Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 4 additions & 5 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,10 +1,9 @@
# Postgres 18 + barman-cloud-*, for continuous WAL archiving and PITR.
#
# Shared by every MetsaApp database that backs up to object storage: o-result,
# metsa api, metsa zitadel. It is deliberately generic -- nothing in here knows
# which database it will hold. The bucket, the server name and the credentials
# all arrive as the accessory's `cmd:` and environment, so one image serves all
# three.
# Shared by every database that backs up to object storage. It is deliberately
# generic -- nothing in here knows which database it will hold. The bucket, the
# server name and the credentials all arrive as the accessory's `cmd:` and
# environment, so one image serves them all.
#
# Why not ghcr.io/cloudnative-pg/postgresql, which already bundles Barman:
# their PG18 image dropped the entrypoint entirely (Entrypoint=[], Cmd=[bash])
Expand Down
21 changes: 21 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2026 metsa.app

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
18 changes: 8 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,9 @@ ghcr.io/metsaapp/postgres-barman:18
ghcr.io/metsaapp/postgres-barman:18-20260712 # immutable
```

One image, every MetsaApp database. It is deliberately generic: nothing in it
knows which database it will hold. The bucket, the server name and the credentials
all arrive as the accessory's `cmd:` and environment.
One image, every database that backs up to object storage. It is deliberately
generic: nothing in it knows which database it will hold. The bucket, the server
name and the credentials all arrive as the accessory's `cmd:` and environment.

```mermaid
flowchart LR
Expand All @@ -22,9 +22,7 @@ flowchart LR
PG -->|"barman-cloud-backup<br/>(nightly base backup)"| S3
S3 -->|"barman-cloud-restore<br/>+ wal-restore"| REC["recovered database"]

C1["o-result"] --> img
C2["metsa api"] -.not yet.-> img
C3["metsa zitadel"] -.not yet.-> img
C1["your databases"] --> img

style S3 fill:#1f6feb,color:#fff
style img fill:#8957e5,color:#fff
Expand All @@ -45,9 +43,9 @@ postgres:
image: ghcr.io/metsaapp/postgres-barman:18
env:
clear:
POSTGRES_USER: oresult
POSTGRES_DB: oresult
AWS_DEFAULT_REGION: fsn1
POSTGRES_USER: myapp
POSTGRES_DB: myapp
AWS_DEFAULT_REGION: us-east-1
secret:
- POSTGRES_PASSWORD
- AWS_ACCESS_KEY_ID # barman-cloud-* reads these straight from the
Expand All @@ -61,7 +59,7 @@ postgres:
-c wal_level=replica
-c archive_mode=on
-c archive_timeout=3600
-c archive_command="barman-cloud-wal-archive -z --cloud-provider aws-s3 --endpoint-url https://fsn1.your-objectstorage.com s3://o-result-backups/api o-result-production %p"
-c archive_command="barman-cloud-wal-archive -z --cloud-provider aws-s3 --endpoint-url https://s3.example.com s3://my-backups/myapp myapp-production %p"
-c shared_preload_libraries=pg_stat_statements
options:
user: "0" # the entrypoint chowns PGDATA, then drops to postgres via gosu
Expand Down
18 changes: 18 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# Security

## Supported versions

The `:18` tag and its immutable `:18-YYYYMMDD` siblings, built from `main`. Older date tags
are not patched -- rebuild from `main` to pick up a new base.

Most of what you would report here lives upstream: this image is `postgres:18` (pinned by
digest) plus `barman[cloud,aws]` from PyPI. A vulnerability in Postgres or Barman itself
belongs to those projects; what we can fix here is the digest we pin and how we build on it.

## Reporting

Report privately via [GitHub Security Advisories](https://github.com/MetsaApp/postgres-barman/security/advisories/new),
not a public issue.

No SLA -- this is a small project. You will get an acknowledgement and an honest answer about
whether and when it will be fixed.
Loading