feat(backup): object-locked off-site buckets with optional server-side expiry #514
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!514
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/465-backup-delete-credential"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
First slice of #465: off-site backups the host cannot destroy.
The OpenStack credential can delete the local backup volume, but not the off-site copies. The S3 keys in
backup.envcan: any compromise of the services user couldrclone deleteevery off-site archive. This PR prepares object-locked buckets.bitborg-backup.sh.j2: per-destinationserver_side_expiryflag. When true, the host skips itsrclone deleteprune and the bucket's lifecycle rule expires archives, so the host key can be denieds3:DeleteObject. Default false: rendered behaviour is unchanged.Limits
[storage]tier is not protected: old base packs leave the lock window but stay in use.mc ls --versions.Not in this PR (plan in #465)
ADR for the target shape, a restic writer without delete rights, separate OpenStack application credentials with access rules, network tiers, one rootless user per service.
Verification
ansible-lint 0/0,
--syntax-checkOK, prettier and markdownlint clean, shellcheck on the rendered script: only a pre-existing SC2086 info. Merging is inert: an apply is needed only after the vault bucket change.Refs #465
e9fc2686a17ae584bcab