Instance backup and restore: one archive of database and media, and a documented way back #32
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#32
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
What exists is per person:
export_dataandimport_data(core/management/commands/), and the Export everything page. An operator has nothing at instance level except copying the data directory, and with SQLite that is not safe while the application is running unless the copy is a proper backup. By default the database file (data/postulo.sqlite3,base.pyline 92) and the media (data/media,MEDIA_ROOT, line 168) share one directory — one Compose volume — which makes a coherent archive easy, provided something writes it correctly.Shape
manage.py backup <target>writes one archive containing:sqlite3backup API (connection.backup()), which is consistent while the application runs, and PostgreSQL throughpg_dumpwhen it is on the path, refusing with a clear message when it is not;manifest.json: Postulo version, format version, database engine, created-at, row counts per model — enough forrestoreto refuse a mismatch politely.manage.py restore <archive>onto an empty instance only (or--force, which says what it will destroy), checks the manifest against the installed version, restores database then media, then runs migrations so an older backup lands on a newer Postulo.backups/directory under/app/dataand the entrypoint mentions it in the logs on first run, because the first time anyone thinks about backups is after they needed one.Classification
Enhancement. Not breaking: two commands and a page section.
Open questions
backupalso produce the per-person exports inside the archive, so a single person can be restored without the whole instance? Proposal: no;export_dataexists for that and the archive would double in size.