Commit

Self-hosted: backups go to a g1t-backups bucket on the compose file's MinIO

syntaqxcommitted Parent0ba5d11Browse files
2 files+21−40/2 viewed
+15−2
1010 // which keeps repositories in the git store (gitstore/server.mjs);
1111 // - EMAIL (Email Sending) becomes a service binding to workers/mail;
1212 // - the packages service keeps files in S3-compatible storage (MinIO)
13−// instead of R2;
13+// instead of R2, and the repos service its nightly backups (a bucket of
14+// their own, BACKUP_S3_BUCKET);
1415 // - services that are off in this phase (agents, the context hub, the
1516 // g1t.page dispatcher, model proxy) are bound to workers/off instead, and
1617 // events stop queueing work for them;
1920 // Usage: node configs.mjs [outDir]
2021 // Environment: PUBLIC_URL, GITSTORE_URL, GITSTORE_SECRET, MAIL_URL,
2122 // ACTIONS_KEY, INTEGRATIONS_KEY, WEBHOOKS_KEY, IDENTITY_KEY,
22−// PACKAGES_TOKEN_SECRET, S3_ENDPOINT, S3_BUCKET, S3_REGION,
23+// PACKAGES_TOKEN_SECRET, S3_ENDPOINT, S3_BUCKET, BACKUP_S3_BUCKET, S3_REGION,
2324 // S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, S3_PUBLIC_ENDPOINT, and optionally
2425 // your own GitHub App: GITHUB_APP_ID, GITHUB_APP_SLUG, GITHUB_APP_CLIENT_ID,
2526 // GITHUB_APP_CLIENT_SECRET, GITHUB_APP_PRIVATE_KEY, GITHUB_APP_WEBHOOK_SECRET.
216217 delete config.vars.R2_ACCOUNT_ID;
217218 delete config.vars.R2_BUCKET;
218219 }
220+ // Nightly backups' bundles go to a bucket of their own on the same
221+ // S3-compatible store, instead of the BACKUPS R2 bucket.
222+ if (hosted.name === "g1t-repos") {
223+ Object.assign(config.vars, {
224+ BACKUP_STORE: "s3",
225+ BACKUP_S3_BUCKET: process.env.BACKUP_S3_BUCKET ?? "g1t-backups",
226+ S3_ENDPOINT: process.env.S3_ENDPOINT ?? "http://minio:9000",
227+ S3_REGION: process.env.S3_REGION ?? "us-east-1",
228+ S3_ACCESS_KEY_ID: process.env.S3_ACCESS_KEY_ID ?? "",
229+ S3_SECRET_ACCESS_KEY: process.env.S3_SECRET_ACCESS_KEY ?? "",
230+ });
231+ }
219232 // Nothing to deploy to: deployments are off (no Cloudflare API token).
220233 if (hosted.name === "g1t-deployments") delete config.vars.CUSTOM_HOSTNAMES_ZONE_ID;
221234
+6−2
5151 S3_ACCESS_KEY_ID: ${S3_ACCESS_KEY_ID:-g1t}
5252 S3_SECRET_ACCESS_KEY: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
5353 S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-}
54+ # Nightly backups' bundles and manifests, in a bucket of their own on
55+ # the same store (docs/SELF_HOSTING.md, "Backups").
56+ BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
5457 volumes:
5558 - g1t-data:/data
5659 - g1t-secrets:/secrets:ro
111114 retries: 20
112115 restart: unless-stopped
113116
114− # Makes the bucket once, then exits.
117+ # Makes the buckets once, then exits: packages' files, and backups.
115118 minio-setup:
116119 image: minio/mc:latest
117120 depends_on:
120123 entrypoint:
121124 - sh
122125 - -c
123− - mc alias set local http://minio:9000 "$$MINIO_ROOT_USER" "$$MINIO_ROOT_PASSWORD" && mc mb --ignore-existing "local/$$S3_BUCKET"
126+ - mc alias set local http://minio:9000 "$$MINIO_ROOT_USER" "$$MINIO_ROOT_PASSWORD" && mc mb --ignore-existing "local/$$S3_BUCKET" && mc mb --ignore-existing "local/$$BACKUP_S3_BUCKET"
124127 environment:
125128 MINIO_ROOT_USER: ${S3_ACCESS_KEY_ID:-g1t}
126129 MINIO_ROOT_PASSWORD: ${S3_SECRET_ACCESS_KEY:-g1t-packages-secret}
127130 S3_BUCKET: ${S3_BUCKET:-g1t-packages}
131+ BACKUP_S3_BUCKET: ${BACKUP_S3_BUCKET:-g1t-backups}
128132
129133 mailpit:
130134 image: axllent/mailpit:latest