feat(hosea): add restic backup for AlbyHub with agenix secret
This commit is contained in:
@@ -26,6 +26,13 @@ in
|
|||||||
owner = "grafana";
|
owner = "grafana";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# NOTE: Before deploying, create the secret with:
|
||||||
|
# agenix -e secrets/albyhub-restic-password.age
|
||||||
|
age.secrets.albyhub-restic-password = {
|
||||||
|
file = ../../../secrets/albyhub-restic-password.age;
|
||||||
|
owner = "root";
|
||||||
|
};
|
||||||
|
|
||||||
# Bootloader
|
# Bootloader
|
||||||
boot = {
|
boot = {
|
||||||
loader = {
|
loader = {
|
||||||
@@ -103,6 +110,29 @@ in
|
|||||||
workDir = "/chain/alby";
|
workDir = "/chain/alby";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
restic.backups.albyhub = {
|
||||||
|
# Backs up AlbyHub's LDK state directory to the nas1 Restic REST server.
|
||||||
|
# The service is stopped before backup to ensure LDK state consistency
|
||||||
|
# and restarted afterward.
|
||||||
|
repository = "rest:https://nas1.shire-zebra.ts.net:30248/albyhub";
|
||||||
|
passwordFile = config.age.secrets.albyhub-restic-password.path;
|
||||||
|
paths = [ "/chain/alby" ];
|
||||||
|
timerConfig = {
|
||||||
|
OnCalendar = "daily";
|
||||||
|
RandomizedDelaySec = "1h";
|
||||||
|
};
|
||||||
|
backupPrepareCommand = ''
|
||||||
|
systemctl stop albyhub.service || true
|
||||||
|
'';
|
||||||
|
backupCleanupCommand = ''
|
||||||
|
systemctl start albyhub.service || true
|
||||||
|
'';
|
||||||
|
pruneOpts = [
|
||||||
|
"--keep-daily 7"
|
||||||
|
"--keep-weekly 4"
|
||||||
|
"--keep-monthly 3"
|
||||||
|
];
|
||||||
|
};
|
||||||
jellyfin = {
|
jellyfin = {
|
||||||
enable = true;
|
enable = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
|
|||||||
Reference in New Issue
Block a user