diff --git a/lambda/backup-verification/app.py b/lambda/backup-verification/app.py index 7b2aae9..a471c0a 100644 --- a/lambda/backup-verification/app.py +++ b/lambda/backup-verification/app.py @@ -92,12 +92,18 @@ def _check_ebs_snapshots(): snapshots = resp.get("Snapshots", []) if not snapshots: return False, "EBS Snapshots: No snapshots found with forgejo-backup tag" - recent = [s for s in snapshots if s["StartTime"] >= cutoff] + recent = [s for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "completed"] if not recent: + pending = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "pending") + errored = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "error") latest = max(snapshots, key=lambda s: s["StartTime"]) age = (now - latest["StartTime"]).total_seconds() / 3600 - return False, f"EBS Snapshots: Latest is {age:.0f}h old ({latest['SnapshotId']})" - return True, f"EBS Snapshots: OK — {len(snapshots)} total, {len(recent)} in last 48h" + return False, ( + f"EBS Snapshots: No completed snapshot in last 48h " + f"(latest {age:.0f}h old, state={latest.get('State')}; " + f"pending={pending}, error={errored})" + ) + return True, f"EBS Snapshots: OK — {len(recent)} completed in last 48h" except Exception as e: return False, f"EBS Snapshots: Error — {e}" diff --git a/lib/forgejo-replica-stack.ts b/lib/forgejo-replica-stack.ts index 1dd21fa..ca8fa5a 100644 --- a/lib/forgejo-replica-stack.ts +++ b/lib/forgejo-replica-stack.ts @@ -26,17 +26,6 @@ export class ForgejoReplicaStack extends cdk.Stack { }, ], }, - { - id: "mirror-to-glacier-then-expire", - prefix: "mirror/", - transitions: [ - { - storageClass: s3.StorageClass.GLACIER, - transitionAfter: cdk.Duration.days(30), - }, - ], - expiration: cdk.Duration.days(365), - }, { id: "cleanup-noncurrent-versions", noncurrentVersionExpiration: cdk.Duration.days(90), diff --git a/scripts/gcp-setup.sh b/scripts/gcp-setup.sh index 274c2a1..db40c88 100755 --- a/scripts/gcp-setup.sh +++ b/scripts/gcp-setup.sh @@ -89,16 +89,15 @@ if $GCLOUD iam service-accounts describe "$SA_EMAIL" &>/dev/null 2>&1; then echo "Service account $SA_EMAIL already exists." else $GCLOUD iam service-accounts create "$SA_NAME" \ - --display-name="Forgejo Backup Writer" \ - --description="Write-only access to forgejo offsite backup bucket" + --display-name="Forgejo Backup Verifier" \ + --description="Read-only access to forgejo offsite backup bucket (verification Lambda)" echo "Created service account $SA_EMAIL." fi echo "" echo "--- Step 8: Grant bucket permissions ---" -$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectCreator" "gs://$BUCKET_NAME" $GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectViewer" "gs://$BUCKET_NAME" -echo "Granted objectCreator + objectViewer to $SA_EMAIL." +echo "Granted objectViewer to $SA_EMAIL." echo "" echo "--- Step 9: Create and store service account key ---"