본문으로 건너뛰기

관리

사용자·그룹·서비스 토큰·OIDC 클라이언트를 관리하는 API입니다.

📄️ Release Deletion Guards

Clear stuck delete guards. Admin only; explicit list, no wildcard. Preconditions are re-checked here rather than trusted from the marker, the same TOCTOU reasoning as the D1b drop guards. The one fact taken from the marker is ``first_seen``, for guards too old to carry a ``start_time`` — it is the only record of their age, and it can only under-state it, so it never lets a young guard through. This frees the 409 only. The name reservation is deliberately left held, so no same-name resource can be created and then destroyed by a late cleanup — release those separately via ``/admin/name-fences/release`` once the physical objects are confirmed gone.

📄️ Retry Cleanups

The lossless counterpart of ``/name-fences/release``: instead of freeing the name and abandoning the physical residue, this re-runs the cleanup so the reservation is released on the normal all-steps-succeeded path. Targets any non-``completed`` checkpoint — including ``exhausted`` (re-arms the reclaim series at attempt 1) and the pre-reclaim backlog the scheduled pass skips as too old. A ``running`` checkpoint younger than an hour is refused (a live run may hold it); an older one is a dead mid-run worker, and re-dispatching it is safe because every step is an idempotent DROP.