SMB (smbclient) and FTP/FTPS (curl with netrc) targets with encrypted credentials and connection test; strategies with cron schedule, retention, optional openssl AES-256 encryption; sources: PVC hostpath tar, pg_dumpall in the Postgres pod, namespace manifests, host directory. Backup job collects, encrypts, uploads, verifies size, records sha256 and applies retention on the target; scheduler starts due strategies. Backups page with target/strategy forms, run now and history. Restore guide in docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1.5 KiB
1.5 KiB
Restoring backups
Backups are plain archives on the SMB share or FTP server, named
<strategy-slug>_<YYYYmmdd-HHMMSS>.<ext>[.enc]. The SHA-256 of every uploaded file is shown
in the backup history of the strategy.
1. Decrypt (only for .enc files)
openssl enc -d -aes-256-cbc -pbkdf2 -in FILE.sql.gz.enc -out FILE.sql.gz
Enter the passphrase of the strategy when prompted.
2. Restore per source type
PostgreSQL dump (.sql.gz, produced by pg_dumpall inside the pod)
gunzip -c gitea-db_*.sql.gz | microk8s kubectl exec -i -n gitea gitea-postgresql-0 -- \
sh -c 'PGPASSWORD="$POSTGRES_PASSWORD" psql -U postgres'
Stop Gitea first (microk8s kubectl scale deploy/gitea -n gitea --replicas=0) and start it again afterwards.
Persistent volume (.tar.gz of the hostpath directory)
Find the directory of the PVC on the host and unpack into it:
PV=$(microk8s kubectl get pvc -n gitea gitea-shared-storage -o jsonpath='{.spec.volumeName}')
DIR=$(microk8s kubectl get pv "$PV" -o jsonpath='{.spec.hostPath.path}')
microk8s kubectl scale deploy/gitea -n gitea --replicas=0
tar -xzf gitea-data_*.tar.gz -C "$DIR"
microk8s kubectl scale deploy/gitea -n gitea --replicas=1
Kubernetes manifests (.yaml.gz)
gunzip -c gitea-manifests_*.yaml.gz | microk8s kubectl apply -f -
Secrets and PVC definitions are included; review before applying to a different cluster.
Host directory (.tar.gz)
tar -xzf name_*.tar.gz -C /path/of/the/source