The 2026-09-29 restore drill (laptop, offsite restic snapshot ccd646cf) restored and verified every repository, release asset and LFS object, but could not check secrets: no copy of /etc/gitbay/secret.key was on the drill machine. gitbayd refuses to start while any sealed value does not open (7 build secrets, 62 mirror tokens, 1 push device, 1 webhook secret at the snapshot), so without that copy a restore does not come up at all until those rows are cleared by hand, losing them.
- Confirm an off-host copy exists (password manager or the keys repository of runbook D) and that
gitbayd admin secrets checkopens every value of a restored database with it. - Consider a
restore-drill --secret-key <file>that runs the same check, so the drill records it. - Record the result in the Admin wiki Restore drill table.
closed by cmc in commit 5c4e2fad20: wiki: off-host secret.key confirmed
2026-09-29 15:11 UTC