diff --git a/roles/backup/defaults/main.yml b/roles/backup/defaults/main.yml new file mode 100644 index 0000000..25bf917 --- /dev/null +++ b/roles/backup/defaults/main.yml @@ -0,0 +1,14 @@ +# ansible/roles/backup/defaults/main.yml +--- +## Directories to include in the backup +backup_include_paths: + - /etc + - /opt/docker + +## Directories to exclude from the backup +backup_exclude_paths: [] ## Nothing to exclude + +## Restic retention policy +backup_retention_daily: 7 +backup_retention_weekly: 4 +backup_retention_monthly: 6 diff --git a/roles/backup/tasks/main.yml b/roles/backup/tasks/main.yml new file mode 100644 index 0000000..22f4bc7 --- /dev/null +++ b/roles/backup/tasks/main.yml @@ -0,0 +1,61 @@ +--- +- name: Install restic + ansible.builtin.apt: + name: restic + state: present + +- name: Initialize restic repository + environment: + RESTIC_REPOSITORY: "{{ vault_restic_repo_url }}" + RESTIC_PASSWORD: "{{ vault_restic_password }}" + AWS_ACCESS_KEY_ID: "{{ vault_aws_access_key }}" + AWS_SECRET_ACCESS_KEY: "{{ vault_aws_secret_key }}" + block: + - name: Check if already initialized + ansible.builtin.command: restic snapshots + register: restic_check + failed_when: false + changed_when: false + + - name: Initialize repository + ansible.builtin.command: restic init + when: restic_check.rc != 0 + +- name: Deploy restic environment file + ansible.builtin.template: + src: restic-backup.env.j2 + dest: /etc/restic-backup.env + owner: root + group: root + mode: "0600" ## only root can read this file + +- name: Deploy restic backup script + ansible.builtin.template: + src: restic-backup.sh.j2 + dest: /usr/local/bin/restic-backup.sh + owner: root + group: root + mode: "0700" ## only root can execute the script + +- name: Deploy restic systemd service + ansible.builtin.template: + src: restic-backup.service.j2 + dest: /etc/systemd/system/restic-backup.service + owner: root + group: root + mode: "0644" + +- name: Deploy restic systemd timer + ansible.builtin.template: + src: restic-backup.timer.j2 + dest: /etc/systemd/system/restic-backup.timer + owner: root + group: root + mode: "0644" + +- name: Enable and start backup timer + ansible.builtin.systemd: + name: restic-backup.timer + enabled: yes + state: started + daemon_reload: yes diff --git a/roles/backup/templates/restic-backup.env.j2 b/roles/backup/templates/restic-backup.env.j2 new file mode 100644 index 0000000..d1b6db1 --- /dev/null +++ b/roles/backup/templates/restic-backup.env.j2 @@ -0,0 +1,5 @@ +# Ansible managed +RESTIC_REPOSITORY="{{ vault_restic_repo_url }}" +RESTIC_PASSWORD="{{ vault_restic_password }}" +AWS_ACCESS_KEY_ID="{{ vault_aws_access_key }}" +AWS_SECRET_ACCESS_KEY="{{ vault_aws_secret_key }}" diff --git a/roles/backup/templates/restic-backup.service.j2 b/roles/backup/templates/restic-backup.service.j2 new file mode 100644 index 0000000..027d216 --- /dev/null +++ b/roles/backup/templates/restic-backup.service.j2 @@ -0,0 +1,8 @@ +[Unit] +Description=Run Restic Backup +After=network-online.target + +[Service] +Type=oneshot +EnvironmentFile=/etc/restic-backup.env +ExecStart=/usr/local/bin/restic-backup.sh diff --git a/roles/backup/templates/restic-backup.sh.j2 b/roles/backup/templates/restic-backup.sh.j2 new file mode 100644 index 0000000..77b76d2 --- /dev/null +++ b/roles/backup/templates/restic-backup.sh.j2 @@ -0,0 +1,30 @@ +#!/bin/bash +## Ansible managed + +set -e + +# Source environment variables if running manually/outside Systemd +if [ -f /etc/restic-backup.env ]; then + # shellcheck source=/dev/null + . /etc/restic-backup.env +fi + +echo "Starting Restic Backup at $(date)" + +## Run the backup using paths and exclusions defined as group_vars +restic backup \ +{% for path in backup_include_paths %} + "{{ path }}" \ +{% endfor %} +{% for path in backup_exclude_paths %} + --exclude "{{ path }}" \ +{% endfor %} + --cleanup-cache + +restic forget \ + --prune \ + --keep-daily {{ backup_retention_daily }} \ + --keep-weekly {{ backup_retention_weekly }} \ + --keep-monthly {{ backup_retention_monthly }} + +echo "Restic backup completed at $(date)" diff --git a/roles/backup/templates/restic-backup.timer.j2 b/roles/backup/templates/restic-backup.timer.j2 new file mode 100644 index 0000000..e68ad85 --- /dev/null +++ b/roles/backup/templates/restic-backup.timer.j2 @@ -0,0 +1,10 @@ +[Unit] +Description=Run Restic Backup + +[Timer] +OnCalendar=*-*-* 04:00:00 +Persistent=true +RandomizedDelaySec=1800 + +[Install] +WantedBy=timers.target