backup: local archives are not encrypted #274

closed cmc opened this on 2026-09-28 04:33 UTC · ops security

Discussion

cmc 2026-09-28 04:33 UTC

gitbayd admin backup writes a plain tar.gz (cmd/gitbayd/backup.go, runBackup). The archive holds the database (including the secrets in the previous issue), every repository, LFS objects and the SSH host key. The restic offsite copy is encrypted; the local archives in /var/backups/gitbay are not.

  • Optional encryption of the archive to a public key (age or similar), so the host can write backups it cannot read.
  • --verify accepts the key to check an encrypted archive.

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

referenced in commit b711b70da5 by cmc: plans: apply decisions on the open questions

2026-09-28 06:16 UTC

closed by cmc in commit 03757af164: deploy, wiki: encrypted archives in the backup scripts and docs

2026-09-28 22:41 UTC

referenced in commit 12a6859743 by cmc: backup: encrypt archives to [backup] age_recipients; --verify --identity

2026-09-28 22:41 UTC

referenced in commit 03e5ee3161 by cmc: config: [backup] age_recipients (filippo.io/age v1.3.2)

2026-09-28 22:41 UTC