feat: daily encrypted database backup to a bucket of its own
All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s
All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s
A backup service runs pg_dump every day at 03:00 Brasília, checks the archive, encrypts it with age to a public key and uploads it with a token for that bucket only. The server cannot read or delete backups: the private key stays with the owner, the bucket's lifecycle rule expires copies and its lock stops early deletion. Each run is recorded and shown on the Kanban's Integrations tab. tests/backup_test.py backs up, restores into a scratch database and compares the rows in CI. Setup and restore: docs/BACKUP.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -67,6 +67,16 @@ def freight_status():
|
||||
'production_days': freight.production_days}
|
||||
|
||||
|
||||
def backup_status(c):
|
||||
"""The latest database backup and the latest run, which may have failed."""
|
||||
ok = c.execute('''SELECT finished_at,bytes FROM dtf_local.backups WHERE status='ok'
|
||||
ORDER BY finished_at DESC LIMIT 1''').fetchone()
|
||||
last = c.execute('SELECT finished_at,status,detail FROM dtf_local.backups ORDER BY finished_at DESC LIMIT 1').fetchone()
|
||||
return {'last_ok': ok['finished_at'].isoformat() if ok else None, 'bytes': ok['bytes'] if ok else None,
|
||||
'failed': last['detail'] if last and last['status'] == 'failed' else None,
|
||||
'failed_at': last['finished_at'].isoformat() if last and last['status'] == 'failed' else None}
|
||||
|
||||
|
||||
@router.get('/api/operator/board')
|
||||
def board(user=Depends(operator)):
|
||||
with db.connect() as c:
|
||||
@@ -97,9 +107,10 @@ def board(user=Depends(operator)):
|
||||
# Pagamentos tab pages through them until someone records a resolution.
|
||||
issues_total = c.execute('''SELECT count(*) AS n FROM dtf_local.payment_events
|
||||
WHERE (outcome LIKE 'refused%' OR outcome LIKE 'attention%') AND resolved_at IS NULL''').fetchone()['n']
|
||||
backup = backup_status(c)
|
||||
return {'states': STATES, 'transitions': TRANSITIONS, 'back': BACK,
|
||||
'orders': orders, 'payment_issues_total': issues_total, 'tiny': tiny_status(), 'operator': user,
|
||||
'providers': {'payment': payment.name, 'freight': freight_status()}, 'environment': ENVIRONMENT,
|
||||
'providers': {'payment': payment.name, 'freight': freight_status(), 'backup': backup}, 'environment': ENVIRONMENT,
|
||||
'finished_shown': len(finished), 'finished_total': finished_total,
|
||||
'quotes': [quote_view(c, q) for q in pending + approved],
|
||||
'pending_total': pending_total, 'approved_total': approved_total}
|
||||
|
||||
@@ -134,6 +134,14 @@ CREATE TABLE IF NOT EXISTS dtf_local.print_files (
|
||||
UNIQUE(order_id,item_index)
|
||||
);
|
||||
|
||||
-- Each run of the off-server database backup (ops/db_backup.py), which the
|
||||
-- Kanban shows so a backup that stopped working does not go unnoticed.
|
||||
CREATE TABLE IF NOT EXISTS dtf_local.backups (
|
||||
id uuid PRIMARY KEY, started_at timestamptz NOT NULL, finished_at timestamptz NOT NULL,
|
||||
status text NOT NULL CHECK(status IN ('ok','failed')), object_key text, bytes bigint, detail text
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS backups_finished ON dtf_local.backups(finished_at DESC);
|
||||
|
||||
CREATE INDEX IF NOT EXISTS uploads_owner ON dtf_local.uploads(owner);
|
||||
|
||||
-- Indexes follow the queries the application actually issues. Only these; every
|
||||
|
||||
Reference in New Issue
Block a user