HA: PostgreSQL replication / managed HA pair #43
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#43
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Move PostgreSQL to a managed/replicated setup or a dedicated HA pair.
Epic: gitborg/gitborg-docs#4
Design/options doc: tracked internally.
TL;DR — defer active HA; harden the single instance now. We run one containerised Postgres 17 (Forgejo + web) on one Bahnhof VM. Recovery today: daily age-encrypted dumps (ADR 0022/0011) proven by the weekly restore drill (ADR 0027) → ~RPO 24h, RTO hours. HA buys lower RTO (mins) and, with streaming replication, lower RPO (secs) — but the DB is only one SPOF on a single-VM stack, scale is tiny, and there's no SLA yet. Backups suffice for now.
Options weighed:
Path: WAL archiving + drilled runbook now → streaming replication when users/SLA warrant → managed only if a sovereign co-located HA option appears. Suggest also making the Forgejo/web DB host a variable (currently hard-coded
postgres:5432). Recommend moving offneeds-triage.