{ lib, ... }: # TODO consistent btrfs snapshots? # TODO dump Home Assistant? Postgres? # TODO explicit backup blacklist for /srv and /var? can be a separate cron { services.restic.backups.local = { # The repo file permissions and our exclude file assume our user. user = "joe"; repository = "/srv/restic/repo"; paths = [ # Same as ~/.dotfiles/restic/run "/etc" "/home" "/root" "/var/home" "/var/spool/cron" "/var/www" "/srv/git" "/var/lib" "/var/secrets" ]; # The restic repo is not secure at rest because our password is colocated. passwordFile = "%d/password"; # Same as ~/.dotfiles/restic/run extraBackupArgs = [ "--one-file-system" "--exclude-file=/home/joe/.dotfiles/restic/exclude" "--exclude-caches" ]; backupPrepareCommand = let ls-lR = [ "/srv/media" "/var/lib/acme" "/var/secrets" ]; in '' ls -lR ${lib.concatStringsSep " " ls-lR} > ~/.dotfiles/restic/errata/ls-lR.excluded ''; # The wrapper would not be able to use RESTIC_PASSWORD_FILE from a systemd # credential. createWrapper = false; timerConfig = null; # TODO daily? }; systemd.services.restic-backups-local = { serviceConfig = { LoadCredential = [ "password:/var/secrets/restic" ]; AmbientCapabilities = [ "CAP_DAC_READ_SEARCH" ]; }; }; # TODO restic-sync to spanommers # TODO mirror? # - /srv/Attic (split into archive/mirror and backup/adhoc?) # - /srv/from-spanommers (move to /srv/Attic/Backups?) # - /srv/syncthing (or configure spanommers with syncthing?) }