feat: daily encrypted database backup to a bucket of its own
All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s

A backup service runs pg_dump every day at 03:00 Brasília, checks the archive,
encrypts it with age to a public key and uploads it with a token for that
bucket only. The server cannot read or delete backups: the private key stays
with the owner, the bucket's lifecycle rule expires copies and its lock stops
early deletion. Each run is recorded and shown on the Kanban's Integrations
tab. tests/backup_test.py backs up, restores into a scratch database and
compares the rows in CI. Setup and restore: docs/BACKUP.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-29 18:49:21 -03:00
parent 1b57313496
commit 20403c5132
14 changed files with 565 additions and 2 deletions

View File

@@ -148,6 +148,9 @@ services:
S3_APP_USER: ${S3_APP_USER:-dtf_app}
S3_APP_PASSWORD: ${S3_APP_PASSWORD:-local-app-storage-only}
S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork}
S3_BACKUP_BUCKET: dtf-local-backups
S3_BACKUP_USER: dtf_backup
S3_BACKUP_PASSWORD: local-backup-storage-only
networks: [local]
depends_on:
storage: {condition: service_healthy}
@@ -197,6 +200,28 @@ services:
timeout: 3s
retries: 12
# The daily database backup, against the local backup bucket. Idle until
# BACKUP_AGE_RECIPIENT is set; tests/backup_test.py runs it with a throwaway key.
backup:
build:
context: .
dockerfile: infra/Dockerfile
command: python -m ops.db_backup serve
environment:
DATABASE_ADMIN_URL: postgresql://${POSTGRES_USER:-dtf_local}:${POSTGRES_PASSWORD:-local-database-only}@db:5432/${POSTGRES_DB:-dtf_local}
BACKUP_S3_ENDPOINT: http://storage:9000
BACKUP_BUCKET: dtf-local-backups
BACKUP_ACCESS_KEY_ID: dtf_backup
BACKUP_SECRET_ACCESS_KEY: local-backup-storage-only
BACKUP_REGION: us-east-1
BACKUP_AGE_RECIPIENT: ${BACKUP_AGE_RECIPIENT:-}
networks: [local]
read_only: true
tmpfs: [/tmp]
depends_on:
db-init: {condition: service_completed_successfully}
storage-init: {condition: service_completed_successfully}
site:
build:
context: .