# Restoring backups Backups are plain archives on the SMB share or FTP server, named `_.[.enc]`. The SHA-256 of every uploaded file is shown in the backup history of the strategy. ## 1. Decrypt (only for `.enc` files) ```bash openssl enc -d -aes-256-cbc -pbkdf2 -in FILE.sql.gz.enc -out FILE.sql.gz ``` Enter the passphrase of the strategy when prompted. ## 2. Restore per source type ### PostgreSQL dump (`.sql.gz`, produced by `pg_dumpall` inside the pod) ```bash gunzip -c gitea-db_*.sql.gz | microk8s kubectl exec -i -n gitea gitea-postgresql-0 -- \ sh -c 'PGPASSWORD="$POSTGRES_PASSWORD" psql -U postgres' ``` Stop Gitea first (`microk8s kubectl scale deploy/gitea -n gitea --replicas=0`) and start it again afterwards. ### Persistent volume (`.tar.gz` of the hostpath directory) Find the directory of the PVC on the host and unpack into it: ```bash PV=$(microk8s kubectl get pvc -n gitea gitea-shared-storage -o jsonpath='{.spec.volumeName}') DIR=$(microk8s kubectl get pv "$PV" -o jsonpath='{.spec.hostPath.path}') microk8s kubectl scale deploy/gitea -n gitea --replicas=0 tar -xzf gitea-data_*.tar.gz -C "$DIR" microk8s kubectl scale deploy/gitea -n gitea --replicas=1 ``` ### Kubernetes manifests (`.yaml.gz`) ```bash gunzip -c gitea-manifests_*.yaml.gz | microk8s kubectl apply -f - ``` Secrets and PVC definitions are included; review before applying to a different cluster. ### Host directory (`.tar.gz`) ```bash tar -xzf name_*.tar.gz -C /path/of/the/source ```