diff --git a/Dockerfile b/Dockerfile
index cbecc6b..c2c0005 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,10 +1,9 @@
# Postgres 18 + barman-cloud-*, for continuous WAL archiving and PITR.
#
-# Shared by every MetsaApp database that backs up to object storage: o-result,
-# metsa api, metsa zitadel. It is deliberately generic -- nothing in here knows
-# which database it will hold. The bucket, the server name and the credentials
-# all arrive as the accessory's `cmd:` and environment, so one image serves all
-# three.
+# Shared by every database that backs up to object storage. It is deliberately
+# generic -- nothing in here knows which database it will hold. The bucket, the
+# server name and the credentials all arrive as the accessory's `cmd:` and
+# environment, so one image serves them all.
#
# Why not ghcr.io/cloudnative-pg/postgresql, which already bundles Barman:
# their PG18 image dropped the entrypoint entirely (Entrypoint=[], Cmd=[bash])
diff --git a/LICENSE b/LICENSE
new file mode 100644
index 0000000..6d7e6b9
--- /dev/null
+++ b/LICENSE
@@ -0,0 +1,21 @@
+MIT License
+
+Copyright (c) 2026 metsa.app
+
+Permission is hereby granted, free of charge, to any person obtaining a copy
+of this software and associated documentation files (the "Software"), to deal
+in the Software without restriction, including without limitation the rights
+to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+copies of the Software, and to permit persons to whom the Software is
+furnished to do so, subject to the following conditions:
+
+The above copyright notice and this permission notice shall be included in all
+copies or substantial portions of the Software.
+
+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+SOFTWARE.
diff --git a/README.md b/README.md
index 5a00c12..067c6ca 100644
--- a/README.md
+++ b/README.md
@@ -8,9 +8,9 @@ ghcr.io/metsaapp/postgres-barman:18
ghcr.io/metsaapp/postgres-barman:18-20260712 # immutable
```
-One image, every MetsaApp database. It is deliberately generic: nothing in it
-knows which database it will hold. The bucket, the server name and the credentials
-all arrive as the accessory's `cmd:` and environment.
+One image, every database that backs up to object storage. It is deliberately
+generic: nothing in it knows which database it will hold. The bucket, the server
+name and the credentials all arrive as the accessory's `cmd:` and environment.
```mermaid
flowchart LR
@@ -22,9 +22,7 @@ flowchart LR
PG -->|"barman-cloud-backup
(nightly base backup)"| S3
S3 -->|"barman-cloud-restore
+ wal-restore"| REC["recovered database"]
- C1["o-result"] --> img
- C2["metsa api"] -.not yet.-> img
- C3["metsa zitadel"] -.not yet.-> img
+ C1["your databases"] --> img
style S3 fill:#1f6feb,color:#fff
style img fill:#8957e5,color:#fff
@@ -45,9 +43,9 @@ postgres:
image: ghcr.io/metsaapp/postgres-barman:18
env:
clear:
- POSTGRES_USER: oresult
- POSTGRES_DB: oresult
- AWS_DEFAULT_REGION: fsn1
+ POSTGRES_USER: myapp
+ POSTGRES_DB: myapp
+ AWS_DEFAULT_REGION: us-east-1
secret:
- POSTGRES_PASSWORD
- AWS_ACCESS_KEY_ID # barman-cloud-* reads these straight from the
@@ -61,7 +59,7 @@ postgres:
-c wal_level=replica
-c archive_mode=on
-c archive_timeout=3600
- -c archive_command="barman-cloud-wal-archive -z --cloud-provider aws-s3 --endpoint-url https://fsn1.your-objectstorage.com s3://o-result-backups/api o-result-production %p"
+ -c archive_command="barman-cloud-wal-archive -z --cloud-provider aws-s3 --endpoint-url https://s3.example.com s3://my-backups/myapp myapp-production %p"
-c shared_preload_libraries=pg_stat_statements
options:
user: "0" # the entrypoint chowns PGDATA, then drops to postgres via gosu
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..9b436c4
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,18 @@
+# Security
+
+## Supported versions
+
+The `:18` tag and its immutable `:18-YYYYMMDD` siblings, built from `main`. Older date tags
+are not patched -- rebuild from `main` to pick up a new base.
+
+Most of what you would report here lives upstream: this image is `postgres:18` (pinned by
+digest) plus `barman[cloud,aws]` from PyPI. A vulnerability in Postgres or Barman itself
+belongs to those projects; what we can fix here is the digest we pin and how we build on it.
+
+## Reporting
+
+Report privately via [GitHub Security Advisories](https://github.com/MetsaApp/postgres-barman/security/advisories/new),
+not a public issue.
+
+No SLA -- this is a small project. You will get an acknowledgement and an honest answer about
+whether and when it will be fixed.