Backups: the docs understate losing the secret key, the archive leaves out plugins, and there is no safe restore in a container #234
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#234
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Backup and restore are well built for SQLite. The gaps are in what the archive holds and in how to restore safely. Found in the 2026-09-15 code audit.
1. Losing the secret key loses more than sessions
Backups and your data (lines ~159-160) says losing
POSTULO_SECRET_KEY"will not lose your data, but it will log everyone out". UnlessPOSTULO_FIELD_KEYis set, that key is the material every connection secret (plugins/secrets.py:25) and the Web Push signing key (plugins/browser/webpush.py) are derived from. Configuration (lines ~341-342) already says so; the backup page contradicts it.2. The archive omits what a restore needs
write_backuparchives only the database and media (core/backup.py:220-254). It leaves out:/app/data/plugins: the record plus the installed packages;A restore onto a fresh instance keeps connection rows whose plugins and secrets are gone, and says nothing.
3. There is no safe restore procedure in a container
uv runcommand.execinto a running web container, with gunicorn and the scheduler live whileload_databaseoverwrites the database (backup.py:154-163) orpg_restore --cleanruns (:175-189).:375-386).postulo.sqlite3back but never mentions deleting the stale-waland-shmfiles that WAL mode (#206) leaves beside it.Proposal
restorewarns loudly on a mismatch.docker compose stop postulo scheduler, thendocker compose run --rm -e POSTULO_SKIP_MIGRATE=1 postulo python manage.py restore ….restorerefuses while other database connections or the scheduler are active, unless--force.