feat(backup-drill): restore and verify the hourly hot backup #521
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!521
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/158-drill-hot"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Rollout PR 3 of #158 (ADR 0041): the weekly drill also proves the hourly hot backup restores.
hotsnapshot for this host must be at most 65 min older than the drill start.ssh … tar. No restic or S3 credentials reach the VM. Free space checked first (backup_drill_hot_min_free_gb, 2); temp dir removed infinally.pg_restorethe portal dump into scratch Postgres and assertbitborg_backup.canary.atis within 2 min of the snapshot time;git fsck --connectivity-onlyon every restored repo, fail on any error or zero repos.bitborg_backup_drill_hot_status,…_snapshot_age_seconds,…_repos_checked. A hot failure fails the overall drill, soBackupDrillFailedfires (description extended). Gated bybackup_drill_hot_enabled(followsbackup_hot_enabled).Verification
--syntax-check, ansible-lint 0, rendered templates passpy_compile,bash -n, shellcheck (one intended SC2016 info). Local unit checks: timestamp parsing on four formats, the metric writer, and the fsck loop against good and corrupted bare repos. Not yet run end to end: the first manual drill after the apply is the test.Closes #158
9c09ebd8402cf944b23c