feat(wiki): nightly postgres backup + TOC on the right (#0048/#0050)
Add wikijs-backup, a nightly Borg CronJob (03:30) that dumps the Wiki.js postgres DB to the Storage Box — the content lives in git-storage, but comments, local accounts and the search index do not, so the runtime state gets its own backup. Mirrors authentik-backup (DB-only), reusing synapse-backup-credentials and -known-hosts with a separate repo path; NetworkPolicy lets the backup pod reach wikijs-postgres. Also flip tocPosition to right so the page TOC sits beside the content instead of in the left rail.
This commit is contained in:
@@ -62,6 +62,7 @@ resources:
|
|||||||
- wikijs.yaml
|
- wikijs.yaml
|
||||||
- wiki-ingress.yaml
|
- wiki-ingress.yaml
|
||||||
- wikijs-config.yaml # Konfig-Job (headless Setup + OIDC + Rollen)
|
- wikijs-config.yaml # Konfig-Job (headless Setup + OIDC + Rollen)
|
||||||
|
- wikijs-postgres-backup.yaml # Nächtliches Borg-Backup der Wiki-DB (#0048)
|
||||||
|
|
||||||
# Synapse-Modul als eigene Datei gepflegt (lintbar/testbar), aber als ConfigMap gemounted -
|
# Synapse-Modul als eigene Datei gepflegt (lintbar/testbar), aber als ConfigMap gemounted -
|
||||||
# disableNameSuffixHash, da der Name in synapse-values.yaml's eingebettetem values.yaml
|
# disableNameSuffixHash, da der Name in synapse-values.yaml's eingebettetem values.yaml
|
||||||
|
|||||||
@@ -401,6 +401,10 @@ spec:
|
|||||||
- podSelector:
|
- podSelector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
app.kubernetes.io/name: wikijs
|
app.kubernetes.io/name: wikijs
|
||||||
|
# Nächtliches Backup (wikijs-postgres-backup.yaml) braucht denselben DB-Zugang.
|
||||||
|
- podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: wikijs-backup
|
||||||
ports:
|
ports:
|
||||||
- protocol: TCP
|
- protocol: TCP
|
||||||
port: postgres
|
port: postgres
|
||||||
|
|||||||
@@ -205,7 +205,7 @@ def ensure_theming(jwt: str):
|
|||||||
gql('mutation($t:String!,$i:String!,$d:Boolean!,$tp:String,$c:String,$h:String,$b:String){'
|
gql('mutation($t:String!,$i:String!,$d:Boolean!,$tp:String,$c:String,$h:String,$b:String){'
|
||||||
'theming{setConfig(theme:$t,iconset:$i,darkMode:$d,tocPosition:$tp,injectCSS:$c,injectHead:$h,'
|
'theming{setConfig(theme:$t,iconset:$i,darkMode:$d,tocPosition:$tp,injectCSS:$c,injectHead:$h,'
|
||||||
'injectBody:$b){responseResult{succeeded message}}}}',
|
'injectBody:$b){responseResult{succeeded message}}}}',
|
||||||
jwt, {"t": tc["theme"], "i": tc["iconset"], "d": True, "tp": tc["tocPosition"],
|
jwt, {"t": tc["theme"], "i": tc["iconset"], "d": True, "tp": "right",
|
||||||
"c": ACCENT_CSS, "h": tc["injectHead"], "b": tc["injectBody"]})
|
"c": ACCENT_CSS, "h": tc["injectHead"], "b": tc["injectBody"]})
|
||||||
# Site-Titel (oben links / Browser-Tab) aus der Deployment-Variable — nicht mehr
|
# Site-Titel (oben links / Browser-Tab) aus der Deployment-Variable — nicht mehr
|
||||||
# das hartkodierte "Wiki.js". Reproduzierbar über WIKI_SITE_TITLE.
|
# das hartkodierte "Wiki.js". Reproduzierbar über WIKI_SITE_TITLE.
|
||||||
|
|||||||
@@ -0,0 +1,82 @@
|
|||||||
|
# Nightly Borg backup der Wiki.js-Postgres-DB auf die Hetzner Storage Box (#0048).
|
||||||
|
# Der Inhalt liegt bereits versioniert in git (git-storage -> Gitea -> git.lab); dieses
|
||||||
|
# Backup sichert den Laufzeit-Zustand, den git NICHT hält: Kommentare, lokale Konten,
|
||||||
|
# OIDC-Nutzer und den Suchindex. Muster: apps/authentik/authentik-backup.yaml (DB-only).
|
||||||
|
# Wiederverwendet die synapse-backup-Credentials (SSH-Key + Borg-Passphrase) und das
|
||||||
|
# -known-hosts (gleicher Namespace, gleiche Storage Box), aber einen EIGENEN Borg-Repo-
|
||||||
|
# Pfad (wikijs-backup) und einen versetzten Zeitplan.
|
||||||
|
apiVersion: batch/v1
|
||||||
|
kind: CronJob
|
||||||
|
metadata:
|
||||||
|
name: wikijs-backup
|
||||||
|
namespace: matrix
|
||||||
|
spec:
|
||||||
|
schedule: "30 3 * * *"
|
||||||
|
concurrencyPolicy: Forbid
|
||||||
|
successfulJobsHistoryLimit: 3
|
||||||
|
failedJobsHistoryLimit: 3
|
||||||
|
jobTemplate:
|
||||||
|
spec:
|
||||||
|
backoffLimit: 2
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: wikijs-backup
|
||||||
|
app.kubernetes.io/component: backup
|
||||||
|
spec:
|
||||||
|
restartPolicy: OnFailure
|
||||||
|
containers:
|
||||||
|
- name: backup
|
||||||
|
image: rohana.axion1337.de/sorb/axion-backup:v2
|
||||||
|
env:
|
||||||
|
- name: BORG_REPO
|
||||||
|
value: "ssh://u641795@u641795.your-storagebox.de:23/./wikijs-backup"
|
||||||
|
- name: BORG_PASSPHRASE
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: synapse-backup-credentials
|
||||||
|
key: borg-passphrase
|
||||||
|
- name: SSH_PRIVATE_KEY_FILE
|
||||||
|
value: /secrets/ssh/ssh-private-key
|
||||||
|
- name: SSH_KNOWN_HOSTS_FILE
|
||||||
|
value: /secrets/known-hosts/known_hosts
|
||||||
|
- name: DB_HOSTS
|
||||||
|
value: "wiki:wikijs-postgres"
|
||||||
|
- name: PGUSER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: wikijs-postgres-secret
|
||||||
|
key: username
|
||||||
|
- name: PGPASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: wikijs-postgres-secret
|
||||||
|
key: password
|
||||||
|
volumeMounts:
|
||||||
|
- name: ssh-key
|
||||||
|
mountPath: /secrets/ssh
|
||||||
|
readOnly: true
|
||||||
|
- name: known-hosts
|
||||||
|
mountPath: /secrets/known-hosts
|
||||||
|
readOnly: true
|
||||||
|
- name: scratch
|
||||||
|
mountPath: /scratch
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
memory: 256Mi
|
||||||
|
volumes:
|
||||||
|
- name: ssh-key
|
||||||
|
secret:
|
||||||
|
secretName: synapse-backup-credentials
|
||||||
|
items:
|
||||||
|
- key: ssh-private-key
|
||||||
|
path: ssh-private-key
|
||||||
|
mode: 0400
|
||||||
|
- name: known-hosts
|
||||||
|
configMap:
|
||||||
|
name: synapse-backup-known-hosts
|
||||||
|
- name: scratch
|
||||||
|
emptyDir: {}
|
||||||
Reference in New Issue
Block a user