backup: archives inherit the database's mode, not the umask default !147

merged merged by cmc on 2026-09-01 05:34 UTC · krz/gitbay:backup-modes into main

1 file changed, +5 −0

Layout: unified · split

deploy/cloud-init.yaml +5
@@ -215,6 +215,8 @@ write_files:
215215 # Nightly consistent backup; keeps the last 7 locally.
216216 # To ship offsite, add an rclone/s3 upload of $out here.
217217 set -eu
218 # The archive carries the database, so it gets the database's mode.
219 umask 027
218220 dir=/var/backups/gitbay
219221 out="$dir/gitbay-$(date -u +%Y%m%d-%H%M%S).tar.gz"
220222 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --out "$out"
@@ -229,8 +231,11 @@ write_files:
229231 content: |
230232 #!/bin/sh
231233 set -eu
234 # The archive is the whole database, so it gets the database's mode.
235 umask 027
232236 dir=/var/backups/gitbay/db
233237 mkdir -p "$dir"
238 chmod 0750 "$dir"
234239 out="$dir/gitbay-db-$(date -u +%Y%m%d-%H%M%S).tar.gz"
235240 /usr/local/bin/gitbayd --config /etc/gitbay/config.toml admin backup --db-only --out "$out"
236241 ls -1t "$dir"/gitbay-db-*.tar.gz | tail -n +49 | xargs -r rm --