Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
## Summary

- What changed:
- Why it changed:

## Backup Risk Review

- [ ] No backup creation, retention, restore, encryption, or storage behavior changed.
- [ ] If backup behavior changed, restore impact is explained below.
- [ ] If retention behavior changed, deletion risk is explained below.
- [ ] If encryption behavior changed, key handling and recovery impact are explained below.
- [ ] If storage provider behavior changed, bucket/path/credential impact is explained below.

## Operational Evidence

- [ ] `pnpm verify` passed locally.
- [ ] New or changed harness rules have clear failure messages.
- [ ] No production secrets or real credentials are included.
- [ ] Docs or exec plans were updated when behavior changed.

## Restore And Rollback Notes

Describe how to verify restore safety, roll back the change, or recover from a failed run:

-

## Deployment Notes

Mention required env/config changes, schedule changes, or migration steps:

-
43 changes: 43 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
name: CI

on:
pull_request:
push:
branches:
- master
- main

permissions:
contents: read

jobs:
verify:
name: Verify
runs-on: ubuntu-latest
timeout-minutes: 10

steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
run_install: false

- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm

- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Validate latest commit message
run: pnpm harness:commit

Comment on lines +20 to +41
- name: Run verification
run: pnpm verify
42 changes: 41 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,46 @@ Reusable multi-project backup runner for database dumps, encrypted external stor

Draft planning stage.

Start with the engineering proposal:
## Quickstart

Install dependencies and run the quality gate:

```bash
pnpm install
pnpm verify
```

The CLI currently exposes a minimal baseline command while the product implementation is still behind the harness:

```bash
pnpm build
node dist/cli.js --version
```

## Commit Format

Use scoped Conventional Commits:

```text
type(scope): message
```

Example:

```text
chore(harness): add strict verification gate
```

Validate the latest commit locally:

```bash
pnpm harness:commit
```

## Docs

Start with the engineering proposal and implementation plan:

- [Reusable Multi-Project Backup Runner Proposal](docs/reusable-backup-runner-proposal.md)
- [Implementation Plan](docs/implementation-plan.md)
- [Harness Engineering Proposal](docs/harness-engineering-proposal.md)
42 changes: 42 additions & 0 deletions config/targets.example.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
version: 1

defaults:
encryption:
type: age
recipientEnv: BACKUP_AGE_RECIPIENT
retention:
keepDaily: 7
keepWeekly: 4
keepMonthly: 3
notifications:
telegram:
enabled: true
onFailure: true
onSuccess: false
successCadence: weekly
botTokenEnv: BACKUP_TELEGRAM_BOT_TOKEN
chatIdEnv: BACKUP_TELEGRAM_CHAT_ID

targets:
- id: maintana
enabled: false
description: Maintana production PostgreSQL database in Docker.
dumper:
type: postgresDocker
container: maintana-postgres
database: maintana
username: maintana
passwordEnv: MAINTANA_POSTGRES_PASSWORD
format: custom
storage:
type: s3
endpoint: https://example-account-id.r2.cloudflarestorage.com
region: auto
bucket: maintana-backups
prefix: production/postgres
accessKeyIdEnv: MAINTANA_BACKUP_R2_ACCESS_KEY_ID
secretAccessKeyEnv: MAINTANA_BACKUP_R2_SECRET_ACCESS_KEY
retention:
keepDaily: 14
keepWeekly: 8
keepMonthly: 6
Loading
Loading