mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-10-04 09:02:01 +00:00
Fix EBS snapshot state check, drop unused GCS write grant and dead lifecycle rule
This commit is contained in:
parent
c771ed4f08
commit
bafb924cfc
3 changed files with 12 additions and 18 deletions
|
|
@ -92,12 +92,18 @@ def _check_ebs_snapshots():
|
||||||
snapshots = resp.get("Snapshots", [])
|
snapshots = resp.get("Snapshots", [])
|
||||||
if not snapshots:
|
if not snapshots:
|
||||||
return False, "EBS Snapshots: No snapshots found with forgejo-backup tag"
|
return False, "EBS Snapshots: No snapshots found with forgejo-backup tag"
|
||||||
recent = [s for s in snapshots if s["StartTime"] >= cutoff]
|
recent = [s for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "completed"]
|
||||||
if not recent:
|
if not recent:
|
||||||
|
pending = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "pending")
|
||||||
|
errored = sum(1 for s in snapshots if s["StartTime"] >= cutoff and s.get("State") == "error")
|
||||||
latest = max(snapshots, key=lambda s: s["StartTime"])
|
latest = max(snapshots, key=lambda s: s["StartTime"])
|
||||||
age = (now - latest["StartTime"]).total_seconds() / 3600
|
age = (now - latest["StartTime"]).total_seconds() / 3600
|
||||||
return False, f"EBS Snapshots: Latest is {age:.0f}h old ({latest['SnapshotId']})"
|
return False, (
|
||||||
return True, f"EBS Snapshots: OK — {len(snapshots)} total, {len(recent)} in last 48h"
|
f"EBS Snapshots: No completed snapshot in last 48h "
|
||||||
|
f"(latest {age:.0f}h old, state={latest.get('State')}; "
|
||||||
|
f"pending={pending}, error={errored})"
|
||||||
|
)
|
||||||
|
return True, f"EBS Snapshots: OK — {len(recent)} completed in last 48h"
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
return False, f"EBS Snapshots: Error — {e}"
|
return False, f"EBS Snapshots: Error — {e}"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -26,17 +26,6 @@ export class ForgejoReplicaStack extends cdk.Stack {
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
|
||||||
id: "mirror-to-glacier-then-expire",
|
|
||||||
prefix: "mirror/",
|
|
||||||
transitions: [
|
|
||||||
{
|
|
||||||
storageClass: s3.StorageClass.GLACIER,
|
|
||||||
transitionAfter: cdk.Duration.days(30),
|
|
||||||
},
|
|
||||||
],
|
|
||||||
expiration: cdk.Duration.days(365),
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
id: "cleanup-noncurrent-versions",
|
id: "cleanup-noncurrent-versions",
|
||||||
noncurrentVersionExpiration: cdk.Duration.days(90),
|
noncurrentVersionExpiration: cdk.Duration.days(90),
|
||||||
|
|
|
||||||
|
|
@ -89,16 +89,15 @@ if $GCLOUD iam service-accounts describe "$SA_EMAIL" &>/dev/null 2>&1; then
|
||||||
echo "Service account $SA_EMAIL already exists."
|
echo "Service account $SA_EMAIL already exists."
|
||||||
else
|
else
|
||||||
$GCLOUD iam service-accounts create "$SA_NAME" \
|
$GCLOUD iam service-accounts create "$SA_NAME" \
|
||||||
--display-name="Forgejo Backup Writer" \
|
--display-name="Forgejo Backup Verifier" \
|
||||||
--description="Write-only access to forgejo offsite backup bucket"
|
--description="Read-only access to forgejo offsite backup bucket (verification Lambda)"
|
||||||
echo "Created service account $SA_EMAIL."
|
echo "Created service account $SA_EMAIL."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "--- Step 8: Grant bucket permissions ---"
|
echo "--- Step 8: Grant bucket permissions ---"
|
||||||
$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectCreator" "gs://$BUCKET_NAME"
|
|
||||||
$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectViewer" "gs://$BUCKET_NAME"
|
$GSUTIL iam ch "serviceAccount:${SA_EMAIL}:objectViewer" "gs://$BUCKET_NAME"
|
||||||
echo "Granted objectCreator + objectViewer to $SA_EMAIL."
|
echo "Granted objectViewer to $SA_EMAIL."
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "--- Step 9: Create and store service account key ---"
|
echo "--- Step 9: Create and store service account key ---"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue