gitbayd admin backup writes a plain tar.gz (cmd/gitbayd/backup.go, runBackup). The archive holds the database (including the secrets in the previous issue), every repository, LFS objects and the SSH host key. The restic offsite copy is encrypted; the local archives in /var/backups/gitbay are not.
- Optional encryption of the archive to a public key (age or similar), so the host can write backups it cannot read.
--verifyaccepts the key to check an encrypted archive.
referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews
2026-09-28 05:43 UTC