Add soft delete for revoked devices

Admins could only revoke devices, so never-enrolled and revoked
inventory rows piled up with no way to remove them. Soft-delete
is limited to REVOKED devices (revoke first), and ITAM GC now
hard-deletes PENDING/REVOKED orphans with no API key, postures,
or valid enrollment token—including user tombstones without
history.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-30 10:11:08 +02:00
parent 41da4bbad1
commit 7731566c68
23 changed files with 773 additions and 61 deletions

View File

@@ -100,10 +100,18 @@ func (h *gcHandler) cleanup(ctx context.Context) error {
return fmt.Errorf("cannot delete expired device enrollment tokens: %w", err)
}
var device coredata.Device
devicesDeleted, err := device.DeleteOrphans(ctx, tx, now)
if err != nil {
return fmt.Errorf("cannot delete orphan devices: %w", err)
}
h.logger.InfoCtx(
ctx,
"itam garbage collector cleaned up",
log.Int64("device_enrollment_tokens_deleted", tokensDeleted),
log.Int64("orphan_devices_deleted", devicesDeleted),
)
return nil