Commit 415c793921

415c79392148f279fd58313935e668f12a5fd5be

parent: 1346335ed2

Verified · cmc ci/build: success ci/test: skipped

cmc <hello@cleberg.net> · 2026-09-29 05:15 UTC

wiki: first restore drill recorded

Closes #259

Layout: unified · split

.gitbay/wiki/Admin.org +7 −3
@@ -728,12 +728,16 @@ the time of the newest restic snapshot restored; record beside it the
728newest issue, comment and push =restore-drill= printed, which show how 728newest issue, comment and push =restore-drill= printed, which show how
729much activity the restore carries. 729much activity the restore carries.
730 730
731No drill has been run yet; the procedure above is written but 731The first drill ran on the operator's laptop rather than a provisioned
732unexercised, and #259 stays open until the first row below is 732host, so its time to service has no provisioning in it, and it could
733recorded. 733not check secrets: no copy of =secret.key= was on the machine, and
734gitbayd refuses to start while any sealed value does not open. The
735sealed values were cleared in the drill copy to reach service; #305
736tracks proving the off-host key.
734 737
735| Date | Host | Snapshot restored (UTC) | Newest issue / comment / push | Time to service | DB integrity | Connectivity | LFS | Release assets | Host key | Secrets | Notes | 738| Date | Host | Snapshot restored (UTC) | Newest issue / comment / push | Time to service | DB integrity | Connectivity | LFS | Release assets | Host key | Secrets | Notes |
736|------+------+-------------------------+-------------------------------+-----------------+--------------+--------------+-----+----------------+----------+---------+-------| 739|------+------+-------------------------+-------------------------------+-----------------+--------------+--------------+-----+----------------+----------+---------+-------|
740| 2026-09-29 | laptop (macOS), restic from offsite | 2026-09-29 00:19:15 (ccd646cf) | 00:05:17 / 00:09:44 / 00:15:31 | 8m43s (restore 1m49s, checks 33s) | ok | ok, 69/69 | ok, 2 | ok, 529 | matches | not checked (#305) | 4.99 GiB restored; 71 sealed values cleared in the drill copy to start |
737 741
738* Upgrades 742* Upgrades
739 743
.gitbay/wiki/Architecture/08-Operations.org +1 −1
@@ -75,7 +75,7 @@ the product activity feed, not an audit trail.
75 cannot destroy its own history (documented: Admin wiki). 75 cannot destroy its own history (documented: Admin wiki).
76- Recovery point: about one hour for database-only data (issues, merge 76- Recovery point: about one hour for database-only data (issues, merge
77 requests, reviews), one day for repositories. 77 requests, reviews), one day for repositories.
78- Recovery time: see the Admin wiki's Restore drill table. 78- Recovery time: 8m43s from the offsite copy to a working clone in the 2026-09-29 drill, without host provisioning; the Admin wiki's Restore drill table has each drill.
79 79
80Restore procedure: extract the archive into an empty directory, point 80Restore procedure: extract the archive into an empty directory, point
81=server.root= at it, start =gitbayd=; hooks regenerate and the host key 81=server.root= at it, start =gitbayd=; hooks regenerate and the host key
.gitbay/wiki/Architecture/09-Controls.org +1 −1
@@ -99,6 +99,6 @@ chapter names of OWASP ASVS 4.0 where one fits.
99| Concurrency limit on git pack generation | in place | global, per-principal, bounded queue across SSH, HTTP and git:// (=internal/packlimit=); not in system SSH mode | 99| Concurrency limit on git pack generation | in place | global, per-principal, bounded queue across SSH, HTTP and git:// (=internal/packlimit=); not in system SSH mode |
100| Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) | 100| Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) |
101| Backups offsite and append-only | in place | restic with append-only credentials (documented) | 101| Backups offsite and append-only | in place | restic with append-only credentials (documented) |
102| Restore tested | gap | tooling in place (=admin restore-drill=, Admin wiki "Restore drill"); clean-host drill pending (#259) | 102| Restore tested | partial | drill 2026-09-29 from the offsite copy (Admin wiki "Restore drill"); secrets not checked, the off-host =secret.key= unproven (#305) |
103| Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) | 103| Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) |
104| Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys | 104| Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys |
.gitbay/wiki/Architecture/10-Known-Gaps.org +2 −2
@@ -10,7 +10,7 @@ what the 2026-09-27 review found; remove a row when its issue closes.
10 10
11| Issue | Area | Gap | Severity | 11| Issue | Area | Gap | Severity |
12|-------+------------------+-----------------------------------------------------------------------+----------| 12|-------+------------------+-----------------------------------------------------------------------+----------|
13| #259 | Recovery | No restore has been exercised; the procedure and tooling (=admin restore-drill=, =backup --verify=) are in place, the clean-host drill is pending | high | 13| #305 | Recovery | The off-host =secret.key= has not been shown to open a restored database; without it a restore does not start | high |
14 14
15* Not filed 15* Not filed
16 16
@@ -26,6 +26,6 @@ what the 2026-09-27 review found; remove a row when its issue closes.
26 26
27| Question | Status | 27| Question | Status |
28|-----------------------------------------------------------+------------------------------------------| 28|-----------------------------------------------------------+------------------------------------------|
29| What is the measured recovery time? | unmeasured (#259) | 29| What is the measured recovery time? | 8m43s from the offsite copy to a clone, laptop drill 2026-09-29, no host provisioning (Admin wiki) |
30| How many concurrent clones does the host sustain? | unmeasured (#262) | 30| How many concurrent clones does the host sustain? | unmeasured (#262) |
31| Have the collaboration features been used by independent users? | no; one human user, tests only | 31| Have the collaboration features been used by independent users? | no; one human user, tests only |