Skip to content

Releases: wus-technik/github-backup-docker

1.2.5

Choose a tag to compare

@cfoellmann cfoellmann released this 11 Sep 15:54

Fixed

  • Important: A repository with its Issues feature turned off no longer turns a clean run into a warning. GitHub answers /repos/<repo>/pulls with 404 for those repositories, which github-backup logs as Pull requests are disabled for this repository, skipping — a permanent property of the repository, not a backup gap. The string was a soft-failure marker, so an organization owning two such repositories sent a warning card every night for weeks while every backup was in fact complete. Pull requests are disabled is dropped from SOFT_FAILURE_MARKERS; is unavailable, repository not accessible and returned 128 stay, since those do mark data that was not backed up.

1.2.4

Choose a tag to compare

@cfoellmann cfoellmann released this 26 Aug 11:25

Added

  • Configuration errors now send a notification card through NOTIFY_WEBHOOK_URL before the container exits. The fail-fast checks added in 1.2.3 were diagnosable but silent — notify_teams was only reachable from a backup run, so a mistyped TOKEN was only found by someone looking at the container.
  • The smoke test runs a real HTTP receiver and asserts that both a configuration error and a failed run post a card. Now 15 checks.

Changed

  • Behaviour change: an unusable configuration exits 78 (EX_CONFIG) instead of 1, so monitoring can tell "misconfigured" from "crashed" without parsing logs. Exit codes are documented in the README.
  • TIME_ZONE is validated and applied before the other checks, so every notification carries local time.

Fixed

  • Important: the webhook call is backgrounded and waited on, like the daily sleep. A POSIX trap only runs once the foreground command returns, so a SIGTERM arriving mid-notification used to sit out the stop grace and end in SIGKILL. Measured against an unreachable webhook under the default 10s grace: exit 137 before, exit 143 within a second after.
  • An INT/TERM trap is installed before anything can block, and the notification attempt is bounded (10s for configuration errors, 60s for run notifications).
  • The token file is written with printf rather than echo.
  • ci/smoke-test.sh no longer reports success when a container fails to complete a cycle within the timeout.

Images

ghcr.io/wus-technik/github-backup-docker:1.2.4 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).

1.2.3

Choose a tag to compare

@cfoellmann cfoellmann released this 26 Aug 08:36

Fixed

  • Critical: MAX_BACKUPS was only rejected when it was the literal 0, so 00 and 000 passed validation. Both reach head -n -N in the pruning step as 0, and head -n -0 emits every line rather than none — the complete list of snapshots was handed to rm -rf after every run.
  • Important: exec.sh fails fast on a missing TOKEN, an invalid MAX_BACKUPS or an unknown TIME_ZONE. With a restart policy in place an invalid value now produces a restart loop rather than an idle container.
  • Important: The daily sleep is backgrounded and waited on, so INT/TERM fire immediately. A container stop used to hit the grace period and exit 137; it now exits 143 within a second.
  • Log retention is grouped by run date, so it matches snapshot retention for multi-entity setups.

Changed

  • COMPRESSION is off for an empty value and for no, false, off, 0 (case-insensitive), on for anything else. Previously any non-empty value enabled compression, so COMPRESSION=no compressed. COMPRESSION=GZIP is unaffected.
  • Soft-failure markers are defined once and shared by the warning detection and the notification card; the shared set matches repository not accessible without the former Skipping prefix.

Added

  • The smoke test grew from 3 to 13 checks: config validation, retention, COMPRESSION handling and SIGTERM behaviour, each confirmed to fail against a deliberately broken image.

Images

ghcr.io/wus-technik/github-backup-docker:1.2.3 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).

1.2.2

Choose a tag to compare

@cfoellmann cfoellmann released this 25 Aug 22:18

Fixed

  • Critical: Every backup run since 1.2.0 aborted immediately. exec.sh passed the token as --token-file=<path>, a flag python-github-backup has never had; argparse exited with code 2 before a single repository was cloned. The token file is now passed as a file:// URI on the flag the tool actually provides (--token for classic PATs/OAuth tokens, --token-fine for github_pat_* tokens, selected from the token prefix).

Added

  • ci/smoke-test.sh: runs the built image with a dummy token and verifies that github-backup rejects the credential rather than the arguments. Wired into ci.yml after the image build and into build.yml as a gate before any image is pushed, so a broken invocation can no longer reach :latest or :stable.

Changed

  • :stable is now computed from plain X.Y.Z release tags only. sort -V ranks a prerelease such as 1.3.0-rc1 above 1.3.0, so a prerelease tag could have claimed :stable and blocked the real release from re-claiming it. Prerelease tags still get their own image tag.
  • README restyled: centered header with badges, feature and environment-variable tables, and the release/tag semantics. The documented default for BACKUP_OPTIONS now matches the code (--all --private --gists).

Images

ghcr.io/wus-technik/github-backup-docker:1.2.2 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).