scripts: restic-prune.sh — quarterly forget + prune ceremony (closes #9)

Toggles --append-only off on the rest-server via a temporary
docker-compose.override.yaml (canonical compose untouched), runs
resticprofile forget --prune --verbose on each client of that
rest-server, then restores --append-only. The restore is wrapped in
a trap so a partial-failure prune still leaves the rest-server in
its safe configuration.

ANA side is fully automated against ana-docker (5 clients:
ana-docker, ana-ml2, esh-docker-vm, vm-esh-nas, esh-vm-db).

NH3 side currently prints a manual DSM ceremony — Synology Container
Manager doesn't expose docker on the expected paths and syncuser
sudo isn't NOPASSWD, so the toggle isn't safely scriptable from
this workstation. The instructions cover the same flow in DSM web
UI + interactive ssh on each NH3 client (nh3-docker, nh3-dev,
irv-ml1).

Usage:
  scripts/restic-prune.sh ana    # ANA only (auto)
  scripts/restic-prune.sh nh3    # NH3 instructions
  scripts/restic-prune.sh all    # both
  scripts/restic-prune.sh -h     # help
  scripts/restic-prune.sh --dry-run ana   # show every command
This commit is contained in:
vh
2026-04-24 22:01:37 -07:00
parent dc0e0b0080
commit 1f14c6d959
2 changed files with 207 additions and 4 deletions
+9 -4
View File
@@ -183,10 +183,15 @@ significant work lands — don't let it drift quietly.
Unlocks cross-site rsync (item 6), rest-server-nh3 healthcheck
deploy, and `.htpasswd` edits on the NH3 side.
9. **`scripts/restic-prune.sh`** — temporarily flip `--append-only` off,
run forget + prune across all hosts, flip back on. Needed quarterly
for disk hygiene. Not urgent; blocks only the "I need to reclaim
disk space now" scenario.
9. ~~**`scripts/restic-prune.sh`**~~ — **done 2026-04-24.** Quarterly
disk-hygiene tool. Drops `--append-only` on the rest-server (via a
temporary `docker-compose.override.yaml` — never edits the canonical
compose), runs `resticprofile forget --prune --verbose` on each
client, restores `--append-only` (with `trap` so it runs even on
partial failure). ANA side fully automated (5 clients); NH3 side
prints a manual ceremony because DSM Container Manager + sudo on
syncuser aren't cleanly scriptable from this workstation. Run with
`scripts/restic-prune.sh ana|nh3|all`, optionally `--dry-run`.
10. ~~**Retire `offen/docker-volume-backup` sidecars**~~ — **done
2026-04-23**. Removed from paperless-ngx and pgadmin composes on