Skip to main content

Configure blob storage

Archives from GitLab need to be temporarily stored so GitHub can read them.

For most customers, we recommend storing archives with GitHub-owned blob storage. This is the simplest path and does not require any extra configuration.

However, you may want to configure storage with an external provider if you have firewall requirements or need to retain archives after the migration is complete.

Choosing where to stage archives

The GL2GH extension exports each GitLab project to an archive, then uploads the archive to blob storage that GitHub can read from. You choose the storage backend when you run a migration.

Storage optionHow to select itNotes
GitHub-owned blob storage (recommended)--use-github-storageNo setup required. GitHub deletes the archive automatically after a successful migration, or seven days after a failed migration.
AWS S3--aws-bucket-name (with the AWS_REGION, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY environment variables, and optionally AWS_SESSION_TOKEN)You own the bucket and its lifecycle. GitHub does not delete archives from your storage.
Azure Blob StorageAZURE_STORAGE_CONNECTION_STRING environment variable (for a single migrate-repo command, you can instead use --azure-storage-connection-string)Only storage-account access-key connection strings are supported (not SAS). GitHub does not delete archives from your storage.

Configuring blob storage

If you are using GitHub-owned blob storage, you do not need to configure anything. You will use the --use-github-storage flag to select this method with the CLI. However, you may want to set the GITHUB_OWNED_STORAGE_MULTIPART_MEBIBYTES variable (default 100 MiB, minimum 5 MiB) to a lower number if you have a slow or proxied connection.

If you are using external blob storage, you will need to set this up.

Setting up an AWS S3 storage bucket

在 AWS 中,设置 S3 Bucket。 有关详细信息,请参阅 AWS 文档中的创建 Bucket

还需要具有以下权限的 AWS 访问密钥和密钥:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListBucketMultipartUploads",
                "s3:AbortMultipartUpload",
                "s3:ListBucket",
                "s3:DeleteObject",
                "s3:ListMultipartUploadParts"
            ],
            "Resource": [
                "arn:aws:s3:::github-migration-bucket",
                "arn:aws:s3:::github-migration-bucket/*"
            ]
        }
    ]
}

注意

迁移完成后,GitHub Enterprise Importer 不会从 AWS 中删除存档。 为了降低存储成本,建议配置在一段时间后自动删除存档。 有关详细信息,请参阅 AWS 文档中的 Bucket 生命周期配置

准备好运行迁移后,你将需要向 GitHub CLI 提供 AWS 凭据:区域、访问密钥、密钥和会话令牌(如果需要)。 可以将它们作为参数传递,或设置名为 AWS_REGIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKEN 的环境变量。

你还需要使用 --aws-bucket-name 参数传入 S3 Bucket 的名称。

Setting up an Azure Blob Storage storage account

在 Azure 中,创建存储帐户并记下连接字符串。 有关详细信息,请参阅 Microsoft Docs 中的管理存储帐户访问密钥

注意

迁移完成后,GitHub Enterprise Importer 不会从 Azure Blob 存储中删除存档。 为了降低存储成本,建议配置为在一段时间后自动删除存档。 有关详细信息,请参阅 Microsoft Docs 中的通过自动管理数据生命周期来优化成本

准备好运行迁移时,可以将连接字符串作为参数传递到 GitHub CLI,或使用名为 AZURE_STORAGE_CONNECTION_STRING 的环境变量将其传入。

Allowing network access

If you have configured firewall rules on your storage account, ensure you have allowed access to the IP ranges for your migration destination. See Manage access for a migration from GitLab to GitHub.