refactor(backup): remove duplicate direct-to-S3 stage
A host-to-iDrive S3 stage was added here and is now removed. It would have written the same data into the same `backup-all` bucket that the TrueNAS cloud-sync task already fills -- duplicate storage, two writers to one prefix, for no additional coverage. Offsite to business-owned storage was already solved: the rsync feeds /mnt/glacier/skudakcloud and TrueNAS cloud-syncs that to Skudak's own iDrive e2 account. The earlier note in skudak/cloud.yml proposed adding S3 *and then dropping the rsync* -- replacement, not addition -- and building both was a misreading of it. If offsite is ever moved onto this host it must REPLACE the rsync, not run beside it. Settle first whether the TrueNAS -> iDrive leg is independently verifiable; keeping this chain means trusting it. Also removes the now-orphaned /etc/backup_s3 credential file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -18,6 +18,18 @@
|
||||
mode: 0600
|
||||
setype: ssh_home_t
|
||||
|
||||
# A direct host-to-S3 stage was added here and then removed. Offsite already
|
||||
# happens: the TrueNAS rsync below feeds /mnt/glacier/skudakcloud, and a
|
||||
# TrueNAS cloud-sync task pushes that to Skudak's own iDrive e2 bucket. A
|
||||
# second, direct push would have written the same data into the same bucket
|
||||
# twice. If offsite is ever moved onto this host, it should REPLACE the rsync
|
||||
# rather than run alongside it.
|
||||
- name: remove obsolete backup S3 credentials
|
||||
become: true
|
||||
ansible.builtin.file:
|
||||
path: "/etc/backup_s3/{{ backup_name }}"
|
||||
state: absent
|
||||
|
||||
- name: template {{ backup_name }} backup script
|
||||
become: true
|
||||
ansible.builtin.template:
|
||||
|
||||
@@ -171,5 +171,4 @@ log "syncing db dumps"
|
||||
rsync -az --timeout=600 --delete --mkpath {{ backup_rsync_extra_args | default('') }} \
|
||||
-e "$SSH" "$STAGE/db/" "$DEST:{{ remote_path }}/_backup/db/"
|
||||
{% endif %}
|
||||
|
||||
log "status=ok"
|
||||
|
||||
Reference in New Issue
Block a user