backup: archives inherit the database's mode, not the umask default !147

merged merged by cmc on 2026-09-01 05:34 UTC · krz/gitbay:backup-modes into main

1 file changed, +5 −0

Layout: unified · split

deploy/cloud-init.yaml +5
@@ -215,6 +215,8 @@ write_files:
215 # Nightly consistent backup; keeps the last 7 locally. 215 # Nightly consistent backup; keeps the last 7 locally.
216 # To ship offsite, add an rclone/s3 upload of $out here. 216 # To ship offsite, add an rclone/s3 upload of $out here.
217 set -eu 217 set -eu
218 # The archive carries the database, so it gets the database's mode.
219 umask 027
218 dir=/var/backups/gitbay 220 dir=/var/backups/gitbay
219 out="$dir/gitbay-$(date -u +%Y%m%d-%H%M%S).tar.gz" 221 out="$dir/gitbay-$(date -u +%Y%m%d-%H%M%S).tar.gz"
220 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --out "$out" 222 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --out "$out"
@@ -229,8 +231,11 @@ write_files:
229 content: | 231 content: |
230 #!/bin/sh 232 #!/bin/sh
231 set -eu 233 set -eu
234 # The archive is the whole database, so it gets the database's mode.
235 umask 027
232 dir=/var/backups/gitbay/db 236 dir=/var/backups/gitbay/db
233 mkdir -p "$dir" 237 mkdir -p "$dir"
238 chmod 0750 "$dir"
234 out="$dir/gitbay-db-$(date -u +%Y%m%d-%H%M%S).tar.gz" 239 out="$dir/gitbay-db-$(date -u +%Y%m%d-%H%M%S).tar.gz"
235 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --db-only --out "$out" 240 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --db-only --out "$out"
236 ls -1t "$dir"/gitbay-db-*.tar.gz | tail -n +49 | xargs -r rm -- 241 ls -1t "$dir"/gitbay-db-*.tar.gz | tail -n +49 | xargs -r rm --