Backups: CI/scratch-instance test-restore job #40
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#40
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
A weekly on-host restore-verification timer already runs. Add the CI/scratch-instance variant: restore into a scratch instance and run
forgejo doctor.Epic: gitborg/gitborg-docs#2
Implemented, deployed, and verified live on prod. 🎉
The CI/scratch-instance variant now runs as a weekly
bitborg-backup-drillsystemd timer on the services host: it fetches the latest off-site archive, decrypts it with the on-host verify key, boots a throwaway OpenStack VM (ADR 0021 pattern, no FIP), restores Postgres + the Forgejo data volume into a clean stack, runsforgejo doctor, records a metric, and tears the VM down. Orchestration lives on the services host (not the CI runner pool) to keep the OpenStack credential + backup-decrypt capability least-privilege.Verified end-to-end: a live run restored the latest off-site archive into a throwaway VM;
forgejo doctorconfirmed 5 repos + DB consistency + version 305; the VM was torn down with no leaked server/volume;gitborg_backup_drill_last_run_status = 0is scraped into VictoriaMetrics;BackupDrillFailed/BackupDrillStalealerts are loaded. (It took 8 runs to go green — each surfaced a real integration bug, which is exactly the point of a restore drill.)Sibling tasks #39 (Bahnhof S3 migration, blocked on the DPA) and #41 (second off-provider destination) remain open under epic gitborg/gitborg-docs#2.