mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-10-07 07:28:53 +00:00
Read backup S3 prefix from SSM parameter at runtime
Adds /forgejo/backup-s3-prefix SSM parameter (value: archive) and updates the backup script to fetch it instead of hardcoding the prefix. Eliminates the manual post-deploy sed step.
This commit is contained in:
parent
9d48c82d77
commit
deaae36396
2 changed files with 13 additions and 11 deletions
12
README.md
12
README.md
|
|
@ -199,17 +199,9 @@ This deploys two stacks:
|
||||||
|
|
||||||
CI/CD is handled by GitHub Actions — PRs run CI, merges to `main` deploy via the reusable CDK workflow.
|
CI/CD is handled by GitHub Actions — PRs run CI, merges to `main` deploy via the reusable CDK workflow.
|
||||||
|
|
||||||
## Post-deploy: update running instance backup path
|
## Post-deploy: store Slack webhook
|
||||||
|
|
||||||
After the first deploy with the 3-2-1 changes, the running instance's backup script still uses the old S3 path (without the `archive/` prefix). Update it via SSM:
|
Store the Slack webhook URL for backup verification alerts:
|
||||||
|
|
||||||
```bash
|
|
||||||
INSTANCE_ID=$(aws cloudformation describe-stacks --stack-name forgejo --query 'Stacks[0].Outputs[?OutputKey==`InstanceId`].OutputValue' --output text)
|
|
||||||
aws ssm start-session --target "$INSTANCE_ID"
|
|
||||||
sudo sed -i 's|s3://forgejo-backups-328440206208/${TIMESTAMP}/|s3://forgejo-backups-328440206208/archive/${TIMESTAMP}/|' /usr/local/bin/forgejo-backup.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
Also store the Slack webhook URL for backup verification alerts:
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
aws secretsmanager create-secret --name forgejo/slack-webhook \
|
aws secretsmanager create-secret --name forgejo/slack-webhook \
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,7 @@ import * as elbv2 from "aws-cdk-lib/aws-elasticloadbalancingv2";
|
||||||
import * as elbv2_targets from "aws-cdk-lib/aws-elasticloadbalancingv2-targets";
|
import * as elbv2_targets from "aws-cdk-lib/aws-elasticloadbalancingv2-targets";
|
||||||
import * as route53 from "aws-cdk-lib/aws-route53";
|
import * as route53 from "aws-cdk-lib/aws-route53";
|
||||||
import * as route53Targets from "aws-cdk-lib/aws-route53-targets";
|
import * as route53Targets from "aws-cdk-lib/aws-route53-targets";
|
||||||
|
import * as ssm from "aws-cdk-lib/aws-ssm";
|
||||||
import * as dlm from "aws-cdk-lib/aws-dlm";
|
import * as dlm from "aws-cdk-lib/aws-dlm";
|
||||||
import { Construct } from "constructs";
|
import { Construct } from "constructs";
|
||||||
import { BackupVerification } from "./constructs/backup-verification";
|
import { BackupVerification } from "./constructs/backup-verification";
|
||||||
|
|
@ -84,6 +85,14 @@ export class ForgejoStack extends cdk.Stack {
|
||||||
|
|
||||||
backupBucket.grantReadWrite(role);
|
backupBucket.grantReadWrite(role);
|
||||||
|
|
||||||
|
const backupS3Prefix = new ssm.StringParameter(this, "BackupS3Prefix", {
|
||||||
|
parameterName: "/forgejo/backup-s3-prefix",
|
||||||
|
description: "S3 key prefix for Forgejo backup dumps",
|
||||||
|
stringValue: "archive",
|
||||||
|
});
|
||||||
|
|
||||||
|
backupS3Prefix.grantRead(role);
|
||||||
|
|
||||||
const replicaBucketArn = "arn:aws:s3:::forgejo-backups-replica-328440206208";
|
const replicaBucketArn = "arn:aws:s3:::forgejo-backups-replica-328440206208";
|
||||||
|
|
||||||
const replicationRole = new iam.Role(this, "ReplicationRole", {
|
const replicationRole = new iam.Role(this, "ReplicationRole", {
|
||||||
|
|
@ -239,11 +248,12 @@ export class ForgejoStack extends cdk.Stack {
|
||||||
"#!/bin/bash",
|
"#!/bin/bash",
|
||||||
"set -euo pipefail",
|
"set -euo pipefail",
|
||||||
"TIMESTAMP=$(date +%Y-%m-%d)",
|
"TIMESTAMP=$(date +%Y-%m-%d)",
|
||||||
|
"S3_PREFIX=$(aws ssm get-parameter --name /forgejo/backup-s3-prefix --query Parameter.Value --output text --region us-east-1)",
|
||||||
"DUMP_DIR=$(mktemp -d)",
|
"DUMP_DIR=$(mktemp -d)",
|
||||||
"chown forgejo:forgejo \"$DUMP_DIR\"",
|
"chown forgejo:forgejo \"$DUMP_DIR\"",
|
||||||
"cd \"$DUMP_DIR\"",
|
"cd \"$DUMP_DIR\"",
|
||||||
"sudo -u forgejo /usr/local/bin/forgejo dump --config /etc/forgejo/app.ini --type tar.gz --file \"$DUMP_DIR/forgejo-${TIMESTAMP}.tar.gz\"",
|
"sudo -u forgejo /usr/local/bin/forgejo dump --config /etc/forgejo/app.ini --type tar.gz --file \"$DUMP_DIR/forgejo-${TIMESTAMP}.tar.gz\"",
|
||||||
"aws s3 cp \"$DUMP_DIR/forgejo-${TIMESTAMP}.tar.gz\" s3://forgejo-backups-328440206208/archive/${TIMESTAMP}/forgejo-${TIMESTAMP}.tar.gz",
|
"aws s3 cp \"$DUMP_DIR/forgejo-${TIMESTAMP}.tar.gz\" s3://forgejo-backups-328440206208/${S3_PREFIX}/${TIMESTAMP}/forgejo-${TIMESTAMP}.tar.gz",
|
||||||
"rm -rf \"$DUMP_DIR\"",
|
"rm -rf \"$DUMP_DIR\"",
|
||||||
"BAKEOF",
|
"BAKEOF",
|
||||||
"chmod +x /usr/local/bin/forgejo-backup.sh",
|
"chmod +x /usr/local/bin/forgejo-backup.sh",
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue