The SnapshotPolicy schedule set both copyTags:true and tagsToAdd
file-share-backup=true. Since that tag is already on the data volume,
copyTags propagates it to each snapshot and the explicit tagsToAdd of
the same key triggers DLM's duplicate-tag error, leaving the policy in
ERROR state -- nightly snapshots of the 500 GB NAS volume were silently
failing. Dropping the redundant tagsToAdd (copyTags still tags the
snapshots) lets the policy run.
The live policy was already corrected out-of-band to stop the failing
backups; this commit codifies that change so the next clean deploy shows
no drift on the policy.
aws-cdk-lib 2.254.0 has a bundled dependency bug where npm ci reports
jsonschema@1.4.1 as missing from the lock file. Pinning to 2.253.1
which is proven working in CI (same version as forgejo).
CDK stack deploying a t4g.small EC2 instance with Samba and FileBrowser
for personal file storage over the site-to-site VPN. Includes 500 GiB
gp3 data volume with daily DLM snapshots.