chore(backup): move the hetzner destination to the object-locked bucket #520
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!520
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/465-hetzner-locked-bucket"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Point the secondary (Hetzner) off-site destination at a new object-locked bucket. Only
vault_backup_s3_hetzner_bucketchanges in the encrypted vault (checked by decrypting both versions and diffing keys).The bucket was created per runbook § "Immutable off-site copies (#465)":
mc mb --with-lock, default retention COMPLIANCE 14 days, lifecycle rulesexpire-archives(prefixbitborg-, 14 days) anddrop-noncurrent-and-markers. It is switched to after the archive rename (#518), so it only ever receivesbitborg-*archives.Apply
Tag
backup,bitborg-prod: onlybackup.envchanges. No restarts.After the apply: one manual backup run, check the archive lands in the new bucket, then the negative control (a versioned delete with the host key must fail). The old bucket is retired after 28 days.
Refs #465