feat(backup): hourly hot backup with a gated billing dump #517
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!517
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/158-hourly-backup"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Rollout PRs 2 and 4 of #158 (ADR 0041), plus the runbook targets (PR 1's infra half).
bitborg-backup-hot.sh, timer at :17): canary row inbitborg_backup.canary(portal DB, own schema),pg_dump -Z0of the Forgejo and portal DBs, a Kanidm backup to its own file, thenrestic backupof the dumps and the Forgejo data volume intorestic/hoton the primary off-site bucket. Forget--keep-hourly 48 --keep-daily 14each run,--pruneonce a day. Excludes regenerable queues, indexers, tmp and push quarantine; restic exit 3 (file vanished mid-scan) is a warning with the snapshot kept.billing_enabled.--host {{ inventory_hostname }};backup_hot_enabledis true only on the prod host, so a scratch or restore host never writes into the prod repo. The units onlyAfter=Forgejo and Postgres, never start them.BackupHotStale(critical, over 3 h, also fires when the metric is absent),BackupHotFailed(status != 0 for 5 min),BackupHotBillingStale(over 1 h, rendered only when billing is enabled). Textfiles of disabled units are removed.podman run, stop the hot timers before any restore, fall back to the previous snapshot if a live-read repo is inconsistent.No new vault values: it reuses the primary off-site keys and the restic password.
Review
An independent review found 8 must-fix and 9 smaller issues; all fixed in
8131d60.Verification
ansible-lint 0/0,
--syntax-checkOK, both scripts render and passbash -nand shellcheck (local 0.11) with billing on and off,check-alert-rules53/54 rules,check-metric-namesOK. Not exercised on a host: the repositories-dir check and the exclude globs. The first manual run tests both.Apply
Tags
backup,monitoring.BackupHotStalefires right after the apply until the first success, so start the first full upload by hand as the runbook says. First upload is the whole Forgejo volume (several GB). No Forgejo or portal restart.Refs #158