Releases: wus-technik/github-backup-docker
Releases · wus-technik/github-backup-docker
Release list
1.2.5
Fixed
- Important: A repository with its Issues feature turned off no longer turns a clean run into a warning. GitHub answers
/repos/<repo>/pullswith404for those repositories, whichgithub-backuplogs asPull requests are disabled for this repository, skipping— a permanent property of the repository, not a backup gap. The string was a soft-failure marker, so an organization owning two such repositories sent a warning card every night for weeks while every backup was in fact complete.Pull requests are disabledis dropped fromSOFT_FAILURE_MARKERS;is unavailable,repository not accessibleandreturned 128stay, since those do mark data that was not backed up.
1.2.4
Added
- Configuration errors now send a notification card through
NOTIFY_WEBHOOK_URLbefore the container exits. The fail-fast checks added in 1.2.3 were diagnosable but silent —notify_teamswas only reachable from a backup run, so a mistypedTOKENwas only found by someone looking at the container. - The smoke test runs a real HTTP receiver and asserts that both a configuration error and a failed run post a card. Now 15 checks.
Changed
- Behaviour change: an unusable configuration exits
78(EX_CONFIG) instead of1, so monitoring can tell "misconfigured" from "crashed" without parsing logs. Exit codes are documented in the README. TIME_ZONEis validated and applied before the other checks, so every notification carries local time.
Fixed
- Important: the webhook call is backgrounded and waited on, like the daily sleep. A POSIX trap only runs once the foreground command returns, so a
SIGTERMarriving mid-notification used to sit out the stop grace and end inSIGKILL. Measured against an unreachable webhook under the default 10s grace: exit137before, exit143within a second after. - An
INT/TERMtrap is installed before anything can block, and the notification attempt is bounded (10s for configuration errors, 60s for run notifications). - The token file is written with
printfrather thanecho. ci/smoke-test.shno longer reports success when a container fails to complete a cycle within the timeout.
Images
ghcr.io/wus-technik/github-backup-docker:1.2.4 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).
1.2.3
Fixed
- Critical:
MAX_BACKUPSwas only rejected when it was the literal0, so00and000passed validation. Both reachhead -n -Nin the pruning step as0, andhead -n -0emits every line rather than none — the complete list of snapshots was handed torm -rfafter every run. - Important:
exec.shfails fast on a missingTOKEN, an invalidMAX_BACKUPSor an unknownTIME_ZONE. With arestartpolicy in place an invalid value now produces a restart loop rather than an idle container. - Important: The daily sleep is backgrounded and waited on, so
INT/TERMfire immediately. A container stop used to hit the grace period and exit 137; it now exits 143 within a second. - Log retention is grouped by run date, so it matches snapshot retention for multi-entity setups.
Changed
COMPRESSIONis off for an empty value and forno,false,off,0(case-insensitive), on for anything else. Previously any non-empty value enabled compression, soCOMPRESSION=nocompressed.COMPRESSION=GZIPis unaffected.- Soft-failure markers are defined once and shared by the warning detection and the notification card; the shared set matches
repository not accessiblewithout the formerSkippingprefix.
Added
- The smoke test grew from 3 to 13 checks: config validation, retention,
COMPRESSIONhandling and SIGTERM behaviour, each confirmed to fail against a deliberately broken image.
Images
ghcr.io/wus-technik/github-backup-docker:1.2.3 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).
1.2.2
Fixed
- Critical: Every backup run since 1.2.0 aborted immediately.
exec.shpassed the token as--token-file=<path>, a flagpython-github-backuphas never had; argparse exited with code 2 before a single repository was cloned. The token file is now passed as afile://URI on the flag the tool actually provides (--tokenfor classic PATs/OAuth tokens,--token-fineforgithub_pat_*tokens, selected from the token prefix).
Added
ci/smoke-test.sh: runs the built image with a dummy token and verifies thatgithub-backuprejects the credential rather than the arguments. Wired intoci.ymlafter the image build and intobuild.ymlas a gate before any image is pushed, so a broken invocation can no longer reach:latestor:stable.
Changed
:stableis now computed from plainX.Y.Zrelease tags only.sort -Vranks a prerelease such as1.3.0-rc1above1.3.0, so a prerelease tag could have claimed:stableand blocked the real release from re-claiming it. Prerelease tags still get their own image tag.- README restyled: centered header with badges, feature and environment-variable tables, and the release/tag semantics. The documented default for
BACKUP_OPTIONSnow matches the code (--all --private --gists).
Images
ghcr.io/wus-technik/github-backup-docker:1.2.2 — also published as :stable (linux/amd64, linux/arm/v7, linux/arm64).