backups: copy the encrypted OpenTofu state off the operator machine #470

Öppen
öppnade 2026-09-08 23:04:28 +00:00 av supernaut · 1 kommentar
Ägare

The OpenTofu state is local and encrypted, and terraform.tfvars is untracked. Both exist only on one machine. scripts/tofu-apply.sh snapshots them locally before every apply, which covers a bad apply but not a lost laptop.

Push each snapshot to the same off-site destinations the backup role uses (they are already ciphertext), or a dedicated bucket, and document the restore path. Depends on the operator machine having the rclone remote configured.

The OpenTofu state is local and encrypted, and `terraform.tfvars` is untracked. Both exist only on one machine. `scripts/tofu-apply.sh` snapshots them locally before every apply, which covers a bad apply but not a lost laptop. Push each snapshot to the same off-site destinations the backup role uses (they are already ciphertext), or a dedicated bucket, and document the restore path. Depends on the operator machine having the rclone remote configured.
Upphovsperson
Ägare
Epic: bitborg/bitborg-docs#107
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#470
Ingen beskrivning angiven.