Files
vngeoguessr/.github/workflows/leaderboard-backup.yml
T

53 lines
2.1 KiB
YAML

# Weekly copy of every leaderboard, kept as a workflow artifact for 90 days.
# Upstash's free plan has no scheduled backups, and the boards are the only
# player data the game holds. Needs the repository secrets KV_REST_API_URL,
# KV_REST_API_TOKEN and BACKUP_PASSPHRASE, plus KEY_PREFIX if the deployment
# sets one. Only the KV_* names are passed through, not UPSTASH_REDIS_REST_*.
# An export that finds no boards fails the job rather than uploading an empty
# file. GitHub disables scheduled workflows after 60 days without repository
# activity; re-enable it from the Actions tab if it goes quiet. The file is
# encrypted with the passphrase before upload: on a public repository any
# signed-in GitHub user can download an artifact, and the boards list every
# player name.
# Decrypt with: openssl enc -d -aes-256-cbc -pbkdf2 -in <file>.enc -out <file>
# then restore with npm run leaderboard:import (see docs/leaderboard-backup.md).
name: Leaderboard backup
on:
schedule:
# GitHub cron runs in UTC: Sunday 17:00 UTC is Monday 00:00 in Vietnam.
- cron: '0 17 * * 0'
workflow_dispatch:
permissions:
contents: read
jobs:
export:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 24
cache: npm
- run: npm ci
- run: npm run leaderboard:export -- leaderboard-backup.json
env:
KV_REST_API_URL: ${{ secrets.KV_REST_API_URL }}
KV_REST_API_TOKEN: ${{ secrets.KV_REST_API_TOKEN }}
KEY_PREFIX: ${{ secrets.KEY_PREFIX }}
- name: Encrypt
run: |
test -n "$BACKUP_PASSPHRASE" || { echo "BACKUP_PASSPHRASE secret is not set"; exit 1; }
openssl enc -aes-256-cbc -pbkdf2 -pass env:BACKUP_PASSPHRASE \
-in leaderboard-backup.json -out leaderboard-backup.json.enc
rm leaderboard-backup.json
env:
BACKUP_PASSPHRASE: ${{ secrets.BACKUP_PASSPHRASE }}
- uses: actions/upload-artifact@v7
with:
name: leaderboard-backup
path: leaderboard-backup.json.enc
retention-days: 90