Fix restore runbook, DLM snapshot tagging, README cleanup, and gsutil prompt

This commit is contained in:
Adam Moussa 2026-05-14 13:56:36 -04:00
parent bafb924cfc
commit 5cae537ee2
3 changed files with 6 additions and 8 deletions

View file

@ -8,7 +8,7 @@ Self-hosted Forgejo git server for archiving GitHub repos and mirroring active o
- **Network**: Private subnet (us-east-1a), behind `seahaven-com` ALB for SSL termination
- **DNS**: `forgejo.seahaven.com` — Route53 alias record pointing to the `seahaven-com` ALB (not a direct A record)
- **TLS**: Wildcard cert on ALB, HTTP internally on port 3000
- **Backup**: Nightly `forgejo dump` to S3 + EBS snapshots via DLM (see [S3 Backups](#s3-backups))
- **Backup**: Nightly `forgejo dump` to S3 + EBS snapshots via DLM (see [3-2-1 Backup Strategy](#3-2-1-backup-strategy))
- **Admin access**: SSM Session Manager (no SSH port exposed)
- **CI/CD**: GitHub Actions with OIDC role `githubdeploy-forgejo`
@ -74,6 +74,9 @@ cp app.ini /etc/forgejo/app.ini
cp gitea-db.sqlite3 /var/lib/forgejo/data/forgejo.db
rm -rf /var/lib/forgejo/data/repositories
cp -a repos /var/lib/forgejo/data/repositories
cp -a data/. /var/lib/forgejo/data/
[ -d lfs ] && cp -a lfs /var/lib/forgejo/data/lfs
[ -d custom ] && cp -a custom /var/lib/forgejo/custom
chown -R forgejo:forgejo /var/lib/forgejo /etc/forgejo/app.ini
systemctl start forgejo
rm -rf /tmp/forgejo-restore /tmp/forgejo-<date>.tar.gz
@ -87,12 +90,6 @@ gsutil cp gs://forgejo-backups-offsite-seahaven/archive/<date>/forgejo-<date>.ta
# Then follow the same restore steps as S3 above
```
To test the backup manually:
```bash
sudo /usr/local/bin/forgejo-backup.sh
```
## Autodiscovery
An hourly cron job checks the `Sea-Haven-Industries` GitHub org for new repositories and mirrors them into Forgejo automatically.

View file

@ -381,6 +381,7 @@ export class ForgejoStack extends cdk.Stack {
createRule: { interval: 24, intervalUnit: "HOURS", times: ["06:00"] },
retainRule: { count: 30 },
copyTags: true,
tagsToAdd: [{ key: "forgejo-backup", value: "true" }],
}],
},
});

View file

@ -76,7 +76,7 @@ echo "Even the project owner cannot shorten or remove the policy."
echo ""
read -p "Lock the retention policy now? (yes/no): " CONFIRM
if [ "$CONFIRM" = "yes" ]; then
$GSUTIL retention lock "gs://$BUCKET_NAME"
echo y | $GSUTIL retention lock "gs://$BUCKET_NAME"
echo "Retention policy LOCKED."
else
echo "Retention policy set but NOT locked. Run 'gsutil retention lock gs://$BUCKET_NAME' when ready."