diff --git a/hosts/nachtigall/apps/forgejo.nix b/hosts/nachtigall/apps/forgejo.nix index 08fd9923..12e7a492 100644 --- a/hosts/nachtigall/apps/forgejo.nix +++ b/hosts/nachtigall/apps/forgejo.nix @@ -107,4 +107,17 @@ environment.variables = { GPG_TTY = "$(tty)"; }; + + services.restic.backups.forgejo = flake.self.lib.droppieBackup { + paths = [ + "/var/lib/forgejo" + "/tmp/forgejo-backup.sql" + ]; + backupPrepareCommand = '' + ${pkgs.sudo}/bin/sudo -iu postgres ${pkgs.postgresql}/bin/pg_dump -d gitea > /tmp/forgejo-backup.sql + ''; + backupCleanupCommand = '' + rm /tmp/forgejo-backup.sql + ''; + }; } diff --git a/hosts/nachtigall/apps/keycloak.nix b/hosts/nachtigall/apps/keycloak.nix index 9db430b0..7c7a41db 100644 --- a/hosts/nachtigall/apps/keycloak.nix +++ b/hosts/nachtigall/apps/keycloak.nix @@ -46,4 +46,16 @@ "pub.solar" = flake.inputs.keycloak-theme-pub-solar.legacyPackages.${pkgs.system}.keycloak-theme-pub-solar; }; }; + + services.restic.backups.keycloak = flake.self.lib.droppieBackup { + paths = [ + "/tmp/keycloak-backup.sql" + ]; + backupPrepareCommand = '' + ${pkgs.sudo}/bin/sudo -iu postgres ${pkgs.postgresql}/bin/pg_dump -d keycloak > /tmp/keycloak-backup.sql + ''; + backupCleanupCommand = '' + rm /tmp/keycloak-backup.sql + ''; + }; } diff --git a/hosts/nachtigall/apps/mailman.nix b/hosts/nachtigall/apps/mailman.nix index 4b79396f..6285c815 100644 --- a/hosts/nachtigall/apps/mailman.nix +++ b/hosts/nachtigall/apps/mailman.nix @@ -79,4 +79,12 @@ # "allauth.socialaccount.providers.gitlab" # ]) #''; + + services.restic.backups.mailman = flake.self.lib.droppieBackup { + paths = [ + "/var/lib/mailman" + "/var/lib/mailman-web/mailman-web.db" + "/var/lib/postfix/conf/aliases.db" + ]; + }; } diff --git a/hosts/nachtigall/apps/mastodon.nix b/hosts/nachtigall/apps/mastodon.nix index c1b7dfaa..fae406d4 100644 --- a/hosts/nachtigall/apps/mastodon.nix +++ b/hosts/nachtigall/apps/mastodon.nix @@ -1,6 +1,10 @@ -{ config, pkgs, flake, inputs, ... }: - { + config, + pkgs, + flake, + inputs, + ... +}: { age.secrets."mastodon-secret-key-base" = { file = "${flake.self}/secrets/mastodon-secret-key-base.age"; mode = "400"; @@ -93,4 +97,16 @@ OMNIAUTH_ONLY = "true"; }; }; + + services.restic.backups.mastodon = flake.self.lib.droppieBackup { + paths = [ + "/tmp/mastodon-backup.sql" + ]; + backupPrepareCommand = '' + ${pkgs.sudo}/bin/sudo -iu postgres ${pkgs.postgresql}/bin/pg_dump -d gitea > /tmp/mastodon-backup.sql + ''; + backupCleanupCommand = '' + rm /tmp/mastodon-backup.sql + ''; + }; } diff --git a/hosts/nachtigall/apps/nextcloud.nix b/hosts/nachtigall/apps/nextcloud.nix index b93af37c..9817a670 100644 --- a/hosts/nachtigall/apps/nextcloud.nix +++ b/hosts/nachtigall/apps/nextcloud.nix @@ -3,8 +3,7 @@ pkgs, flake, ... -}: -{ +}: { age.secrets."nextcloud-secrets" = { file = "${flake.self}/secrets/nextcloud-secrets.age"; mode = "400"; @@ -130,4 +129,17 @@ autoUpdateApps.enable = true; database.createLocally = true; }; + + services.restic.backups.nextcloud = flake.self.lib.droppieBackup { + paths = [ + "/var/lib/nextcloud/data" + "/tmp/nextcloud-backup.sql" + ]; + backupPrepareCommand = '' + ${pkgs.sudo}/bin/sudo -iu postgres ${pkgs.postgresql}/bin/pg_dump -d nextcloud > /tmp/nextcloud-backup.sql + ''; + backupCleanupCommand = '' + rm /tmp/nextcloud-backup.sql + ''; + }; } diff --git a/hosts/nachtigall/backups.nix b/hosts/nachtigall/backups.nix new file mode 100644 index 00000000..2495365d --- /dev/null +++ b/hosts/nachtigall/backups.nix @@ -0,0 +1,7 @@ +{ flake, ... }: { + age.secrets."restic-repo-droppie" = { + file = "${flake.self}/secrets/restic-repo-droppie.age"; + mode = "400"; + owner = "root"; + }; +} diff --git a/hosts/nachtigall/default.nix b/hosts/nachtigall/default.nix index 9f3aabcd..de927890 100644 --- a/hosts/nachtigall/default.nix +++ b/hosts/nachtigall/default.nix @@ -7,6 +7,7 @@ ./configuration.nix ./networking.nix + ./backups.nix ./apps/nginx.nix ./apps/collabora.nix diff --git a/lib/default.nix b/lib/default.nix index d7448e45..20566ff9 100644 --- a/lib/default.nix +++ b/lib/default.nix @@ -11,6 +11,10 @@ ## In configs, they can be used under "lib.our" deploy = import ./deploy.nix { inherit inputs lib; }; + + linux = { + unlockZFSOnBoot = import ./unlock-zfs-on-boot.nix {publicKeys = self.publicKeys.allAdmins;}; + }; }; }; } diff --git a/lib/droppie-backup.nix b/lib/droppie-backup.nix new file mode 100644 index 00000000..be834607 --- /dev/null +++ b/lib/droppie-backup.nix @@ -0,0 +1,10 @@ +{ config, ... }: extraOptions: { + timerConfig = { + OnCalendar = "*-*-* 02:00:00 Etc/UTC"; + # droppie will be offline if nachtigall misses the timer + Persistent = false; + }; + initialize = true; + passwordFile = config.age.secrets."restic-repo-droppie".path; + repository = "yule@droppie.b12f.io:/media/internal/backups-pub-solar"; +} // extraOptions diff --git a/secrets/restic-repo-droppie.age b/secrets/restic-repo-droppie.age new file mode 100644 index 00000000..11cdb63a --- /dev/null +++ b/secrets/restic-repo-droppie.age @@ -0,0 +1,27 @@ +age-encryption.org/v1 +-> ssh-ed25519 iDKjwg T5uxRdAUm+mxC5VdLsJcvA7BolM8l0cofI8V6fEUEBE +dCpeg4SheN/krKGe72jHNbdul3Lvy/AwG3dq4pY/AkM +-> ssh-ed25519 uYcDNw PGHCygBqKuORMouxi/JHzzRPeM2ON+YMOYV9E1vX+Vo +F7yp4gLrEEj4BCYwsDl2LPCCRUtbDfZ/AzAAhah4+dA +-> ssh-rsa kFDS0A +lQLfw3v75CzhrS7WyHPwU+Cm+vwrlCg7hhfKGb7J67elxh21GG/6qaZfRwWL11zc +P6G3Gt//92qBwrRuWN+G7fuhThTuEsHsqqpA8JOnNIgwfk8rNN2kTj8XbkIE7Uq8 +R5ZQplV7QTtWZ0CGBl4lu4d6cf3zdFZJw6VaDoqNmC6WjwEGw4T6maZqlEmtsEra +i1LYssPXAFbeYxa1wsD/B9pI05WrGbgpBuEpybb+9v3O+u57bLAFAC1NCsj0OKNz ++7HJe5jaC5yntOjitrIrG7hIemOR5oPn5rX4+gyhEOzGud4IyMmMRKw8+1lsSqEJ +88BLgtO1LZ+K7XA4T4uhMNzJNlibo8uhPZVcpuOHAM2mb77kyOEEnGBTewT17Wyg +pJUIigTd8RHQmhQoyRM/EwbX15fSHmjrqwppCpQmTCNDdj+BhdfjaE8nRSJzBWDa +1C4tzxEoCAwCdowdS5Dh8Ho73JCbZr0GGpZgEoKhZJtPW/is9LCYKUIn/RQCfWvS +J9rQIGBJt3e0zNz2l+/cab0Z7z5nrfN8WJUYRWe/LJ4w2UbhTp8Qo9c5kKmP0qJg +cej2+H/v3o1KNdXdumUgmL9XeKTJeFQ1XIAbNzWa2eziLAigeg1fPraPpxLm6vfm +JBOB7xuATiOegs1KxnZh3GI6tO9GRaN1GOGMj6Vw/yc +-> ssh-ed25519 YFSOsg fO1nyrzWiiDBKUsi5WVZs6gj0oj8AnCDgzT45RuTaEI +zLBD5W/Ab8afsUGjBk2DHGYnwYca11FWRubaHPQqu0w +-> ssh-ed25519 iHV63A LEq9h44BkYmAt3ABHka7EdfZVQ7VGbU81SApWQ4O0TA +kqOs+WIAQKQdCEyDSHF0+1TU6W0d9Nk5uMzpw1X9tE8 +-> ssh-ed25519 BVsyTA 15QuQEzMBnFLOQ1VXYc/bhXPClbNY27WUxVi/PKdrg4 +k5J8BnC0ltep+Unjvc9rbsTAERAAwHVBx3Le1Uw3i7k +-> fz6"|e\K-grease ~A 1vo}k)X ;M