Captures the full workspace state built up to this point:
- CLAUDE.md + README.md describing conventions and the four-host fleet
(ana-ml2, ana-docker, nh3-docker, esh-docker-vm).
- Per-host notes under servers/<host>/ with ssh-target fallback files
and latest system-details snapshots (two in-compose credential leaks
scrubbed; the upstream compose files still need to move those to .env).
- scripts/: server_inspect.sh (read-only remote diagnostic),
refresh-server-info.sh (dir-driven discovery + snapshot capture with
validation warnings), add-host.sh, sync-stacks.sh (pull
compose/conf trees), deploy-stack.sh (push with per-file diff + prompt).
- stacks/: canonical compose for backrest, beszel, dozzle, llama-swap,
rest-server-ana, rest-server-nh3, vllm-qwen3, plus the retired
infinity reference. All use the .env-driven + traefik-net + homepage
label pattern.
- configs/restic/ana-docker/: first resticprofile config + pre-backup
hook (Synapse pg_dump, Seafile mysqldump, Vaultwarden SQLite); templates
for the other three hosts to come.
- docs/pfi/: general infrastructure reference carried over.
- .gitignore excludes .env, stacks-mirror/, and assorted secret/state
filenames to prevent re-leaks on later commits.
77 lines
2.3 KiB
YAML
77 lines
2.3 KiB
YAML
# resticprofile config for ana-docker.
|
|
#
|
|
# Writes to the Anaheim-side rest-server at 10.250.50.70 as user
|
|
# `ana-docker`. The full REST URL (including HTTP basic-auth creds)
|
|
# lives in /etc/restic/restic.env — loaded via env-file so this YAML
|
|
# carries zero secrets and is safe to version-control.
|
|
#
|
|
# The client-side encryption passphrase lives in /etc/restic/password.
|
|
|
|
version: "1"
|
|
|
|
global:
|
|
priority: low
|
|
ionice: true
|
|
ionice-class: 2
|
|
ionice-level: 7
|
|
min-memory: 100
|
|
|
|
default:
|
|
env-file: /etc/restic/restic.env # provides RESTIC_REPOSITORY=rest:http://user:pw@…
|
|
env:
|
|
RESTIC_PASSWORD_FILE: /etc/restic/password
|
|
initialize: false # repo was created by `restic init`
|
|
lock: /var/lock/restic-ana-docker.lock
|
|
|
|
backup:
|
|
verbose: 1
|
|
run-before:
|
|
- /etc/restic/pre-backup.sh
|
|
run-after:
|
|
- date +%s > /var/lib/restic/last-success
|
|
source:
|
|
- /opt/docker
|
|
- /var/lib/docker/volumes
|
|
- /var/lib/restic/stage
|
|
exclude:
|
|
# Docker internals we never want in a backup
|
|
- /var/lib/docker/volumes/backingFsBlockDev
|
|
- /var/lib/docker/volumes/metadata.db
|
|
# Raw DB files — we dump them via pre-backup.sh into /var/lib/restic/stage
|
|
- /var/lib/docker/volumes/synapse-db-data
|
|
- /var/lib/docker/volumes/synapse_synapse-db-data
|
|
- /var/lib/docker/volumes/seafile_db
|
|
# Ephemeral / regenerable junk
|
|
- /opt/docker/compose/*/logs
|
|
- /opt/docker/conf/traefik-ana/acme.json # secret material; excluded everywhere
|
|
- /opt/docker/conf/crowdsec/hub # upstream-managed, regenerable
|
|
- "**/*.log"
|
|
- "**/*.log.*"
|
|
- "**/*.pid"
|
|
tag:
|
|
- host:ana-docker
|
|
- site:ana
|
|
- fleet:pfi
|
|
schedule: "*-*-* 01:00:00"
|
|
schedule-permission: system
|
|
schedule-log: /var/log/restic-backup.log
|
|
|
|
forget:
|
|
keep-daily: 7
|
|
keep-weekly: 4
|
|
keep-monthly: 12
|
|
keep-yearly: 3
|
|
# NOTE: no `prune: true` — rest-server runs with --append-only, which
|
|
# blocks the destructive half of prune. See README.md "Prune ceremony".
|
|
tag:
|
|
- host:ana-docker
|
|
schedule: "*-*-* 03:00:00"
|
|
schedule-permission: system
|
|
schedule-log: /var/log/restic-forget.log
|
|
|
|
check:
|
|
read-data-subset: 10%
|
|
schedule: "Sun *-*-* 05:00:00"
|
|
schedule-permission: system
|
|
schedule-log: /var/log/restic-check.log
|