feat(backup): Postgres backups to the hov1 site through the Barman Cloud plugin #22

Merged
beddari merged 1 commit from backup-hov1 into main 2026-09-20 21:04:31 +00:00
Owner

Goal: back up PostgreSQL in dataverket-prod safely to the hov1 S3 host.

Cluster side: infrastructure/cnpg-barman-plugin installs the Barman Cloud plugin v0.15.0 into cnpg-system beside CNPG 1.30.0. In forgejo and zitadel: a plain Secret hov1-s3 (CA root, endpoint, region), a sops-encrypted Secret s3-cnpg- (the writer account), an ObjectStore hov1 (14 days retention, gzip WAL and data, endpointCA and region from hov1-s3) and a daily ScheduledBackup with immediate: true. Both Cluster objects get the plugin stanza with isWALArchiver. Applying adds a sidecar to every instance: a rolling restart of both clusters and one primary switchover each.

Site side: backup/versitygw is now versitygw alone behind a private CA made offline with step (root and certificate valid three years, bin/cert); no step-ca, no renewer. Scripts keep every secret out of argv. backup/hov1 is live on the host with buckets cnpg-forgejo and cnpg-zitadel, each owned by its account.

Docs: the three backup READMEs rewritten for scanning (map, runbooks, failure modes, references) and updated for the offline CA and the sops handover; plan text follows.

Not included: a swamp model for the compose lifecycle. @smith/docker-compose fails on current swamp (reserved data name latest) and declares no repository or license; a @dataverket compose model is the follow-up.

Goal: back up PostgreSQL in dataverket-prod safely to the hov1 S3 host. Cluster side: infrastructure/cnpg-barman-plugin installs the Barman Cloud plugin v0.15.0 into cnpg-system beside CNPG 1.30.0. In forgejo and zitadel: a plain Secret hov1-s3 (CA root, endpoint, region), a sops-encrypted Secret s3-cnpg-<bucket> (the writer account), an ObjectStore hov1 (14 days retention, gzip WAL and data, endpointCA and region from hov1-s3) and a daily ScheduledBackup with immediate: true. Both Cluster objects get the plugin stanza with isWALArchiver. Applying adds a sidecar to every instance: a rolling restart of both clusters and one primary switchover each. Site side: backup/versitygw is now versitygw alone behind a private CA made offline with step (root and certificate valid three years, bin/cert); no step-ca, no renewer. Scripts keep every secret out of argv. backup/hov1 is live on the host with buckets cnpg-forgejo and cnpg-zitadel, each owned by its account. Docs: the three backup READMEs rewritten for scanning (map, runbooks, failure modes, references) and updated for the offline CA and the sops handover; plan text follows. Not included: a swamp model for the compose lifecycle. @smith/docker-compose fails on current swamp (reserved data name latest) and declares no repository or license; a @dataverket compose model is the follow-up.
beddari deleted branch backup-hov1 2026-09-20 21:05:25 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk-infra!22
No description provided.