Backup

Introduction

The backup module schedules rsync pushes from named local paths to SSH targets. A target can receive several independently named paths beneath a shared remote root.

Requirements

Each target must be reachable over SSH with the configured identity, and every source path must be mounted before its timer runs. The remote account must permit rsync writes beneath backup.remoteRoot.

The SSH identity should be supplied through agenix and persisted when the host uses an impermanent root. Confirm that each source path is mounted before relying on a scheduled backup.

Persistence

Systemd stores per-target service state locally, but the durable backup is the remote rsync tree. Persist the SSH identity through agenix and ensure source datasets are mounted rather than backing up empty mountpoint directories.

Troubleshooting

Inspect the generated backup-<target>.service and .timer; current examples are backup-de4856-de4856-rsync-net.service and backup-pbovbel-offsite.service. Each target stores its accepted host key under /var/lib/backup-<target>/known_hosts. Verify every configured /storage/app/<service>, /storage/backup, or /storage/media/<library> source is mounted before running the unit, since rsync cannot distinguish an empty mountpoint from an empty dataset.

Options

backup.identityFile

SSH private key used to connect to backup targets.

Type: null or string

Default:

null

Declared by:

backup.remoteRoot

Remote directory that receives backup path subdirectories.

Type: string

Default:

"nixos"

Declared by:

backup.targets

SSH targets and the backup paths each receives.

Type: attribute set of (submodule)

Default:

{ }

Example:

{
  "12345@usw-s001.rsync.net" = {
    paths = {
      documents = {
        destination = "backup/documents";
        source = "/storage/backup/documents";
      };
    };
  };
}

Declared by:

backup.targets.<name>.paths

Named local paths to push to this backup target.

Type: attribute set of (submodule)

Default:

{ }

Declared by:

backup.targets.<name>.paths.<name>.destination

Directory name under backup.remoteRoot on backup targets.

Type: string

Default:

"‹name›"

Declared by:

backup.targets.<name>.paths.<name>.excludes

rsync exclude patterns for this path.

Type: list of string

Default:

[ ]

Declared by:

backup.targets.<name>.paths.<name>.source

Local path to push to backup targets.

Type: string

Declared by:

backup.timer

systemd OnCalendar expression for backup runs.

Type: string

Default:

"daily"

Declared by: