mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 01:53:11 +00:00
* fix(terraform): allow HCP refresh of the log group and parameter The scoped apply role can create those resources, but CloudWatch and SSM list them on a wildcard ARN. DescribeLogGroups and DescribeParameters need that resource. * fix(terraform): let the plan role read bucket website config The S3 provider refreshes GetBucketWebsite. The plan role was denied on the three Forgejo buckets. * fix(terraform): let the plan role read backup object metadata HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs. * fix(terraform): let the plan role read object tags and retention The S3 provider refreshes tagging, ACL, attributes, and Object Lock on the Lambda zip. * fix(terraform): scope plan object reads and restore on the data volume The plan role only needs object reads for the verification zip. Unpacking a dump in /tmp fills the root volume. * fix(terraform): accept dumps that already contain data/forgejo.db Today's archive has no gitea-db.sqlite3 at the root. Copy that file only when it is present. * docs(terraform): keep restore runbook on one bucket and fail closed Glacier and the download use the prod bucket. GCS unpacks on the data volume. Neither path deletes live repos until the dump has a database. * docs(terraform): keep optional restore copies from aborting under set -e if/fi matches user_data.sh. The file comment now says forgejo-services versions also go through the org-account role. * fix(terraform): restore the dump app.ini with the database INTERNAL_TOKEN, JWT_SECRET, and LFS_JWT_SECRET live in that file. A restore that keeps the generated file cannot decrypt the dumped secrets. |
||
|---|---|---|
| .. | ||
| .terraform.lock.hcl | ||
| alarms.tf | ||
| alb.tf | ||
| build_lambda.sh | ||
| build_lambda_external.sh | ||
| data.tf | ||
| ec2.tf | ||
| hcp_iam.tf | ||
| iam.tf | ||
| lambda.tf | ||
| locals.tf | ||
| outputs.tf | ||
| providers.tf | ||
| s3.tf | ||
| terraform.tfvars.example | ||
| user_data.sh | ||
| variables.tf | ||
| versions.tf | ||