mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 14:23:11 +00:00
Implements a fully compliant 3-2-1 backup architecture: - Copy 1 (live): Harden existing EBS snapshots to 30-day retention - Copy 2 (near-site): S3 cross-region replication to us-west-2 with Object Lock (governance 90d) and versioning - Copy 3 (offsite): GCS bucket in dedicated seahaven-backups GCP project with 2-year irreversible retention lock Also adds a verification Lambda that checks all 3 locations daily and runs monthly restore tests with SQLite integrity checks.
48 lines
1.4 KiB
TypeScript
48 lines
1.4 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as s3 from "aws-cdk-lib/aws-s3";
|
|
import { Construct } from "constructs";
|
|
|
|
export class ForgejoReplicaStack extends cdk.Stack {
|
|
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
|
super(scope, id, props);
|
|
|
|
new s3.Bucket(this, "ReplicaBucket", {
|
|
bucketName: "forgejo-backups-replica-328440206208",
|
|
encryption: s3.BucketEncryption.S3_MANAGED,
|
|
blockPublicAccess: s3.BlockPublicAccess.BLOCK_ALL,
|
|
versioned: true,
|
|
objectLockEnabled: true,
|
|
objectLockDefaultRetention: s3.ObjectLockRetention.governance(
|
|
cdk.Duration.days(90)
|
|
),
|
|
lifecycleRules: [
|
|
{
|
|
id: "archive-to-glacier",
|
|
prefix: "archive/",
|
|
transitions: [
|
|
{
|
|
storageClass: s3.StorageClass.GLACIER,
|
|
transitionAfter: cdk.Duration.days(30),
|
|
},
|
|
],
|
|
},
|
|
{
|
|
id: "mirror-to-glacier-then-expire",
|
|
prefix: "mirror/",
|
|
transitions: [
|
|
{
|
|
storageClass: s3.StorageClass.GLACIER,
|
|
transitionAfter: cdk.Duration.days(30),
|
|
},
|
|
],
|
|
expiration: cdk.Duration.days(365),
|
|
},
|
|
{
|
|
id: "cleanup-noncurrent-versions",
|
|
noncurrentVersionExpiration: cdk.Duration.days(90),
|
|
},
|
|
],
|
|
removalPolicy: cdk.RemovalPolicy.RETAIN,
|
|
});
|
|
}
|
|
}
|