Restore has never been exercised.
Backups run hourly (db-only) and nightly (full), with a nightly restic copy offsite. No restore onto a clean host is recorded, and recovery time is unmeasured. --verify (cmd/gitbayd/backup.go:227) checks SQLite integrity and that each repository's HEAD is present, not that its objects are.
The backup snapshots SQLite, then walks the live filesystem with no coordination against repository deletion (internal/control/repo.go:611). A repository deleted between the two is named in the database and absent from the archive.
- Restore drill on a clean host: database integrity,
git fsck --connectivity-onlyper repository, LFS objects, release assets, config, host keys, secrets. Record time to service and the recovered timestamps. --verifyruns a connectivity check on each repository.- Hold repository deletion and rename off while a backup runs, or snapshot the filesystem.
- Record the drill and its numbers on the Admin wiki page; repeat on a schedule.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC