fix(backup): back up + verify + drill the portal DB (gitborg_web) #149
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!149
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/122-portal-db-backup"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Problem (#122 — CRITICAL, pre-onboarding)
The portal DB
gitborg_web(same Postgres as forgejo; created by the web role) holds signup accounts, consent/GDPR records, invites, subscriptions, sessions — and the backup only dumps-d forgejo, so it's captured by nothing. On host loss, portal state is unrecoverable. Worse, the weekly verify and the restore drill are also blind to it (both only touch forgejo), soforgejo doctorstays green whilegitborg_webis silently absent from every archive.Fix (close the loop across all three)
bitborg-backup.sh.j2) — add a custom-formatpg_dump -d gitborg_web→gitborg_web.dumpinto the bundle (fail-closed: empty dump aborts the run). Targeted per-DB dump keeps the existingpg_restoreflow; roles/globals are re-provisioned by Ansible on restore.bitborg-backup-verify.sh.j2) —pg_restore --list gitborg_web.dump(TOC intact / restorable).restore-on-scratch.sh.j2) — restoregitborg_webinto the scratch Postgres and assert it has ≥1 public table (schema + data round-trip), so the drill actually proves portal state is recoverable.Backward-compatible: the verify + drill checks are guarded on
gitborg_web.dumpbeing present, so a transition-period run against a pre-#122 archive skips cleanly; every archive written after this becomes an always-on check.Design note: targeted
pg_dump -d gitborg_web(custom format) rather thanpg_dumpall— keeps the custom-format/pg_restorepath the drill was just stabilized on; Ansible re-provisions roles on restore.Validation
ansible-lint (production profile) ·
--check --diffrenders clean (0 failed) ·bash -non all three rendered scripts.Verify after apply
--tags backup,backup-drill, then one backup run (archive containsgitborg_web.dump) + one drill run (asserts the portal DB round-trips).Closes #122.