Record verified Forgejo Scaleway backup and recovery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 01:03:02 +02:00
parent be45c4e3fd
commit 4a9d6e6c7f
8 changed files with 114 additions and 11 deletions

View file

@ -9,7 +9,7 @@ Backup, 10 GiB quota. Provider selection does not establish asset coverage.
| apps-pg | Scaleway Barman base backups + WAL, `platform-pg/apps-pg/` | Fresh isolated physical restore passed in 42.64 seconds; Nextcloud logical copy is separate |
| platform-pg | Scaleway Barman base backups + WAL, `platform-pg/` | Earlier package restore evidence; independent logical Nextcloud copy |
| platform-pg-2 | Scaleway Barman base backups + WAL, `platform-pg/platform-pg-2/` | Earlier package restore evidence; independent logical Nextcloud copy |
| forgejo-db | No native Barman destination observed | Logical SQL/full archive helper targets Nextcloud; primary coverage needs implementation |
| forgejo-db | Scaleway Barman base backups + WAL, `platform-pg/forgejo-db/`; daily 02:35 UTC, 30-day retention | Fresh isolated physical restore passed in 45.08 seconds; full archive coverage remains separate |
| Forgejo repositories/packages/blobs | No reviewed Scaleway archive destination found | Corrected full-archive capture; 5.35 GB verified encrypted artifact staged; secondary download/application restore still pending |
| net-kingdom-pg / state-hub-db | No native Barman destination observed | Do not infer protection from the shared cells' healthy backup status |
| OpenBao / S1 host configuration | Not evaluated by this database restore | Their own encrypted snapshot/host backup and recovery contracts still apply |
@ -37,11 +37,15 @@ or assume a top-level `forgejo/` prefix is permitted. Before extending coverage:
3. Use a streaming multipart S3 uploader for growing archives, with abort/cleanup
and immutable object naming. Verify completion and content, then recover by
GET from Scaleway into the isolated Forgejo procedure.
4. Set native forgejo-db Barman coverage through its owning package/source,
with a separate tested recovery and no production in-place restore.
4. Native forgejo-db Barman coverage and isolated recovery are complete in
RPF-WP-0038-T02/T03. See `docs/evidence/forgejo-scaleway-restore-2026-09-06.json`.
5. Record provider-native retention and primary failure reporting separately
from the 10 GiB secondary budget. No retained backup deletion is implicit.
WP-0029 remains the secondary credential incident: old Bernd-share invalidation
and replacement recovery. The full primary coverage gap belongs to S3 assurance
(RPF-WP-0036-T03), with forge requirements and package/storage-owner inputs.
RPF-WP-0038-T04 tracks the remaining primary full-archive delivery and application
recovery contract. Native database recovery verified 142 repository records,
six users and 2,040 package blob records; it did not recover the blob files.