Portal DB gitborg_web is never backed up (consent/GDPR + accounts unrecoverable) #122

Stängd
öppnade 2026-07-19 06:56:06 +00:00 av supernaut · 1 kommentar
Ägare

Severity: CRITICAL — pre-onboarding infra audit (2026-07-19).

The portal database gitborg_web is never backed up

ansible/roles/backup/templates/bitborg-backup.sh.j2:84-86 dumps only pg_dump -d forgejo. The portal DB gitborg_web (created by ansible/roles/web/tasks/main.yml:18-37 in the same Postgres) holds all portal-side state — signup accounts, consent/GDPR records, invite/subscription/session data — and is captured by nothing.

Impact

On host loss the portal state is unrecoverable. Neither the weekly bitborg-backup-verify nor the restore drill would notice — both only touch the forgejo DB, so forgejo doctor stays green while gitborg_web is silently absent from every archive.

Ask

  • Switch the dump to pg_dumpall (captures all DBs + roles/globals — also resolves the "roles not in dump" gap) or add a second pg_dump -d gitborg_web.
  • Extend bitborg-backup-verify and the backup-drill role to assert on gitborg_web too.

Effort S. This should land before any real signups create consent records.

**Severity: CRITICAL** — pre-onboarding infra audit (2026-07-19). ### The portal database `gitborg_web` is never backed up `ansible/roles/backup/templates/bitborg-backup.sh.j2:84-86` dumps only `pg_dump -d forgejo`. The portal DB `gitborg_web` (created by `ansible/roles/web/tasks/main.yml:18-37` in the same Postgres) holds all portal-side state — signup accounts, consent/GDPR records, invite/subscription/session data — and is captured by **nothing**. ### Impact On host loss the portal state is **unrecoverable**. Neither the weekly `bitborg-backup-verify` nor the restore drill would notice — both only touch the forgejo DB, so `forgejo doctor` stays green while `gitborg_web` is silently absent from every archive. ### Ask - Switch the dump to `pg_dumpall` (captures all DBs + roles/globals — also resolves the "roles not in dump" gap) **or** add a second `pg_dump -d gitborg_web`. - Extend `bitborg-backup-verify` and the `backup-drill` role to assert on `gitborg_web` too. Effort S. This should land before any real signups create consent records.
Upphovsperson
Ägare

✅ Applied + verified (PR #149, 2026-07-19). --tags backup,backup-drill (prod changed=3, 0 failed).

Verified the new dump against the live DB: pg_dump -U forgejo -d gitborg_web --format=custom produces a valid custom-format archive (pg_restore --list parses it) with 3 TABLE DATA entries — the portal schema round-trips. (Small today: no real signups yet.) The archive+restore path (bundle contains gitborg_web.dump; drill restores it and asserts ≥1 public table) is now guarded-then-always-on and will be exercised by tonight's nightly backup + the weekly drill.

✅ **Applied + verified** (PR #149, 2026-07-19). `--tags backup,backup-drill` (prod changed=3, 0 failed). Verified the new dump against the live DB: `pg_dump -U forgejo -d gitborg_web --format=custom` produces a valid custom-format archive (`pg_restore --list` parses it) with **3 TABLE DATA entries** — the portal schema round-trips. (Small today: no real signups yet.) The archive+restore path (bundle contains `gitborg_web.dump`; drill restores it and asserts ≥1 public table) is now guarded-then-always-on and will be exercised by tonight's nightly backup + the weekly drill.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#122
Ingen beskrivning angiven.