backup pipeline: configs, runbooks, NH3 Synology rest-server, cross-site rsync
Bundles the post-2026-04-21 work that built out the two-layer backup architecture (PBS for VM images + restic for file/DB), plus the cross- site mirror and the disaster-recovery runbook. - configs/restic/esh-docker-vm/profiles.yaml: drop the obsolete *_offen_backup_data exclude (offen sidecars retired fleet-wide 2026-04-23; restic now covers the equivalent scope directly). - configs/restic/esh-vm-db/: new profile for the dedicated DB VM (10.0.50.60), with pre-backup pg_dumpall + mongodump hooks. - configs/rsync/: ana-nas → nh3-nas (04:00 daily, runs as lkraven) and nh3-nas → ana-nas (05:00 daily, runs as root because DSM rest-server-nh3 writes mode-400 files only root can read). - docs/runbooks/pbs-deployment.md: 9-phase PBS rollout runbook, refined during the 2026-04-22 deployment with per-hypervisor namespaces, NFSv3 + ZFS-case-insensitivity workaround, and the Synology syno_acl flatten step. - docs/runbooks/disaster-recovery.md: blast-radius runbook ordered Tier 0 → 5 (ana-nas → hypervisors → Docker hosts → VMs → specialty); references incident memory + recovery-step playbooks per consumer.
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
[Unit]
|
||||
Description=Mirror rest-server-nh3 restic repo to ANA NAS
|
||||
Documentation=https://github.com/lkraven/eshpfi-management/blob/main/configs/rsync/nh3-nas-to-ana/README.md
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
ConditionPathIsDirectory=/volume1/Backup/restic
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
User=root
|
||||
Group=root
|
||||
Nice=10
|
||||
IOSchedulingClass=idle
|
||||
|
||||
# Runs as root because rest-server-nh3's Docker container writes the
|
||||
# restic repo files as admin:users mode 400 — only root bypasses that
|
||||
# via CAP_DAC_READ_SEARCH. Running as syncuser (even with admins
|
||||
# group membership) was denied by POSIX mode. Earlier attempt with
|
||||
# synoacltool ACL grants failed because this DSM version ships
|
||||
# without the tool.
|
||||
#
|
||||
# Dedicated key for this job, ed25519, nh3-nas:root → ana-nas:lkraven.
|
||||
# Does NOT include /volume1/Backup/restic-ana-mirror (that's data
|
||||
# ana-nas just sent us; mirroring it back would be a dedupe-less loop).
|
||||
# Source is the per-host tree under /volume1/Backup/restic/ only:
|
||||
# nh3-docker/, nh3-dev/, repo/.
|
||||
# tmp/ and .lock excluded to avoid mirroring in-flight transfers.
|
||||
# SSH keepalive + rsync --timeout ensure a dead WAN is detected in
|
||||
# ~90s instead of hanging on kernel TCP retransmit backoff.
|
||||
#
|
||||
# NO Restart=on-failure here: DSM's systemd is pre-v247 and refuses
|
||||
# Restart= on Type=oneshot. If a run fails, the daily timer picks
|
||||
# up again tomorrow — a single missed mirror is acceptable for DR.
|
||||
ExecStart=/usr/bin/rsync \
|
||||
--recursive \
|
||||
--links \
|
||||
--times \
|
||||
--no-perms \
|
||||
--no-owner \
|
||||
--no-group \
|
||||
--chmod=D755,F644 \
|
||||
--delete \
|
||||
--partial \
|
||||
--info=stats2 \
|
||||
--timeout=300 \
|
||||
--exclude=tmp/ \
|
||||
--exclude=.lock \
|
||||
-e "ssh -i /root/.ssh/id_mirror_ana -o StrictHostKeyChecking=accept-new -o BatchMode=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o ConnectTimeout=30" \
|
||||
/volume1/Backup/restic/ \
|
||||
lkraven@10.250.50.50:/mnt/backup/restic-nh3-mirror/
|
||||
|
||||
TimeoutStartSec=6h
|
||||
Reference in New Issue
Block a user