about summary refs log tree commit diff stats
path: root/modules/by-name/ba/backup/module.nix
blob: 856a1c329344b21e339b36bf3d26fce34aab5b1d (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
{
  config,
  pkgs,
  lib,
  ...
}: let
  cfg = config.vhack.backup;
  snapshots = "/srv/snapshots";
  postgresUser = "postgres";
in {
  options.vhack.backup = {
    enable = lib.mkEnableOption "backups with restic";
    user = lib.mkOption {
      type = lib.types.str;
      description = "The storagebox-user to use";
      example = "u384702-sub2";
    };
    privateSshKey = lib.mkOption {
      type = lib.types.path;
      description = "The age-encrypted ssh-key, passed to agenix";
    };
    privatePassword = lib.mkOption {
      type = lib.types.path;
      description = "The age-encrypted restic password, passed to agenix";
    };
  };
  config = lib.mkIf cfg.enable {
    vhack.persist.directories = [
      {
        directory = "/root/.ssh";
        user = "root";
        group = "root";
        mode = "0700";
      }
    ];
    age.secrets = {
      resticpass = {
        file = cfg.privatePassword;
        mode = "0700";
        owner = "root";
        group = "root";
      };
      resticssh = {
        file = cfg.privateSshKey;
        mode = "0700";
        owner = "root";
        group = "root";
      };
    };
    services.restic.backups = {
      storagebox = {
        initialize = true;
        backupPrepareCommand = ''
          ${pkgs.sudo}/bin/sudo -u ${postgresUser} ${pkgs.postgresql}/bin/pg_dumpall --clean --if-exists --quote-all-identifiers > /srv/db_backup.sql

          [ -d /srv/snapshots ] || ${pkgs.btrfs-progs}/bin/btrfs subvolume create /srv/snapshots;
          [ -d /srv/snapshots/srv ] && ${pkgs.btrfs-progs}/bin/btrfs subvolume delete /srv/snapshots/srv;
          ${pkgs.btrfs-progs}/bin/btrfs subvolume snapshot -r /srv /srv/snapshots/srv;

          # dump() {
          #   # compression:
          #   # pg_dump -F t -v "$1" | xz -z -9 -e -T0 > "db_$1.tar.xz"
          #   pg_dump -v "$1" > "db_$1.tar.xz"
          # }
          # # List all databases, and dump each of them in its own file
          # # psql --list --csv | while read -r line; do echo "$line" | grep ','; done | while IFS=, read -r name _; do  echo "$name"; done | sed '1d' | while read -r db_name; do dump "$db_name"; done
        '';
        paths = [
          snapshots
        ];
        exclude = [
          ".snapshots"
          "/var/lib/postgresql" # included in the db dump
        ];
        extraBackupArgs = [
          "--verbose" # spam log
        ];
        passwordFile = config.age.secrets.resticpass.path;
        extraOptions = [
          "rclone.program='ssh -p 23 ${cfg.user}@${cfg.user}.your-storagebox.de -i ${config.age.secrets.resticssh.path}'"
        ];
        repository = "rclone: "; # There is only one repository served
        timerConfig = {
          Requires = "network-online.target";
          OnCalendar = "daily";
          Persistent = true;
        };
      };
    };
  };
}