summaryrefslogtreecommitdiff
path: root/hostnix/elmo/backup.nix
blob: edba6b988e75df52bfc6b7c00437482aa5a42f6b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
{ lib, ... }:

# TODO consistent btrfs snapshots?
# TODO dump Home Assistant? Postgres?
# TODO explicit backup blacklist for /srv and /var? can be a separate cron

{
  services.restic.backups.local = {
    # The repo file permissions and our exclude file assume our user.
    user = "joe";
    repository = "/srv/restic/repo";
    paths = [
      # Same as ~/.dotfiles/restic/run
      "/etc"
      "/home"
      "/root"
      "/var/home"
      "/var/spool/cron"
      "/var/www"

      "/srv/git"
      "/var/lib"
      "/var/secrets"
    ];
    # The restic repo is not secure at rest because our password is colocated.
    passwordFile = "%d/password";
    # Same as ~/.dotfiles/restic/run
    extraBackupArgs = [
      "--one-file-system"
      "--exclude-file=/home/joe/.dotfiles/restic/exclude"
      "--exclude-caches"
    ];
    backupPrepareCommand = let ls-lR = [
      "/srv/media"
      "/var/lib/acme"
      "/var/secrets"
    ];
    in
    ''
      ls -lR ${lib.concatStringsSep " " ls-lR} > ~/.dotfiles/restic/errata/ls-lR.excluded
    '';
    # The wrapper would not be able to use RESTIC_PASSWORD_FILE from a systemd
    # credential.
    createWrapper = false;
    timerConfig = null;  # TODO daily?
  };

  systemd.services.restic-backups-local = {
    serviceConfig = {
      LoadCredential = [ "password:/var/secrets/restic" ];
      AmbientCapabilities = [ "CAP_DAC_READ_SEARCH" ];
    };
  };

  # TODO restic-sync to spanommers

  # TODO mirror?
  # - /srv/Attic (split into archive/mirror and backup/adhoc?)
  # - /srv/from-spanommers (move to /srv/Attic/Backups?)
  # - /srv/syncthing (or configure spanommers with syncthing?)
}