Commit 415c793921
415c79392148f279fd58313935e668f12a5fd5be
parent: 1346335ed2
Verified · cmc ci/build: success ci/test: skipped
cmc <hello@cleberg.net> · 2026-09-29 05:15 UTC
wiki: first restore drill recorded
Closes #259
Layout: unified · split
.gitbay/wiki/Admin.org
+7 −3
| @@ -728,12 +728,16 @@ the time of the newest restic snapshot restored; record beside it the |
| 728 | 728 | newest issue, comment and push =restore-drill= printed, which show how |
| 729 | 729 | much activity the restore carries. |
| 730 | 730 | |
| 731 | | No drill has been run yet; the procedure above is written but |
| 732 | | unexercised, and #259 stays open until the first row below is |
| 733 | | recorded. |
| 731 | The first drill ran on the operator's laptop rather than a provisioned |
| 732 | host, so its time to service has no provisioning in it, and it could |
| 733 | not check secrets: no copy of =secret.key= was on the machine, and |
| 734 | gitbayd refuses to start while any sealed value does not open. The |
| 735 | sealed values were cleared in the drill copy to reach service; #305 |
| 736 | tracks proving the off-host key. |
| 734 | 737 | |
| 735 | 738 | | Date | Host | Snapshot restored (UTC) | Newest issue / comment / push | Time to service | DB integrity | Connectivity | LFS | Release assets | Host key | Secrets | Notes | |
| 736 | 739 | |------+------+-------------------------+-------------------------------+-----------------+--------------+--------------+-----+----------------+----------+---------+-------| |
| 740 | | 2026-09-29 | laptop (macOS), restic from offsite | 2026-09-29 00:19:15 (ccd646cf) | 00:05:17 / 00:09:44 / 00:15:31 | 8m43s (restore 1m49s, checks 33s) | ok | ok, 69/69 | ok, 2 | ok, 529 | matches | not checked (#305) | 4.99 GiB restored; 71 sealed values cleared in the drill copy to start | |
| 737 | 741 | |
| 738 | 742 | * Upgrades |
| 739 | 743 | |
.gitbay/wiki/Architecture/08-Operations.org
+1 −1
| @@ -75,7 +75,7 @@ the product activity feed, not an audit trail. |
| 75 | 75 | cannot destroy its own history (documented: Admin wiki). |
| 76 | 76 | - Recovery point: about one hour for database-only data (issues, merge |
| 77 | 77 | requests, reviews), one day for repositories. |
| 78 | | - Recovery time: see the Admin wiki's Restore drill table. |
| 78 | - Recovery time: 8m43s from the offsite copy to a working clone in the 2026-09-29 drill, without host provisioning; the Admin wiki's Restore drill table has each drill. |
| 79 | 79 | |
| 80 | 80 | Restore procedure: extract the archive into an empty directory, point |
| 81 | 81 | =server.root= at it, start =gitbayd=; hooks regenerate and the host key |
.gitbay/wiki/Architecture/09-Controls.org
+1 −1
| @@ -99,6 +99,6 @@ chapter names of OWASP ASVS 4.0 where one fits. |
| 99 | 99 | | Concurrency limit on git pack generation | in place | global, per-principal, bounded queue across SSH, HTTP and git:// (=internal/packlimit=); not in system SSH mode | |
| 100 | 100 | | Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) | |
| 101 | 101 | | Backups offsite and append-only | in place | restic with append-only credentials (documented) | |
| 102 | | | Restore tested | gap | tooling in place (=admin restore-drill=, Admin wiki "Restore drill"); clean-host drill pending (#259) | |
| 102 | | Restore tested | partial | drill 2026-09-29 from the offsite copy (Admin wiki "Restore drill"); secrets not checked, the off-host =secret.key= unproven (#305) | |
| 103 | 103 | | Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) | |
| 104 | 104 | | Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys | |
.gitbay/wiki/Architecture/10-Known-Gaps.org
+2 −2
| @@ -10,7 +10,7 @@ what the 2026-09-27 review found; remove a row when its issue closes. |
| 10 | 10 | |
| 11 | 11 | | Issue | Area | Gap | Severity | |
| 12 | 12 | |-------+------------------+-----------------------------------------------------------------------+----------| |
| 13 | | | #259 | Recovery | No restore has been exercised; the procedure and tooling (=admin restore-drill=, =backup --verify=) are in place, the clean-host drill is pending | high | |
| 13 | | #305 | Recovery | The off-host =secret.key= has not been shown to open a restored database; without it a restore does not start | high | |
| 14 | 14 | |
| 15 | 15 | * Not filed |
| 16 | 16 | |
| @@ -26,6 +26,6 @@ what the 2026-09-27 review found; remove a row when its issue closes. |
| 26 | 26 | |
| 27 | 27 | | Question | Status | |
| 28 | 28 | |-----------------------------------------------------------+------------------------------------------| |
| 29 | | | What is the measured recovery time? | unmeasured (#259) | |
| 29 | | What is the measured recovery time? | 8m43s from the offsite copy to a clone, laptop drill 2026-09-29, no host provisioning (Admin wiki) | |
| 30 | 30 | | How many concurrent clones does the host sustain? | unmeasured (#262) | |
| 31 | 31 | | Have the collaboration features been used by independent users? | no; one human user, tests only | |