Commit graph

17 commits

Author SHA1 Message Date
Adam Moussa
c771ed4f08 Rename SECRET_ARN env vars to SECRET_NAME to match actual values 2026-05-14 11:38:31 -04:00
Adam Moussa
d59623599c Fix GCS backup check: align staleness cutoff and add size validation
GCS check used a 72h cutoff but only listed 2 days of prefixes (~48h),
making the staleness check unreachable. Also added 1MB minimum file
size validation to match the S3 check.
2026-05-14 10:25:05 -04:00
Adam Moussa
0ab9cc9f30 Handle SQL text dumps separately from binary SQLite in restore test
Forgejo dump produces gitea-db.sql as a text SQL dump (XORM export),
not a binary SQLite file. Opening it directly with sqlite3.connect()
throws DatabaseError. Now imports the SQL dump into a temp DB first.
2026-05-13 18:54:04 -04:00
Cursor Agent
b9726e5176
Fix backup strategy bug findings 2026-05-13 22:32:26 +00:00
Adam Moussa
fa51085578 Address code review findings for backup verification
Fix 4 critical issues:
- Add filter/priority/deleteMarkerReplication to S3 CRR rule (deploy would fail without)
- Add stack dependency so replica deploys before main stack
- Fix DB file extension matching (.sqlite3/.sql instead of .db)
- Replace nonexistent `forgejo restore` command with actual restore steps in README

Fix 4 moderate issues:
- Add timeout=10 to Slack webhook urlopen call
- Add filter='data' to tarfile.extract for PEP 706 compliance
- Add explicit ValueError for unknown handler mode
- Use date-scoped S3/GCS prefix instead of unbounded listing
2026-05-13 18:29:28 -04:00
Adam Moussa
17179c84b2 Fix GCP project ID to sea-haven-backups 2026-05-13 18:15:56 -04:00
Adam Moussa
0d3f9ad5a3 Commit cdk.context.json for CI synth without AWS credentials
Vpc.fromLookup requires cached context to synthesize without
AWS credentials. Required for CI which runs cdk synth without
an OIDC role.
2026-05-13 18:15:37 -04:00
Adam Moussa
5904fcc4d7 Enable QEMU in CI for arm64 Lambda Docker builds 2026-05-13 18:09:21 -04:00
Adam Moussa
d57aea19f3 Add 3-2-1 backup strategy with cross-region replication and GCS offsite
Implements a fully compliant 3-2-1 backup architecture:
- Copy 1 (live): Harden existing EBS snapshots to 30-day retention
- Copy 2 (near-site): S3 cross-region replication to us-west-2 with
  Object Lock (governance 90d) and versioning
- Copy 3 (offsite): GCS bucket in dedicated seahaven-backups GCP project
  with 2-year irreversible retention lock

Also adds a verification Lambda that checks all 3 locations daily and
runs monthly restore tests with SQLite integrity checks.
2026-05-13 18:02:50 -04:00
Adam Moussa
6ccfc1c506
Update README with backup, autodiscovery, and token management docs (#1)
Some checks failed
Deploy / deploy (push) Has been cancelled
Add documentation for S3 backups with Glacier lifecycle, hourly
autodiscovery of new GitHub org repos, daily PAT token refresh,
PAT rotation procedure, and Secrets Manager secret inventory.
2026-05-11 19:03:42 -04:00
Adam Moussa
ba937f1b83 Add autodiscovery and token refresh crons
Autodiscovery runs hourly — creates Forgejo mirrors for new GitHub
org repos. Token refresh runs daily — propagates the current PAT
from Secrets Manager to all mirror git remotes.
2026-05-11 18:46:25 -04:00
Adam Moussa
2f344ac7c0 Add nightly S3 backups with Glacier lifecycle
Some checks are pending
Deploy / deploy (push) Waiting to run
S3 bucket for Forgejo dumps (Standard 30d → Glacier, expire 365d).
Cron runs forgejo dump at 5 AM UTC and uploads to S3.
2026-05-11 18:26:26 -04:00
Adam Moussa
0a4119880e Update README for ALB-backed HTTPS setup 2026-05-11 18:13:54 -04:00
Adam Moussa
ed41fd4eac Add ALB egress rule for Forgejo target group
ALB security group has restricted outbound — needed explicit
egress to the Forgejo SG on port 3000 for health checks.
2026-05-11 18:13:21 -04:00
Adam Moussa
9e0a14e5b8 Route through seahaven-com ALB for HTTPS
Add target group, listener rule (forgejo.seahaven.com), and alias
the Route53 record to the ALB. SSL termination via wildcard cert.
2026-05-11 18:08:36 -04:00
Adam Moussa
83c381b1da Fix subnet import to include availability zone
CDK requires availabilityZone when using fromSubnetAttributes
for EC2 instance placement.
2026-05-11 17:58:14 -04:00
Adam Moussa
a500d69716 Add Forgejo CDK stack
EC2 (t4g.small, arm64) in private subnet with VPN-only access,
DLM nightly snapshots, and Route53 DNS at forgejo.seahaven.com.
2026-05-11 17:52:37 -04:00