backup: hold moves off, refs before objects, directory entries, verify connectivity !504

merged merged by cmc on 2026-09-28 23:09 UTC · krz/gitbay:backup-verify-lock into main

Discussion

cmc

A full backup restores: it holds repository moves off, captures refs before objects, carries directories, and --verify checks git connectivity.

  • A full backup holds <root>/backup.lock from its database snapshot to its last repository; repository delete, rename, transfer, admin repo delete, org rename, admin gc and MR prune refuse with "a backup is running" meanwhile (exit 1), and a backup waits for one already running.
  • Inside each repository the walk archives HEAD, refs/ and packed-refs before objects/, so a push during the walk cannot leave an archived ref without its objects. A pack removed under objects/ mid-walk (git's own auto gc) is skipped; --verify reports any repository that is then incomplete.
  • Archives carry a directory entry for every directory, so a bare repository whose refs are all packed restores. An older archive lacks them; the upgrade note says how to recover.
  • --verify runs git fsck --connectivity-only --git-dir= on each archived repository and names any that fail; it ignores alternates and commondir members, so an archive cannot make git read another repository on the host.
  • admin backup opens the database without the key file or migrations; stale .gitbay-snap-* and .<name>.tmp-<digits> older than a day are removed at start; --out inside server.root is refused.
  • admin secrets init and rotate hold an exclusive lock on <key>.lock, so two runs cannot drop each other's key (#273).
  • Admin: restore puts the key file back before starting gitbayd; the offsite job does not carry the key yet; the restore drill procedure (not yet run). Threat-Model, Architecture 06/08; CHANGELOG with upgrade notes; cloud-init header.

Stacked on !503 (wiki-raw-links).

Ref #259