|
All checks were successful
secrets-guard / encrypted (pull_request) Successful in 7s
PR build (required check) / changes (pull_request) Successful in 8s
PR build (required check) / build-backend (pull_request) Has been skipped
PR build (required check) / build-frontend (pull_request) Has been skipped
PR build (required check) / validate-observability (pull_request) Has been skipped
PR build (required check) / gate (pull_request) Successful in 3s
Prod DB dumps and Forgejo (db + data volume) are now copied off-box to the era5-thermograph S3 bucket, age-encrypted to the vault recipient so the host age key at /etc/thermograph/age.key decrypts them for restore. Nothing plaintext leaves the box; no local intermediate (streamed via age | rclone rcat). ops-cron: the prod pg_dump job gains an off-box push; a new forgejo-backup job dumps Forgejo's Postgres + tars its data volume on beta (the git host had NO backup at all). 30-day off-box retention on both. S3 creds are Forgejo Actions secrets (S3_ENDPOINT/BUCKET/ACCESS_KEY/SECRET_KEY), mirrored into the SOPS vault (prod.yaml/beta.yaml) for host-side use. Contabo needs path-style addressing. Adds deploy/backup/README.md with the DR restore runbook. |
||
|---|---|---|
| .. | ||
| backend-build-push.yml | ||
| backend-deploy-dev.yml | ||
| backend-deploy-prod.yml | ||
| backend-deploy.yml | ||
| build.yml | ||
| frontend-build-push.yml | ||
| frontend-deploy-dev.yml | ||
| frontend-deploy-prod.yml | ||
| frontend-deploy.yml | ||
| infra-sync.yml | ||
| observability-validate.yml | ||
| ops-cron.yml | ||
| pr-build.yml | ||
| secrets-guard.yml | ||