All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s
A backup service runs pg_dump every day at 03:00 Brasília, checks the archive, encrypts it with age to a public key and uploads it with a token for that bucket only. The server cannot read or delete backups: the private key stays with the owner, the bucket's lifecycle rule expires copies and its lock stops early deletion. Each run is recorded and shown on the Kanban's Integrations tab. tests/backup_test.py backs up, restores into a scratch database and compares the rows in CI. Setup and restore: docs/BACKUP.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
21 lines
1010 B
Docker
21 lines
1010 B
Docker
# Same pinned base as deploy/Dockerfile.api, so the integration suite exercises
|
|
# the image that ships rather than a different one.
|
|
FROM python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9
|
|
# pg_dump and age are for the database backup (ops/db_backup.py). Debian 13
|
|
# ships PostgreSQL 17, the server's major version, which pg_dump must match.
|
|
RUN apt-get update \
|
|
&& apt-get upgrade -y \
|
|
&& apt-get install -y --no-install-recommends postgresql-client-17 age \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
WORKDIR /app
|
|
COPY infra/requirements.txt infra/requirements.lock /app/infra/
|
|
RUN pip install --no-cache-dir --require-hashes -r infra/requirements.lock
|
|
COPY app /app/app
|
|
COPY ops /app/ops
|
|
# The local image carries the suites so they can run inside the stack network.
|
|
# deploy/Dockerfile.api deliberately does not: tests are not part of what ships.
|
|
COPY tests /app/tests
|
|
RUN useradd --uid 10001 --create-home dtf
|
|
USER dtf
|
|
ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1
|