# Runbook — bring Gitea back from the off-site copy on ep0 (R-232) > **TESTED 2026-10-09** into a throwaway (the bench, LXC 9401 on demo-hp): 10 of 10 repositories listed, the four > product repositories' `main` equal to live Gitea (one was one commit behind: that commit was pushed three minutes > after the copy, and the copy's commit is its parent), one file byte for byte, a throwaway admin logged in. Restore > from ep0: 544 MB in 22 s. Evidence: `audits/dooplex-survival-2026-10-09/partC/`. The copy itself: > `audits/dooplex-survival-2026-10-09/PLAN.md` and `scripts/dooplex-offsite/`. ## What the copy holds One encrypted archive `dooplex.pxar` per night in ep0's PBS, namespace `operator`, group `host/dooplex-gitea` (14 daily + 8 weekly kept). Inside: | Path | What | |---|---| | `db/gitea.dump` | `pg_dump -Fc` of the `gitea` database (PostgreSQL 17.2), taken BEFORE the files | | `db/globals.sql`, `db/DUMP-FOLDER` | all roles of the CNPG cluster (password hashes — not needed for this restore); which dump | | `gitea/git/repositories//.git` | the bare repositories | | `gitea/git/lfs`, `gitea/gitea/{attachments,avatars,repo-avatars,jwt}` | the rest of Gitea's data | | `gitea/gitea/conf/app.ini` | the config, **with Gitea's secrets** (`SECRET_KEY`, `INTERNAL_TOKEN`, JWT, the DB password) | | `secrets/*.gpg` | DooPlex's nightly k8s Secrets/ConfigMaps export, GPG-encrypted with DooPlex's restic passphrase | | `MANIFEST.sha256`, `REPOS` | a checksum of every file; the repository count | **Not in it:** the container registry (`/data/gitea/packages`, 27.7 GB). The images rebuild from the code. ## What you need - **The key**: the `data` field of the paper key from the password manager („DooPlex off-site (Gitea) key"). Write `{"kdf": null, "created": "2026-01-01T00:00:00+00:00", "modified": "2026-01-01T00:00:00+00:00", "data": ""}` to `enc.key` (root, `umask 077`). On DooPlex it is `/etc/felhom-dooplex-offsite/enc.key`. - **A read-only token** for `dooplex-hub@pbs!restore` (DooPlex: `/etc/felhom-hub-backup/token-restore`), or ep0 root to mint one (`RUNBOOK-hub-db-offsite-backup.md` Step 2). - **A route to ep0's PBS** (`127.0.0.1:18007` through DooPlex's tunnel, or ep0's 8007 over the WireGuard). - A machine with Docker. For the secrets files: DooPlex's restic passphrase (operator, offline). ## Steps 1. **Restore the newest copy** (any machine with `proxmox-backup-client`): ```bash export PBS_PASSWORD_FILE= PBS_FINGERPRINT= R='dooplex-hub@pbs!restore@:felhom-offsite' proxmox-backup-client snapshot list host/dooplex-gitea --ns operator --repository "$R" # pick the newest umask 077; proxmox-backup-client restore host/dooplex-gitea/