A full backup restores: it holds repository moves off, captures refs before objects, carries directories, and --verify checks git connectivity.
- A full backup holds
<root>/backup.lockfrom its database snapshot to its last repository; repository delete, rename, transfer,admin repo delete, org rename,admin gcand MR prune refuse with "a backup is running" meanwhile (exit 1), and a backup waits for one already running. - Inside each repository the walk archives HEAD,
refs/andpacked-refsbeforeobjects/, so a push during the walk cannot leave an archived ref without its objects. A pack removed underobjects/mid-walk (git's own auto gc) is skipped;--verifyreports any repository that is then incomplete. - Archives carry a directory entry for every directory, so a bare repository whose refs are all packed restores. An older archive lacks them; the upgrade note says how to recover.
--verifyrunsgit fsck --connectivity-only --git-dir=on each archived repository and names any that fail; it ignoresalternatesandcommondirmembers, so an archive cannot make git read another repository on the host.admin backupopens the database without the key file or migrations; stale.gitbay-snap-*and.<name>.tmp-<digits>older than a day are removed at start;--outinsideserver.rootis refused.admin secrets initandrotatehold an exclusive lock on<key>.lock, so two runs cannot drop each other's key (#273).- Admin: restore puts the key file back before starting gitbayd; the offsite job does not carry the key yet; the restore drill procedure (not yet run). Threat-Model, Architecture 06/08; CHANGELOG with upgrade notes; cloud-init header.
Stacked on !503 (wiki-raw-links).
Ref #259