Commit 86a293b4bf

86a293b4bfa84821f12d125778226680498883e8

parent: 8ae7a036fb

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-01 04:45 UTC

Admin: backup schedule and the recovery-point decision

Two timers now: the nightly full archive, and an hourly database-only
snapshot. Records why continuous replication was not adopted — it would
leave the repositories on the nightly archive, so a restore could produce
a database referencing commits the repository backup lacks.

Ref #28

Layout: unified · split

Admin.org +23
@@ -186,6 +186,29 @@ Restore: extract into an empty directory, point =server.root= at it,
186186start gitbayd. Host keys are preserved, so clients keep their
187187known_hosts entries; hooks regenerate at startup.
188188
189** Schedule and recovery point
190
191Two timers, because the two halves of the data have different exposure.
192
193- =gitbay-backup.timer=, nightly. The full archive above, last 7 kept.
194- =gitbay-db-backup.timer=, hourly. =admin backup --db-only=, which
195 writes the SQLite snapshot alone, last 48 kept. A few MB against the
196 full archive's hundreds, which is what makes the frequency affordable.
197
198The split follows what a loss would actually cost. Repositories are git,
199so a mirror or any clone is a second copy; the database is the only copy
200of issues, merge requests, comments and review state. So the recovery
201point is about an hour for the data that exists nowhere else, and a day
202for the data that does.
203
204Continuous replication (litestream and similar) was considered and not
205adopted. It would take the database's recovery point to seconds, but the
206repositories would still be on the nightly archive, so a restore could
207produce a database referencing commits the repository backup does not
208have. Consistency between the two halves is worth more here than latency
209on one of them. Revisit if repository replication becomes continuous
210too.
211
189212* Upgrades
190213
191214Replace the binary, restart the unit. Migrations apply automatically and