diff --git a/recipes/backup/01_install-restic.md b/recipes/backup/01_install-restic.md new file mode 100644 index 0000000..254d0af --- /dev/null +++ b/recipes/backup/01_install-restic.md @@ -0,0 +1,46 @@ +# Install Restic + +This recipe installs Restic, a fast, secure, and encrypted backup tool. + +## Install Package + +```bash +sudo apt update +sudo apt install -y restic +``` + +## Verify Installation + +```bash +restic version +``` + +Expected output: + +```text +restic x.x.x compiled with go... +``` + +## Verify Binary Location + +```bash +which restic +``` + +Expected output: + +```text +/usr/bin/restic +``` + +## Troubleshooting + +### Command not found + +Verify that the package is installed. + +```bash +dpkg -l | grep restic +``` + +If it is not installed, repeat the installation step. diff --git a/recipes/backup/02_configure-s3.md b/recipes/backup/02_configure-s3.md new file mode 100644 index 0000000..44110a2 --- /dev/null +++ b/recipes/backup/02_configure-s3.md @@ -0,0 +1,115 @@ +# Configure Restic S3 Repository + +This recipe configures an encrypted Restic repository stored in an S3-compatible object storage. + +## Supported Providers + +Restic supports any S3-compatible storage provider, including: + +- MinIO +- Amazon S3 +- Cloudflare R2 +- Oracle Cloud Object Storage + +## Create Environment File + +```bash +sudo nano /etc/restic.env +``` + +Example: + +```bash +export AWS_DEFAULT_REGION=YOUR_BUCKET_REGION_OR_AUTO +export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY +export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY + +export RESTIC_PASSWORD=CHANGE_ME +export RESTIC_REPOSITORY=s3:https:////restic/ +``` + +Replace: + +- `` with your provider endpoint. +- `` with your bucket name. +- `` with a prefix for backups (e.g. machine name) + +Protect the file: + +```bash +sudo chmod 600 /etc/restic.env +sudo chown root:root /etc/restic.env +``` + +## Common Endpoint Examples + +| Provider | Endpoint | +|---------------------|-------------------------------------------------------------| +| MinIO | `minio.example.com` | +| Amazon S3 | `s3.amazonaws.com` | +| Cloudflare R2 | `.r2.cloudflarestorage.com` | +| Oracle Cloud | `.compat.objectstorage..oraclecloud.com` | + +## Example Configurations + +Cloudflare R2: + +```bash +RESTIC_REPOSITORY=s3:https://xxxxxxxx.r2.cloudflarestorage.com/backups/restic +``` + +Oracle Cloud: + +```bash +RESTIC_REPOSITORY=s3:https://mynamespace.compat.objectstorage.sa-saopaulo-1.oraclecloud.com/backups/restic +``` + +## Load Environment + +```bash +source <(sudo cat /etc/restic.env) +``` + +## Initialize Repository + +```bash +restic init +``` + +Expected output: + +```text +created restic repository +``` + +If the repository already exists: + +```text +repository master key and config already initialized +``` + +## Verify Repository + +```bash +restic snapshots +``` + +Expected output: + +```text +no snapshots found +``` + +## Troubleshooting + +### Repository already initialized + +Expected if repository exists. + +### Wrong password + +Verify the value of: + +```bash +echo $RESTIC_PASSWORD +``` diff --git a/recipes/backup/03_create-backup-job.md b/recipes/backup/03_create-backup-job.md new file mode 100644 index 0000000..a8bdb1f --- /dev/null +++ b/recipes/backup/03_create-backup-job.md @@ -0,0 +1,114 @@ +# Create Automatic Backup Job + +This recipe creates a daily backup job using Restic and systemd. + +## Create Backup Script + +```bash +sudo nano /usr/local/bin/restic-backup.sh +``` + +Contents: + +```bash +#!/usr/bin/env bash +set -e + +source /etc/restic.env + +restic backup + +restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --keep-yearly 3 --prune +``` + +Replace: + +- `` with the folder path you want to backup (e.g. `/srv/samba`) + +## Make Script Executable + +```bash +sudo chmod +x /usr/local/bin/restic-backup.sh +``` + +## Load Environment + +```bash +source <(sudo cat /etc/restic.env) +``` + +## Test Backup + +```bash +sudo /usr/local/bin/restic-backup.sh +``` + +## Verify Snapshot + +```bash +restic snapshots +``` + +Expected output: + +```text +ID Time Host +---------------------------------------- +xxxxxxxx YYYY-MM-DD HH:MM hostname +``` + +## Automate with Cron + +Edit root crontab. + +```bash +sudo crontab -e +``` + +Add: + +```cron +0 2 * * * /usr/local/bin/restic-backup.sh +``` + +## Verify Cron + +```bash +sudo crontab -l +``` + +Expected output should contain: + +```cron +0 2 * * * /usr/local/bin/restic-backup.sh +``` + +## Troubleshooting + +### Repository not found + +Verify: + +```bash +echo $RESTIC_REPOSITORY +``` + +### Authentication failed + +Verify the configured S3 credentials. + +```bash +echo $AWS_ACCESS_KEY_ID +``` + +```bash +echo $AWS_SECRET_ACCESS_KEY +``` + +### Wrong password + +Verify: + +```bash +echo $RESTIC_PASSWORD +``` diff --git a/recipes/backup/04_restore.md b/recipes/backup/04_restore.md new file mode 100644 index 0000000..d3de589 --- /dev/null +++ b/recipes/backup/04_restore.md @@ -0,0 +1,95 @@ +# Restore Backup + +This recipe restores files from a Restic repository. + +## Load Environment + +```bash +source <(sudo cat /etc/restic.env) +``` + +## List Snapshots + +```bash +restic snapshots +``` + +Expected output: + +```text +ID Time Host +---------------------------------------- +xxxxxxxx YYYY-MM-DD HH:MM +``` + +## Restore Latest Snapshot + +```bash +restic restore latest --target /tmp/restore +``` + +## Restore Specific Snapshot + +Replace `` with the desired snapshot. + +```bash +restic restore --target /tmp/restore +``` + +## Restore a Single Directory + +```bash +restic restore latest --target /tmp/restore --include +``` + +Replace: + +- `` with the folder path you want to restore (e.g. `/srv/samba`) + +## Verify Restored Files + +```bash +ls -la /tmp/restore +``` + +## Verify Repository Integrity + +```bash +restic check +``` + +Expected output: + +```text +no errors were found +``` + +## Troubleshooting + +### Repository not found + +Verify: + +```bash +echo $RESTIC_REPOSITORY +``` + +### Authentication failed + +Verify the configured S3 credentials. + +```bash +echo $AWS_ACCESS_KEY_ID +``` + +```bash +echo $AWS_SECRET_ACCESS_KEY +``` + +### Wrong password + +Verify: + +```bash +echo $RESTIC_PASSWORD +```