The dump assumed the official image's environment and the postgres superuser. Bitnami keeps its passwords in files, and on this cluster the superuser password no longer matches the database, so the Gitea database backup would have failed. The collector now resolves the credentials from either layout, probes them before dumping so a failed login cannot truncate the archive, and falls back to a single-database dump when only the application user works. Verified against both databases on the server. Also adds the Nextcloud manifest that installs it on the cluster. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
69 lines
2.2 KiB
Markdown
69 lines
2.2 KiB
Markdown
# Restoring backups
|
|
|
|
Backups are plain archives on the SMB share or FTP server, named
|
|
`<strategy-slug>_<YYYYmmdd-HHMMSS>.<ext>[.enc]`. The SHA-256 of every uploaded file is shown
|
|
in the backup history of the strategy.
|
|
|
|
## 1. Decrypt (only for `.enc` files)
|
|
|
|
```bash
|
|
openssl enc -d -aes-256-cbc -pbkdf2 -in FILE.sql.gz.enc -out FILE.sql.gz
|
|
```
|
|
|
|
Enter the passphrase of the strategy when prompted.
|
|
|
|
## 2. Restore per source type
|
|
|
|
### PostgreSQL dump (`.sql.gz`)
|
|
|
|
The archive is one of two shapes, depending on which credentials the pod exposes. The first
|
|
line says which one:
|
|
|
|
- `-- PostgreSQL database cluster dump` — every database and all roles, taken with the
|
|
superuser. Restore it into the cluster.
|
|
- `-- PostgreSQL database dump` — a single database, taken with the application user because
|
|
the superuser password of the pod did not work. Restore it into that database.
|
|
|
|
Stop the application first, for example
|
|
`microk8s kubectl scale deploy/gitea -n gitea --replicas=0`, and start it again afterwards.
|
|
|
|
Cluster dump:
|
|
|
|
```bash
|
|
gunzip -c nextcloud-db_*.sql.gz | microk8s kubectl exec -i -n nextcloud nextcloud-postgresql-0 -- \
|
|
sh -c 'PGPASSWORD="$POSTGRES_PASSWORD" psql -U "$POSTGRES_USER" -d postgres'
|
|
```
|
|
|
|
Single database:
|
|
|
|
```bash
|
|
gunzip -c gitea-db_*.sql.gz | microk8s kubectl exec -i -n gitea gitea-postgresql-0 -- \
|
|
sh -c 'PGPASSWORD=$(cat "$POSTGRES_PASSWORD_FILE") psql -U "$POSTGRES_USER" -d "$POSTGRES_DATABASE"'
|
|
```
|
|
|
|
### Persistent volume (`.tar.gz` of the hostpath directory)
|
|
|
|
Find the directory of the PVC on the host and unpack into it:
|
|
|
|
```bash
|
|
PV=$(microk8s kubectl get pvc -n gitea gitea-shared-storage -o jsonpath='{.spec.volumeName}')
|
|
DIR=$(microk8s kubectl get pv "$PV" -o jsonpath='{.spec.hostPath.path}')
|
|
microk8s kubectl scale deploy/gitea -n gitea --replicas=0
|
|
tar -xzf gitea-data_*.tar.gz -C "$DIR"
|
|
microk8s kubectl scale deploy/gitea -n gitea --replicas=1
|
|
```
|
|
|
|
### Kubernetes manifests (`.yaml.gz`)
|
|
|
|
```bash
|
|
gunzip -c gitea-manifests_*.yaml.gz | microk8s kubectl apply -f -
|
|
```
|
|
|
|
Secrets and PVC definitions are included; review before applying to a different cluster.
|
|
|
|
### Host directory (`.tar.gz`)
|
|
|
|
```bash
|
|
tar -xzf name_*.tar.gz -C /path/of/the/source
|
|
```
|