blob: 856a1c329344b21e339b36bf3d26fce34aab5b1d (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
|
{
config,
pkgs,
lib,
...
}: let
cfg = config.vhack.backup;
snapshots = "/srv/snapshots";
postgresUser = "postgres";
in {
options.vhack.backup = {
enable = lib.mkEnableOption "backups with restic";
user = lib.mkOption {
type = lib.types.str;
description = "The storagebox-user to use";
example = "u384702-sub2";
};
privateSshKey = lib.mkOption {
type = lib.types.path;
description = "The age-encrypted ssh-key, passed to agenix";
};
privatePassword = lib.mkOption {
type = lib.types.path;
description = "The age-encrypted restic password, passed to agenix";
};
};
config = lib.mkIf cfg.enable {
vhack.persist.directories = [
{
directory = "/root/.ssh";
user = "root";
group = "root";
mode = "0700";
}
];
age.secrets = {
resticpass = {
file = cfg.privatePassword;
mode = "0700";
owner = "root";
group = "root";
};
resticssh = {
file = cfg.privateSshKey;
mode = "0700";
owner = "root";
group = "root";
};
};
services.restic.backups = {
storagebox = {
initialize = true;
backupPrepareCommand = ''
${pkgs.sudo}/bin/sudo -u ${postgresUser} ${pkgs.postgresql}/bin/pg_dumpall --clean --if-exists --quote-all-identifiers > /srv/db_backup.sql
[ -d /srv/snapshots ] || ${pkgs.btrfs-progs}/bin/btrfs subvolume create /srv/snapshots;
[ -d /srv/snapshots/srv ] && ${pkgs.btrfs-progs}/bin/btrfs subvolume delete /srv/snapshots/srv;
${pkgs.btrfs-progs}/bin/btrfs subvolume snapshot -r /srv /srv/snapshots/srv;
# dump() {
# # compression:
# # pg_dump -F t -v "$1" | xz -z -9 -e -T0 > "db_$1.tar.xz"
# pg_dump -v "$1" > "db_$1.tar.xz"
# }
# # List all databases, and dump each of them in its own file
# # psql --list --csv | while read -r line; do echo "$line" | grep ','; done | while IFS=, read -r name _; do echo "$name"; done | sed '1d' | while read -r db_name; do dump "$db_name"; done
'';
paths = [
snapshots
];
exclude = [
".snapshots"
"/var/lib/postgresql" # included in the db dump
];
extraBackupArgs = [
"--verbose" # spam log
];
passwordFile = config.age.secrets.resticpass.path;
extraOptions = [
"rclone.program='ssh -p 23 ${cfg.user}@${cfg.user}.your-storagebox.de -i ${config.age.secrets.resticssh.path}'"
];
repository = "rclone: "; # There is only one repository served
timerConfig = {
Requires = "network-online.target";
OnCalendar = "daily";
Persistent = true;
};
};
};
};
}
|