Commit 86a293b4bf
Verified · cmc
Layout: unified · split
Admin.org +23
| @@ -186,6 +186,29 @@ Restore: extract into an empty directory, point =server.root= at it, | |||
| 186 | start gitbayd. Host keys are preserved, so clients keep their | 186 | start gitbayd. Host keys are preserved, so clients keep their |
| 187 | known_hosts entries; hooks regenerate at startup. | 187 | known_hosts entries; hooks regenerate at startup. |
| 188 | 188 | ||
| 189 | ** Schedule and recovery point | ||
| 190 | |||
| 191 | Two timers, because the two halves of the data have different exposure. | ||
| 192 | |||
| 193 | - =gitbay-backup.timer=, nightly. The full archive above, last 7 kept. | ||
| 194 | - =gitbay-db-backup.timer=, hourly. =admin backup --db-only=, which | ||
| 195 | writes the SQLite snapshot alone, last 48 kept. A few MB against the | ||
| 196 | full archive's hundreds, which is what makes the frequency affordable. | ||
| 197 | |||
| 198 | The split follows what a loss would actually cost. Repositories are git, | ||
| 199 | so a mirror or any clone is a second copy; the database is the only copy | ||
| 200 | of issues, merge requests, comments and review state. So the recovery | ||
| 201 | point is about an hour for the data that exists nowhere else, and a day | ||
| 202 | for the data that does. | ||
| 203 | |||
| 204 | Continuous replication (litestream and similar) was considered and not | ||
| 205 | adopted. It would take the database's recovery point to seconds, but the | ||
| 206 | repositories would still be on the nightly archive, so a restore could | ||
| 207 | produce a database referencing commits the repository backup does not | ||
| 208 | have. Consistency between the two halves is worth more here than latency | ||
| 209 | on one of them. Revisit if repository replication becomes continuous | ||
| 210 | too. | ||
| 211 | |||
| 189 | * Upgrades | 212 | * Upgrades |
| 190 | 213 | ||
| 191 | Replace the binary, restart the unit. Migrations apply automatically and | 214 | Replace the binary, restart the unit. Migrations apply automatically and |