develop migrations 005–009 into one v5 file with
ensure/clamp paths for pre-squash local DBs; add HITL catalog picker,
shared runtime package install for ONNX/desktop, and short-id list UX for
knowledge bases and skill packages.

Co-authored-by: Cursor <cursoragent@cursor.com>
Adds support for audio/mpeg (MP3), audio/wav, audio/webm, audio/ogg, audio/flac, audio/aac, audio/x-wav
to the media/preview endpoint by adding a new _PREVIEW_AUDIO set and checking it in is_previewable_mime
* fix: fix script version issue and change output to english

* fix:cancel delete octop-login.txt logic
…uling

- Added new API endpoints for managing automatic backup settings.
- Introduced a new BackupConfig class to handle automatic backup configurations.
- Implemented functionality to create, run, and manage automatic backups.
- Updated the dashboard to include UI elements for configuring automatic backups.
- Enhanced CLI commands to support automatic backup operations.
- Added localization strings for new backup features in English and Chinese.
- Updated documentation to reflect changes in backup commands and configurations.
- Bumped octop version to 0.9.23 to include these features.
…lop-after-manual

chore: sync develop onto main after manual
…oud#276)

* feat: add per-user module permissions (RBAC) with admin bypass

Introduce a module-level permission system so non-admin users can be
scoped to a subset of dashboard modules. Adds a `permissions` TEXT column
on the `users` table (migration 006, SQLite + PostgreSQL), a central
permission catalog in `infra/users/permissions.py`, backend ACL checks
across routers, and dashboard gating via `RequirePermission` /
`ForbiddenPage` keyed by nav module. `admin` always bypasses every gate;
read access and chat/agent use are never gated.

* fix: gate connector install-cli by connectors permission (not admin-only)

The host CLI installer is a connectors-module operation and should be
gated by the `connectors` module permission, consistent with the rest of
the connector routes, instead of being admin-only.

The earlier RBAC change demoted this route from `current_admin` but the
test `test_install_cli_forbidden_for_non_admin` still failed because the
`create_user` test helper grants `BASELINE_PERMISSIONS` (which includes
`connectors`) by default, so the "non-admin" user actually held the
permission. Gate the route with `require_permission("connectors")` and
create the test user with `permissions=[]` so it genuinely lacks the
key and is rejected with 403.

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
- Removed unused localization strings related to backup types in English and Chinese.
- Simplified the BackupRestore component by eliminating the auto backup name check and associated UI elements.
- Updated styles by removing the kindBadge class, streamlining the backup card display.
@liukewia liukewia closed this Aug 14, 2026
Comment thread src/octop/config.py
if raw is None:
return BackupConfig()
if not isinstance(raw, dict):
msg = f"config.backup must be an object, got {type(raw).__name__}"
Comment thread src/octop/infra/server.py Dismissed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants