Fix EBS snapshot state check, drop unused GCS write grant and dead lifecycle rule

This commit is contained in:
Adam Moussa 2026-05-14 13:24:24 -04:00
parent c771ed4f08
commit bafb924cfc
3 changed files with 12 additions and 18 deletions

View file

@ -92,12 +92,18 @@ def _check_ebs_snapshots():
snapshots = resp.get("Snapshots", [])
if not snapshots:
return False, "EBS Snapshots: No snapshots found with forgejo-backup tag"
recent = [s for s in snapshots if s["StartTime"] >= cutoff]
recent = [s for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "completed"]
if not recent:
pending = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "pending")
errored = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "error")
latest = max(snapshots, key=lambda s: s["StartTime"])
age = (now - latest["StartTime"]).total_seconds() / 3600
return False, f"EBS Snapshots: Latest is {age:.0f}h old ({latest['SnapshotId']})"
return True, f"EBS Snapshots: OK — {len(snapshots)} total, {len(recent)} in last 48h"
return False, (
f"EBS Snapshots: No completed snapshot in last 48h "
f"(latest {age:.0f}h old, state={latest.get('State')}; "
f"pending={pending}, error={errored})"
)
return True, f"EBS Snapshots: OK — {len(recent)} completed in last 48h"
except Exception as e:
return False, f"EBS Snapshots: Error — {e}"

View file

@ -26,17 +26,6 @@ export class ForgejoReplicaStack extends cdk.Stack {
},
],
},
{
id: "mirror-to-glacier-then-expire",
prefix: "mirror/",
transitions: [
{
storageClass: s3.StorageClass.GLACIER,
transitionAfter: cdk.Duration.days(30),
},
],
expiration: cdk.Duration.days(365),
},
{
id: "cleanup-noncurrent-versions",
noncurrentVersionExpiration: cdk.Duration.days(90),

View file

@ -89,16 +89,15 @@ if $GCLOUD iam service-accounts describe "$SA_EMAIL" &>/dev/null 2>&1; then
echo "Service account $SA_EMAIL already exists."
else
$GCLOUD iam service-accounts create "$SA_NAME" \
--display-name="Forgejo Backup Writer" \
--description="Write-only access to forgejo offsite backup bucket"
--display-name="Forgejo Backup Verifier" \
--description="Read-only access to forgejo offsite backup bucket (verification Lambda)"
echo "Created service account $SA_EMAIL."
fi
echo ""
echo "--- Step 8: Grant bucket permissions ---"
$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectCreator" "gs://$BUCKET_NAME"
$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectViewer" "gs://$BUCKET_NAME"
echo "Granted objectCreator + objectViewer to $SA_EMAIL."
echo "Granted objectViewer to $SA_EMAIL."
echo ""
echo "--- Step 9: Create and store service account key ---"