backup: decouple Forgejo [storage] tier into incremental restic backups #211
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!211
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/backup-storage-decoupling"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
The daily encrypted backup archive bundled the entire Forgejo
[storage]tier (~9 GB, dominated bythe package/container registry) into every run, so each archive grew to ~9.6 GB and the backup
volume filled up. This branch decouples that tier:
[storage]tier is no longerin it.
bitborg-backup-storageservice + timer backs up[storage]separately with restic —incremental, deduplicated, encrypted — to the off-site Glesys S3 repo. It never consumes the local
backup volume.
repo-archive,actions_log,actions_artifacts,lost+found) — durable user data only.BackupStorageFailed/BackupStorageStale, mirroring the existing backup alerts.kanidm) and then
restic restorethe[storage]tier, with a fallback for legacy archives duringthe transition window.
Before applying (do NOT apply to prod until these are done)
vault_backup_restic_passwordin the vault —backup.envwill not render until it is set(same bare-vault-ref convention as the other backup secrets).
--tags backup,monitoring. First storage run doesrestic init+ one fullsnapshot.
reassembled restore (age archive +
restic restore) before relying on it.Notes
to
podmanas bare-e VAR(never on a command line).--keep-daily 7 --keep-weekly 4.restore-on-scratch.sh[storage]section also changes on the rootless-migrationbranch — reconcile the two on merge.
11bb90271bcf9ecfc89a