libretechandClaude Opus 4.7 07a713c90e Add deploy workflow and backup tooling
CI deployment (.gitea/workflows/deploy.yml):
- Two jobs (build, deploy) gated on the repo variable
  DEPLOY_ENABLED=true so the workflow exists but does nothing
  until secrets and host are configured.
- Build pushes two image tags per run: rolling :main + the short
  SHA on main, or vX.Y.Z + :latest on tag pushes. Immutable per
  commit/tag tags make rollback trivial.
- Deploy SSHes to DEPLOY_HOST, runs docker compose pull && up -d
  in DEPLOY_PATH, then polls HEALTH_URL for up to a minute. A
  failed health check fails the workflow, which is the alert.
- Required secrets and the rollback procedure are documented in
  docs/operations.md.

Backup tooling (scripts/):
- backup.sh: SQLite online .backup snapshot + tarball of the
  per-tenant data dir + info.txt header, all wrapped into a
  single librenotes-YYYYMMDD-HHMMSS.tar.gz. Optional BACKUP_REMOTE
  triggers an rclone copy for off-site storage.
- backup-prune.sh: enforces retention "30 daily + 12 monthly".
  Sorts archives by filename (date is in the name so lex order
  matches chronological) and keeps the newest 30 plus the newest
  archive for each of the most recent 12 months.
- backup-restore-test.sh: extracts the most recent archive into
  a tmpdir, runs sqlite3 .schema (proves DB readability), and
  asserts the notes tar has at least one entry. Failure is the
  alert. Wired into a separate weekly timer.
- librenotes-backup.{service,timer}: systemd units for the daily
  03:17 UTC run with 5min jitter; ProtectSystem=strict, only
  /var/backups/librenotes is writable.
- librenotes-backup-verify.{service,timer}: weekly Monday
  04:00 UTC restore test.

Closes #26 and #27.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 22:49:40 +02:00
2026-04-28 21:58:59 +02:00
2026-04-28 21:58:59 +02:00
2026-04-28 21:58:59 +02:00

librenotes

CI

Cloud-native, multi-tenant notes application. A fork of Notesium extended with authentication, per-user data isolation, sync, and PWA support so it can run as a hosted service at librenot.es.

Features

  • Markdown notes with bi-directional links (Zettelkasten / evergreen notes)
  • Embedded web app — no Electron, no Node runtime, single static binary
  • Multi-tenant backend with magic-link authentication (in development)
  • Offline-capable PWA with background sync (planned, Phase 4)

Build

Requires Go 1.20 or later.

go build ./cmd/librenotes

This produces a librenotes binary in the current directory. The web frontend and shell completion are embedded into the binary at compile time, so no extra files are needed at runtime.

A Makefile with build, test, run, and clean targets is provided for convenience:

make build
make test

Run

./librenotes web --notes-dir ~/notes

See ./librenotes help for the full command list.

Development setup

A Nix flake provides a reproducible development environment with Go, build tools, and the project CLIs. Use the plain dev shell for a non-sandboxed Go toolchain:

nix develop .#dev

Alternatively, build a Docker-based dev environment:

docker build -f Dockerfile.dev -t librenotes-dev .
docker run --rm -it -v "$PWD:/workspace" librenotes-dev

The repository layout follows the standard Go project structure:

cmd/librenotes/      Binary entry point
internal/notesium/   Core notes package (forked from Notesium)
internal/notesium/web/   Embedded frontend assets

The Go module path is git.librete.ch/public/librenotes.

Fork attribution

librenotes is a fork of Notesium by Alon Swartz, used and redistributed under the MIT License. See NOTICE for the upstream commit hash at fork time and instructions for tracking upstream changes.

License

MIT — see LICENSE. Copyright is shared between the original Notesium author and the librenotes contributors.

S
Description
No description provided
Readme MIT
987 KiB
2026-04-29 01:30:06 +02:00
Languages
JavaScript 51.3%
Go 33.8%
HTML 8%
Shell 2.9%
CSS 2.4%
Other 1.6%