chore(backup): move the hetzner destination to the object-locked bucket #520

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/465-hetzner-locked-bucket in i main 2026-10-02 13:51:32 +00:00
Ägare

What

Point the secondary (Hetzner) off-site destination at a new object-locked bucket. Only vault_backup_s3_hetzner_bucket changes in the encrypted vault (checked by decrypting both versions and diffing keys).

The bucket was created per runbook § "Immutable off-site copies (#465)": mc mb --with-lock, default retention COMPLIANCE 14 days, lifecycle rules expire-archives (prefix bitborg-, 14 days) and drop-noncurrent-and-markers. It is switched to after the archive rename (#518), so it only ever receives bitborg-* archives.

Apply

Tag backup, bitborg-prod: only backup.env changes. No restarts.

After the apply: one manual backup run, check the archive lands in the new bucket, then the negative control (a versioned delete with the host key must fail). The old bucket is retired after 28 days.

Refs #465

## What Point the secondary (Hetzner) off-site destination at a new object-locked bucket. Only `vault_backup_s3_hetzner_bucket` changes in the encrypted vault (checked by decrypting both versions and diffing keys). The bucket was created per runbook § "Immutable off-site copies (#465)": `mc mb --with-lock`, default retention COMPLIANCE 14 days, lifecycle rules `expire-archives` (prefix `bitborg-`, 14 days) and `drop-noncurrent-and-markers`. It is switched to after the archive rename (#518), so it only ever receives `bitborg-*` archives. ## Apply Tag `backup`, `bitborg-prod`: only `backup.env` changes. No restarts. After the apply: one manual backup run, check the archive lands in the new bucket, then the negative control (a versioned delete with the host key must fail). The old bucket is retired after 28 days. Refs #465
supernaut lade till 1 incheckning 2026-10-02 13:44:42 +00:00
chore(backup): move the hetzner destination to the object-locked bucket
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m53s
879980db84
The new bucket is created with object lock (COMPLIANCE, 14 days) and the lifecycle rules from the runbook. Only vault_backup_s3_hetzner_bucket changes.

Refs #465
supernaut schemalade den här ändringsförfrågan för automatisk sammanfogning när alla kontroller lyckas 2026-10-02 13:47:02 +00:00
supernaut sammanfogade incheckning 55974bd27b till main 2026-10-02 13:51:32 +00:00
supernaut tog bort grenen chore/465-hetzner-locked-bucket 2026-10-02 13:51:32 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!520
Ingen beskrivning angiven.