Plan and summary of the containerized deployment (six ASNs, three FQDNs,
token in .env, published on all interfaces, backups on the volume) and the
updated analysis. The .env file stays out of git.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Plan and summary of the isolated Compose run on copies of the real data
files: migration without losses, real collection of AS62041, diff,
backup and restore. Updates the analysis (observation 1, risk 9).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Risks 1-3 closed, observations 2 and 5 closed, new observations on module
growth, stale knowledge graph and Docker image clutter; next step is the
run on real data.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Collectors record the result of every source (schema v3, table
source_status); /health reports failing sources (failures in a row >=
source_failure_threshold) and turns degraded; GET /sources shows the full
state; runs end with a summary log line instead of "data saved".
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Restoring a backup with no data while sources are configured now sets the
db_recreated.json marker (503 until data is collected), and the backup job
skips copying an empty database in that state. Adds finding 11 to the review.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Job state is changed under one RLock, the Dockerfile copies all root
modules and imports them at build time, RIPEstat requests go through a
retrying session with the sourceapp parameter (ripestat_sourceapp) and a
capped Retry-After. Adds the summary and marks review findings 5-10 fixed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
/addresses reads the cursor and data in one session and one snapshot,
/health exposes only time and backup file name of the last restore,
get_changes checks presence in batches instead of per value (6.8 s -> 88 ms
on a 12k-entry journal). Adds the plan for review fixes 5-10.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
When ripe.db is corrupted and no valid backup exists, a new empty database
is created with a db_recreated.json marker; /addresses and /addresses/diff
answer 503 until the collector gathers data again, /health reports
db_recreated. Tests now isolate all state files via conftest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
X-API-Key compared as bytes (401 instead of 500 on non-ASCII), strict
parsing of the diff "since" parameter (400 instead of 500), FQDN
resolution keeps only global addresses (allow_non_global_ips to opt out).
Adds the code review report and the plan/summary for this change.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Daemon job "backup" (online copy, quick_check, rotation), restore of the
newest valid copy when the database cannot be opened, change journal reset
after restore, last_restore in /health, docs and tests.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Exact versions for direct dependencies, full pip freeze of the tested
image as constraints, both Dockerfiles install with -c constraints.txt.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>