Backup archives are encrypted to age recipients.
[backup] age_recipients = ["age1…"](X25519, filippo.io/age v1.3.2), validated at config load. The identity stays off the server.- With recipients set,
gitbayd admin backupstreams tar → gzip → age into a dot-prefixed temp file beside the archive, syncs, renames to<name>.tar.gz.ageand syncs the directory. An--outending in.ageis refused without recipients. Archives are 0600. - The database snapshot is taken into a 0700
.gitbay-snap-*directory beside the archive and removed afterwards (it was a predictable name in/tmp). admin backup --verify <archive> --identity <file>detects encryption from the header, reads the archive to the end (a truncated archive fails, plain or encrypted), and says so when--identityis given for an unencrypted archive.- Backup and monitor scripts in
deploy/cloud-init.yamlcount and prune.tar.gz.age. bay1's installed copies of those scripts predate this and need the same glob edits by hand. - Admin and Architecture pages; #274 leaves Known-Gaps; CHANGELOG.
Stacked on !495 (secrets-at-rest).
Closes #274