ADR 0214 / to-be 43. restic keeps one repository per machine and takes a nightly snapshot per module — 14 daily, 8 weekly, 6 monthly — and restores beside the live data, never over it. postgres, mssql and mongodb contribute a consistent dump; minio, influxdb, the vault, mailu, gitea and nextcloud the directories that hold their data.
91 lines
1.6 KiB
JSON
91 lines
1.6 KiB
JSON
{
|
|
"module": "mesh-vault",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "secret",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"provisioned",
|
|
"rotated",
|
|
"deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mesh-vault.provisioned",
|
|
"mesh-vault.rotated",
|
|
"mesh-vault.deprovisioned"
|
|
],
|
|
"receives": {
|
|
"secret": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"secret": "${dir:grants}"
|
|
},
|
|
"keeps": "/var/lib/mesh-vault/root",
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "ledger",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "root",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_VAULT_LEDGER": "${dir:ledger}",
|
|
"MESH_VAULT_ROOT": "${dir:root}"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "mesh-vault",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"contributions": [
|
|
{
|
|
"seat": "node-backup",
|
|
"kind": "backup",
|
|
"content": "path ${dir:state}\npath ${dir:ledger}\npath ${dir:root}\n"
|
|
}
|
|
]
|
|
}
|