feat(backup): add Restic S3 backup recipes
Introduce comprehensive recipes for Restic-based S3 backups. Covers installation, S3 repository configuration, automated backup job creation, and restoration of files.
This commit is contained in:
@@ -0,0 +1,46 @@
|
|||||||
|
# Install Restic
|
||||||
|
|
||||||
|
This recipe installs Restic, a fast, secure, and encrypted backup tool.
|
||||||
|
|
||||||
|
## Install Package
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo apt update
|
||||||
|
sudo apt install -y restic
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Installation
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic version
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
restic x.x.x compiled with go...
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Binary Location
|
||||||
|
|
||||||
|
```bash
|
||||||
|
which restic
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
/usr/bin/restic
|
||||||
|
```
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Command not found
|
||||||
|
|
||||||
|
Verify that the package is installed.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
dpkg -l | grep restic
|
||||||
|
```
|
||||||
|
|
||||||
|
If it is not installed, repeat the installation step.
|
||||||
@@ -0,0 +1,115 @@
|
|||||||
|
# Configure Restic S3 Repository
|
||||||
|
|
||||||
|
This recipe configures an encrypted Restic repository stored in an S3-compatible object storage.
|
||||||
|
|
||||||
|
## Supported Providers
|
||||||
|
|
||||||
|
Restic supports any S3-compatible storage provider, including:
|
||||||
|
|
||||||
|
- MinIO
|
||||||
|
- Amazon S3
|
||||||
|
- Cloudflare R2
|
||||||
|
- Oracle Cloud Object Storage
|
||||||
|
|
||||||
|
## Create Environment File
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nano /etc/restic.env
|
||||||
|
```
|
||||||
|
|
||||||
|
Example:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
export AWS_DEFAULT_REGION=YOUR_BUCKET_REGION_OR_AUTO
|
||||||
|
export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY
|
||||||
|
export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY
|
||||||
|
|
||||||
|
export RESTIC_PASSWORD=CHANGE_ME
|
||||||
|
export RESTIC_REPOSITORY=s3:https://<S3_ENDPOINT>/<BUCKET>/restic/<PREFIX>
|
||||||
|
```
|
||||||
|
|
||||||
|
Replace:
|
||||||
|
|
||||||
|
- `<S3_ENDPOINT>` with your provider endpoint.
|
||||||
|
- `<BUCKET>` with your bucket name.
|
||||||
|
- `<PREFIX>` with a prefix for backups (e.g. machine name)
|
||||||
|
|
||||||
|
Protect the file:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo chmod 600 /etc/restic.env
|
||||||
|
sudo chown root:root /etc/restic.env
|
||||||
|
```
|
||||||
|
|
||||||
|
## Common Endpoint Examples
|
||||||
|
|
||||||
|
| Provider | Endpoint |
|
||||||
|
|---------------------|-------------------------------------------------------------|
|
||||||
|
| MinIO | `minio.example.com` |
|
||||||
|
| Amazon S3 | `s3.amazonaws.com` |
|
||||||
|
| Cloudflare R2 | `<ACCOUNT_ID>.r2.cloudflarestorage.com` |
|
||||||
|
| Oracle Cloud | `<NAMESPACE>.compat.objectstorage.<REGION>.oraclecloud.com` |
|
||||||
|
|
||||||
|
## Example Configurations
|
||||||
|
|
||||||
|
Cloudflare R2:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
RESTIC_REPOSITORY=s3:https://xxxxxxxx.r2.cloudflarestorage.com/backups/restic
|
||||||
|
```
|
||||||
|
|
||||||
|
Oracle Cloud:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
RESTIC_REPOSITORY=s3:https://mynamespace.compat.objectstorage.sa-saopaulo-1.oraclecloud.com/backups/restic
|
||||||
|
```
|
||||||
|
|
||||||
|
## Load Environment
|
||||||
|
|
||||||
|
```bash
|
||||||
|
source <(sudo cat /etc/restic.env)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Initialize Repository
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic init
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
created restic repository
|
||||||
|
```
|
||||||
|
|
||||||
|
If the repository already exists:
|
||||||
|
|
||||||
|
```text
|
||||||
|
repository master key and config already initialized
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Repository
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic snapshots
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
no snapshots found
|
||||||
|
```
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Repository already initialized
|
||||||
|
|
||||||
|
Expected if repository exists.
|
||||||
|
|
||||||
|
### Wrong password
|
||||||
|
|
||||||
|
Verify the value of:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $RESTIC_PASSWORD
|
||||||
|
```
|
||||||
@@ -0,0 +1,114 @@
|
|||||||
|
# Create Automatic Backup Job
|
||||||
|
|
||||||
|
This recipe creates a daily backup job using Restic and systemd.
|
||||||
|
|
||||||
|
## Create Backup Script
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo nano /usr/local/bin/restic-backup.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
Contents:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
source /etc/restic.env
|
||||||
|
|
||||||
|
restic backup <PATH>
|
||||||
|
|
||||||
|
restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --keep-yearly 3 --prune
|
||||||
|
```
|
||||||
|
|
||||||
|
Replace:
|
||||||
|
|
||||||
|
- `<PATH>` with the folder path you want to backup (e.g. `/srv/samba`)
|
||||||
|
|
||||||
|
## Make Script Executable
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo chmod +x /usr/local/bin/restic-backup.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## Load Environment
|
||||||
|
|
||||||
|
```bash
|
||||||
|
source <(sudo cat /etc/restic.env)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Test Backup
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo /usr/local/bin/restic-backup.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Snapshot
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic snapshots
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
ID Time Host
|
||||||
|
----------------------------------------
|
||||||
|
xxxxxxxx YYYY-MM-DD HH:MM hostname
|
||||||
|
```
|
||||||
|
|
||||||
|
## Automate with Cron
|
||||||
|
|
||||||
|
Edit root crontab.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo crontab -e
|
||||||
|
```
|
||||||
|
|
||||||
|
Add:
|
||||||
|
|
||||||
|
```cron
|
||||||
|
0 2 * * * /usr/local/bin/restic-backup.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Cron
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo crontab -l
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output should contain:
|
||||||
|
|
||||||
|
```cron
|
||||||
|
0 2 * * * /usr/local/bin/restic-backup.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Repository not found
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $RESTIC_REPOSITORY
|
||||||
|
```
|
||||||
|
|
||||||
|
### Authentication failed
|
||||||
|
|
||||||
|
Verify the configured S3 credentials.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $AWS_ACCESS_KEY_ID
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $AWS_SECRET_ACCESS_KEY
|
||||||
|
```
|
||||||
|
|
||||||
|
### Wrong password
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $RESTIC_PASSWORD
|
||||||
|
```
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
# Restore Backup
|
||||||
|
|
||||||
|
This recipe restores files from a Restic repository.
|
||||||
|
|
||||||
|
## Load Environment
|
||||||
|
|
||||||
|
```bash
|
||||||
|
source <(sudo cat /etc/restic.env)
|
||||||
|
```
|
||||||
|
|
||||||
|
## List Snapshots
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic snapshots
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
ID Time Host
|
||||||
|
----------------------------------------
|
||||||
|
xxxxxxxx YYYY-MM-DD HH:MM
|
||||||
|
```
|
||||||
|
|
||||||
|
## Restore Latest Snapshot
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic restore latest --target /tmp/restore
|
||||||
|
```
|
||||||
|
|
||||||
|
## Restore Specific Snapshot
|
||||||
|
|
||||||
|
Replace `<snapshot-id>` with the desired snapshot.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic restore <snapshot-id> --target /tmp/restore
|
||||||
|
```
|
||||||
|
|
||||||
|
## Restore a Single Directory
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic restore latest --target /tmp/restore --include <PATH>
|
||||||
|
```
|
||||||
|
|
||||||
|
Replace:
|
||||||
|
|
||||||
|
- `<PATH>` with the folder path you want to restore (e.g. `/srv/samba`)
|
||||||
|
|
||||||
|
## Verify Restored Files
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ls -la /tmp/restore
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify Repository Integrity
|
||||||
|
|
||||||
|
```bash
|
||||||
|
restic check
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
no errors were found
|
||||||
|
```
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Repository not found
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $RESTIC_REPOSITORY
|
||||||
|
```
|
||||||
|
|
||||||
|
### Authentication failed
|
||||||
|
|
||||||
|
Verify the configured S3 credentials.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $AWS_ACCESS_KEY_ID
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $AWS_SECRET_ACCESS_KEY
|
||||||
|
```
|
||||||
|
|
||||||
|
### Wrong password
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
echo $RESTIC_PASSWORD
|
||||||
|
```
|
||||||
Reference in New Issue
Block a user