Bundles the post-2026-04-21 work that built out the two-layer backup architecture (PBS for VM images + restic for file/DB), plus the cross- site mirror and the disaster-recovery runbook. - configs/restic/esh-docker-vm/profiles.yaml: drop the obsolete *_offen_backup_data exclude (offen sidecars retired fleet-wide 2026-04-23; restic now covers the equivalent scope directly). - configs/restic/esh-vm-db/: new profile for the dedicated DB VM (10.0.50.60), with pre-backup pg_dumpall + mongodump hooks. - configs/rsync/: ana-nas → nh3-nas (04:00 daily, runs as lkraven) and nh3-nas → ana-nas (05:00 daily, runs as root because DSM rest-server-nh3 writes mode-400 files only root can read). - docs/runbooks/pbs-deployment.md: 9-phase PBS rollout runbook, refined during the 2026-04-22 deployment with per-hypervisor namespaces, NFSv3 + ZFS-case-insensitivity workaround, and the Synology syno_acl flatten step. - docs/runbooks/disaster-recovery.md: blast-radius runbook ordered Tier 0 → 5 (ana-nas → hypervisors → Docker hosts → VMs → specialty); references incident memory + recovery-step playbooks per consumer.
47 lines
1.8 KiB
Desktop File
47 lines
1.8 KiB
Desktop File
[Unit]
|
|
Description=Mirror rest-server-ana restic repo to NH3 Synology
|
|
Documentation=https://github.com/lkraven/eshpfi-management/blob/main/configs/rsync/ana-nas-to-nh3/README.md
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
ConditionPathIsDirectory=/mnt/backup/restic/repo/ana
|
|
StartLimitBurst=3
|
|
StartLimitIntervalSec=1h
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
User=lkraven
|
|
Group=lkraven
|
|
Nice=10
|
|
IOSchedulingClass=idle
|
|
|
|
# Dedicated key for this job, ed25519, ana-nas → nh3-nas:syncuser.
|
|
# --append-only on rest-server-ana means source files are never
|
|
# rewritten or deleted by clients; --delete here mirrors any explicit
|
|
# prune operations (done out-of-band during the quarterly ceremony).
|
|
# tmp/ and .lock excluded to avoid mirroring in-flight transfers.
|
|
ExecStart=/usr/bin/rsync \
|
|
--archive \
|
|
--delete \
|
|
--partial \
|
|
--info=stats2 \
|
|
--timeout=300 \
|
|
--exclude=tmp/ \
|
|
--exclude=.lock \
|
|
-e "ssh -i /home/lkraven/.ssh/id_mirror_nh3 -o StrictHostKeyChecking=accept-new -o BatchMode=yes -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o ConnectTimeout=30" \
|
|
/mnt/backup/restic/repo/ana/ \
|
|
syncuser@10.100.50.50:/volume1/Backup/restic-ana-mirror/
|
|
|
|
# ServerAlive{Interval,CountMax}=30/3 + rsync --timeout bound below
|
|
# force detection of dead WAN within ~90s; without this, a silent TCP
|
|
# drop holds the service in "activating" for hours on kernel retransmit
|
|
# backoff. TimeoutStartSec=6h caps worst-case initial sync; after
|
|
# that systemd kills the service even if rsync somehow wedges.
|
|
TimeoutStartSec=6h
|
|
|
|
# Tight retry window — a transient WAN blip shouldn't wedge the timer
|
|
# schedule, but spamming retries on a real outage is noise.
|
|
# StartLimitBurst/Interval live in [Unit] (systemd v230+); the burst
|
|
# cap prevents runaway retries even with the short RestartSec.
|
|
Restart=on-failure
|
|
RestartSec=30s
|