backup: encrypt archives to age recipients !498

merged merged by cmc on 2026-09-28 22:41 UTC · krz/gitbay:backup-age into main

Discussion

cmc

Backup archives are encrypted to age recipients.

  • [backup] age_recipients = ["age1…"] (X25519, filippo.io/age v1.3.2), validated at config load. The identity stays off the server.
  • With recipients set, gitbayd admin backup streams tar → gzip → age into a dot-prefixed temp file beside the archive, syncs, renames to <name>.tar.gz.age and syncs the directory. An --out ending in .age is refused without recipients. Archives are 0600.
  • The database snapshot is taken into a 0700 .gitbay-snap-* directory beside the archive and removed afterwards (it was a predictable name in /tmp).
  • admin backup --verify <archive> --identity <file> detects encryption from the header, reads the archive to the end (a truncated archive fails, plain or encrypted), and says so when --identity is given for an unencrypted archive.
  • Backup and monitor scripts in deploy/cloud-init.yaml count and prune .tar.gz.age. bay1's installed copies of those scripts predate this and need the same glob edits by hand.
  • Admin and Architecture pages; #274 leaves Known-Gaps; CHANGELOG.

Stacked on !495 (secrets-at-rest).

Closes #274