From 3c87b48fdfb20f70b57db81dd166cb4cd1affabf Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 1 Jul 2025 13:27:56 -0400 Subject: Unattended local backups Needs /var/secrets/restic to be manually provisioned. Based on ~/.dotfiles/restic/run, as a starting point. Backing up /srv/Attic is huge (100s of GBs), redundant (same hard drive), and slow (hours). It probably makes sense to mirror it instead. The repo password is stored on the same hard drive in plaintext, which means our repo is not secure at rest. This is a bigger issue with the initial setup without full disk encryption, so we choose not to address it; however, this does expose all backups whereas previously just this server was exposed. The most important remaining tasks are to mirror the restic backups remotely, and to automate on a timer. --- hostnix/elmo/configuration.nix | 1 + 1 file changed, 1 insertion(+) (limited to 'hostnix/elmo/configuration.nix') diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix index 0bdda0d..dee01be 100644 --- a/hostnix/elmo/configuration.nix +++ b/hostnix/elmo/configuration.nix @@ -3,6 +3,7 @@ { imports = [ ./acme.nix + ./backup.nix ./dns.nix ./dyndns.nix ./email.nix -- cgit v1.3.1