Bundles the post-2026-04-21 work that built out the two-layer backup architecture (PBS for VM images + restic for file/DB), plus the cross- site mirror and the disaster-recovery runbook. - configs/restic/esh-docker-vm/profiles.yaml: drop the obsolete *_offen_backup_data exclude (offen sidecars retired fleet-wide 2026-04-23; restic now covers the equivalent scope directly). - configs/restic/esh-vm-db/: new profile for the dedicated DB VM (10.0.50.60), with pre-backup pg_dumpall + mongodump hooks. - configs/rsync/: ana-nas → nh3-nas (04:00 daily, runs as lkraven) and nh3-nas → ana-nas (05:00 daily, runs as root because DSM rest-server-nh3 writes mode-400 files only root can read). - docs/runbooks/pbs-deployment.md: 9-phase PBS rollout runbook, refined during the 2026-04-22 deployment with per-hypervisor namespaces, NFSv3 + ZFS-case-insensitivity workaround, and the Synology syno_acl flatten step. - docs/runbooks/disaster-recovery.md: blast-radius runbook ordered Tier 0 → 5 (ana-nas → hypervisors → Docker hosts → VMs → specialty); references incident memory + recovery-step playbooks per consumer.
18 lines
633 B
SYSTEMD
18 lines
633 B
SYSTEMD
[Unit]
|
|
Description=Daily mirror of rest-server-ana restic repo to NH3
|
|
Documentation=https://github.com/lkraven/eshpfi-management/blob/main/configs/rsync/ana-nas-to-nh3/README.md
|
|
|
|
[Timer]
|
|
# 04:00 daily — sits between ana-side restic clients (01:00 finish
|
|
# window) and the PBS-ANA → PBS-NH3 sync at 06:00, so WAN contention
|
|
# is minimized. Persistent=true catches missed runs if ana-nas was
|
|
# offline; RandomizedDelaySec smears load if this ever scales to
|
|
# multiple mirror jobs on the same host.
|
|
OnCalendar=*-*-* 04:00:00
|
|
Persistent=true
|
|
RandomizedDelaySec=300
|
|
Unit=restic-mirror-to-nh3.service
|
|
|
|
[Install]
|
|
WantedBy=timers.target
|