feat(backup): Postgres backups to the hov1 site through the Barman Cloud plugin #22
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "backup-hov1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal: back up PostgreSQL in dataverket-prod safely to the hov1 S3 host.
Cluster side: infrastructure/cnpg-barman-plugin installs the Barman Cloud plugin v0.15.0 into cnpg-system beside CNPG 1.30.0. In forgejo and zitadel: a plain Secret hov1-s3 (CA root, endpoint, region), a sops-encrypted Secret s3-cnpg- (the writer account), an ObjectStore hov1 (14 days retention, gzip WAL and data, endpointCA and region from hov1-s3) and a daily ScheduledBackup with immediate: true. Both Cluster objects get the plugin stanza with isWALArchiver. Applying adds a sidecar to every instance: a rolling restart of both clusters and one primary switchover each.
Site side: backup/versitygw is now versitygw alone behind a private CA made offline with step (root and certificate valid three years, bin/cert); no step-ca, no renewer. Scripts keep every secret out of argv. backup/hov1 is live on the host with buckets cnpg-forgejo and cnpg-zitadel, each owned by its account.
Docs: the three backup READMEs rewritten for scanning (map, runbooks, failure modes, references) and updated for the offline CA and the sops handover; plan text follows.
Not included: a swamp model for the compose lifecycle. @smith/docker-compose fails on current swamp (reserved data name latest) and declares no repository or license; a @dataverket compose model is the follow-up.