Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
5 KiB
| id | type | title | domain | repo | status | owner | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|
| RPF-WP-0038 | workplan | Close Forgejo primary backup coverage on Scaleway | financials | railiance-platform | active | codex | 2026-09-06 | 2026-09-06 | 7beec1a7-aa82-5a36-9a66-6b60008a2455 |
Scaleway is the user-confirmed primary; Nextcloud is independent secondary. Follow-up to the live coverage gap in RPF-WP-0036-T03. WP-0029 retains the secondary incident and old-share invalidation. No old backups are deleted.
Verify ownership and scoped primary destination
id: RPF-WP-0038-T01
status: done
priority: high
state_hub_task_id: "4f5e594a-e731-5298-8ba4-5b1e0cd9e71d"
This repository owns helm/forgejo-db-cluster.yaml and its deploy target. Reuse CCR-2026-0012's backup runtime identity and existing databases Secret. The reviewed bucket policy permits platform-pg/*; choose the separate native Barman destination platform-pg/forgejo-db/. No bootstrap key, IAM mutation or namespace expansion is required. Never write full archives into a Barman server directory. Retention follows the existing 30-day primary contract.
Activate native database backup and prove fresh completion
id: RPF-WP-0038-T02
status: done
priority: high
state_hub_task_id: "b6960c2e-1ad3-5c23-bfb6-9f1f16d0f0c2"
Add exact Scaleway destination, HTTPS/DNS egress, continuous WAL and daily base backup. Apply only the reviewed backup field with a resource-version guard, preserving unrelated live settings. Require a completed fresh Backup, continuous archiving and source readiness; record metadata only.
Completed: fresh backup forgejo-db-daily-20260905225013, backup ID
20260905T225115, source Ready and continuous archiving healthy. Evidence:
docs/evidence/forgejo-scaleway-activation-2026-09-06.json.
Prove isolated primary database recovery
id: RPF-WP-0038-T03
status: done
priority: high
state_hub_task_id: "b47b5905-83c8-5da8-9951-e8cb7b7459f9"
Recover a new scratch cluster from the native Scaleway base backup/WAL. Verify expected Forgejo database and nonempty repository/user/package metadata, source readiness and scratch cleanup. This is database recovery, not combined Forgejo blob/application recovery.
Completed: restored in 45.08 seconds, 142 repository records, six users and
2,040 package blob records. Production remained Ready; scratch namespace
removed. Evidence: docs/evidence/forgejo-scaleway-restore-2026-09-06.json.
Establish primary full-archive delivery and application recovery
id: RPF-WP-0038-T04
status: progress
priority: high
state_hub_task_id: "a4807df0-ec96-58f1-9cbd-42b1dcde0d6f"
Choose an independent archive prefix and confirm storage retention/caller contract, bounded worker credential delivery and multipart transfer/abort. Then retrieve a primary full archive and execute isolated application recovery. The existing 5.35 GB encrypted verified archive is available in private staging. Keep Nextcloud's 10 GiB secondary budget separate. The current helper still uploads only to Nextcloud until this task's full delivery is implemented and verified; native database backup alone cannot close the workplan.
Secondary capacity observation (not a native-primary acceptance gate): after the successful full recovery and rejected-fixture DELETE, immediate Nextcloud metadata still reported 5,234,716,518 free bytes, below one current archive's 5,353,024,293 bytes. Recheck quota and settle bounded archive retention/capacity with the owning package; do not automatically delete retained good backups.
User-directed storage split assessment: docs/backup-storage-tiers.md and
history/2026-09-06-backup-capacity-and-essentials-assessment.md. Keep full
archives on Scaleway and design a measured essentials-only Nextcloud profile.
T04 acceptance includes package/bootstrap audit, primary-independent essentials
recovery, quota preflight and separate bounded retention execution before
changing scheduled secondary scope. No blanket package exclusion is activated.
Implementation evidence, September 6: full Scaleway multipart transfer, versioned
GET, decryption and isolated application recovery passed (all 2,040 package
blobs). Essentials capture is 273 MiB; real Nextcloud round trip and isolated
source/collaboration recovery passed with package service disabled. Retention
planner and separate attended owner executor are implemented and tested; no
live expiration or cron cutover performed. T04 remains in progress for durable
scheduled caller/dependency binding, canonical verified inventory, fresh quota
checks and owner retention activation. See
history/2026-09-06-backup-tiers-implementation.md.
Receipt follow-up, September 6: new archive transfer/decryption/restore runs now record operation timestamps and provenance receipt hashes. Cleanup failure cannot leave a successful restore status. Historical primary decryption receipts remain accepted explicitly, while new decryption retains its own schema. No repeat upload, expiry or scheduled caller change was made; T04 remains in progress for the existing durable caller, inventory, quota and retention gates.