backup: update coverage map and blind spots (2026-05-28)
- CT 108 Zoraxy decommissioned -> Traefik on CT 109 - Add critical blind spots: Vaultwarden (local FS, not backed up), Garage S3 data (WAL-G archive store, not backed up), Paperless media - Fix services plan path list to match actual Backrest config.json - Mark stale plan paths: arcane, arr-stack, gluetun - Note Garage config incident: garage.toml became a directory after Portainer redeploy; fixed 2026-05-28 by manual replace + layout apply
This commit is contained in:
+14
-7
@@ -33,18 +33,19 @@
|
|||||||
| `media-backup-plan` | `media-repo` | `30 1 * * 1-5` weekdays 01:30 | 4w · 6m · 1y | `/mnt/pve/unas/media/images/library` |
|
| `media-backup-plan` | `media-repo` | `30 1 * * 1-5` weekdays 01:30 | 4w · 6m · 1y | `/mnt/pve/unas/media/images/library` |
|
||||||
| `video-projects-plan` | `media-repo` | nightly 02:00 | per config | `/mnt/pve/unas/media/video-projects` |
|
| `video-projects-plan` | `media-repo` | nightly 02:00 | per config | `/mnt/pve/unas/media/video-projects` |
|
||||||
|
|
||||||
**Services plan paths** (all under `/mnt/pve/unas/`):
|
**Services plan paths** (all under `/mnt/pve/unas/`, verified 2026-05-28):
|
||||||
|
|
||||||
```
|
```
|
||||||
services/vaultwarden services/n8n services/memos
|
services/arcane services/arr-stack services/coder
|
||||||
services/karakeep services/traccar services/gitea
|
services/gitea services/gluetun services/karakeep
|
||||||
services/coder services/nextcloud
|
services/memos services/n8n services/nextcloud
|
||||||
services/arr-stack services/gluetun
|
services/pocketid-backup services/traccar
|
||||||
backup/home-assistant backup/immich backup/nextcloud
|
backup/home-assistant backup/immich backup/nextcloud
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> ⚠️ `services/arcane`, `services/arr-stack`, `services/gluetun` are stale paths (services decommissioned or moved) — harmless but should be pruned from the plan.
|
||||||
|
|
||||||
`services/shared-db` was removed when CT 113 came online — postgres is now WAL-G → Garage S3 → JottaCloud.
|
`services/shared-db` was removed when CT 113 came online — postgres is now WAL-G → Garage S3 → JottaCloud.
|
||||||
`services/arcane` removed 2026-05-26 — Arcane decommissioned, replaced by Portainer.
|
|
||||||
`services/pocketid` removed 2026-05-26 — Pocket-ID moved to CT 109 local FS (not UNAS); now covered by `ops-backup.timer` → Garage S3.
|
`services/pocketid` removed 2026-05-26 — Pocket-ID moved to CT 109 local FS (not UNAS); now covered by `ops-backup.timer` → Garage S3.
|
||||||
|
|
||||||
> **JottaCloud web UI tip**: rclone writes to the **Archive** section. The default landing page shows only Sync + Backup. Browse to `https://www.jottacloud.com/web/archive` to see the restic repos.
|
> **JottaCloud web UI tip**: rclone writes to the **Archive** section. The default landing page shows only Sync + Backup. Browse to `https://www.jottacloud.com/web/archive` to see the restic repos.
|
||||||
@@ -83,13 +84,15 @@ Garage → JottaCloud offsite sync runs daily 02:30 on CT 103 via `/usr/local/sb
|
|||||||
| CT 104 Gitea + Coder | `services/{gitea,coder}` (UNAS; moved from CT 111 2026-05-26) | ✓ |
|
| CT 104 Gitea + Coder | `services/{gitea,coder}` (UNAS; moved from CT 111 2026-05-26) | ✓ |
|
||||||
| CT 105 Nextcloud user files | `services/nextcloud` | ✓ |
|
| CT 105 Nextcloud user files | `services/nextcloud` | ✓ |
|
||||||
| CT 105 Nextcloud AIO volumes | AIO Borg → `/mnt/pve/unas/backup/nextcloud/` → Backrest | ✓ |
|
| CT 105 Nextcloud AIO volumes | AIO Borg → `/mnt/pve/unas/backup/nextcloud/` → Backrest | ✓ |
|
||||||
| CT 108 Zoraxy | Phase 3 git push → `fkrebs/zoraxy-conf` | ✗ not deployed |
|
| ~~CT 108 Zoraxy~~ | **DESTROYED 2026-05-28** — replaced by Traefik on CT 109 | — |
|
||||||
|
| CT 109 Traefik config + acme.json | Not backed up (LE can reissue; config in `/opt/stacks/traefik/`) | ✗ low risk |
|
||||||
| CT 109 Portainer config | Daily tar → Garage S3 `ct109-portainer-backup` → JottaCloud sync | ✓ |
|
| CT 109 Portainer config | Daily tar → Garage S3 `ct109-portainer-backup` → JottaCloud sync | ✓ |
|
||||||
| CT 109 Pocket-ID | Daily tar → Garage S3 `ct109-portainer-backup` (key `ops-*.tar.gz`) → JottaCloud sync via `ops-backup.timer` | ✓ |
|
| CT 109 Pocket-ID | Daily tar → Garage S3 `ct109-portainer-backup` (key `ops-*.tar.gz`) → JottaCloud sync via `ops-backup.timer` | ✓ |
|
||||||
| CT 109 Infisical | pg_dump in `ops-*.tar.gz` (same as above) | ✓ |
|
| CT 109 Infisical | pg_dump in `ops-*.tar.gz` (same as above) | ✓ |
|
||||||
| ~~CT 110 Pocket-ID~~ | **CT 110 destroyed 2026-05-26 — see CT 109 row above** | ✓ |
|
| ~~CT 110 Pocket-ID~~ | **CT 110 destroyed 2026-05-26 — see CT 109 row above** | ✓ |
|
||||||
| ~~CT 111 Gitea + Coder~~ | **CT 111 destroyed 2026-05-26 — see CT 104 row above** | ✓ |
|
| ~~CT 111 Gitea + Coder~~ | **CT 111 destroyed 2026-05-26 — see CT 104 row above** | ✓ |
|
||||||
| ~~CT 112 Infisical~~ | **CT 112 destroyed 2026-05-26 — see CT 109 row above** | ✓ |
|
| ~~CT 112 Infisical~~ | **CT 112 destroyed 2026-05-26 — see CT 109 row above** | ✓ |
|
||||||
|
| ~~CT 108 Zoraxy~~ | **CT 108 destroyed 2026-05-28 — Traefik on CT 109 is replacement** | — |
|
||||||
| VM 100 HAOS config | Phase 3 git addon → `fkrebs/ha-config` | ✗ not deployed |
|
| VM 100 HAOS config | Phase 3 git addon → `fkrebs/ha-config` | ✗ not deployed |
|
||||||
| VM 100 HAOS daily tar | HA → UNAS → Backrest | ✓ |
|
| VM 100 HAOS daily tar | HA → UNAS → Backrest | ✓ |
|
||||||
| PVE host `/etc/pve/` | Phase 3 git push → `fkrebs/pve-conf` | ✗ not deployed |
|
| PVE host `/etc/pve/` | Phase 3 git push → `fkrebs/pve-conf` | ✗ not deployed |
|
||||||
@@ -137,11 +140,15 @@ Script template in [appendix](#phase-3-config-to-git-scripts).
|
|||||||
|
|
||||||
| # | Severity | Issue | Fix |
|
| # | Severity | Issue | Fix |
|
||||||
|---|---|---|---|
|
|---|---|---|---|
|
||||||
|
| 1 | **CRITICAL** | **Vaultwarden data at `/opt/stacks/vaultwarden/data` (CT 104 local FS) — not on UNAS, not in any plan.** Password vault loss is unrecoverable. | Move volume to `/mnt/pve/unas/services/vaultwarden/` and add that path to `services-backup-plan`. |
|
||||||
|
| 2 | HIGH | **Garage S3 data at `/opt/stacks/shared-db/garage/` (CT 104 local FS) — contains all WAL-G DB archives.** If CT 104 disk dies before WAL-G → JottaCloud sync runs, all DB backups are gone. | Add `/opt/stacks/shared-db/garage/` to a Backrest plan, OR verify JottaCloud sync runs frequently enough. Note: Garage had a config incident 2026-05-28 (toml path became a directory after Portainer redeploy — fixed manually). |
|
||||||
|
| 3 | MEDIUM | Paperless-ngx media at `/mnt/pve/unas/media/documents/public/paperless-ngx/` not in any Backrest plan. | Add to `services-backup-plan` paths. |
|
||||||
| 4 | MEDIUM | n8n encryption key in `/opt/stacks/n8n/data/` on CT 104 local FS — not in any plan. If CT 104 dies, DB restore is unusable. | Move n8n data volume to `/mnt/pve/unas/services/n8n/` (already in plan). |
|
| 4 | MEDIUM | n8n encryption key in `/opt/stacks/n8n/data/` on CT 104 local FS — not in any plan. If CT 104 dies, DB restore is unusable. | Move n8n data volume to `/mnt/pve/unas/services/n8n/` (already in plan). |
|
||||||
| 4b | MEDIUM | Nextcloud AIO Borg passphrase only in container env. Borg repo encrypted — without it, restore impossible. | Store `BORG_PASSWORD` in Vaultwarden. |
|
| 4b | MEDIUM | Nextcloud AIO Borg passphrase only in container env. Borg repo encrypted — without it, restore impossible. | Store `BORG_PASSWORD` in Vaultwarden. |
|
||||||
| 5 | MEDIUM | Both Backrest repo passwords are `tapirnase`. | Rotate before first scheduled run completes; `restic key passwd` re-encrypts in place. Store in Vaultwarden. |
|
| 5 | MEDIUM | Both Backrest repo passwords are `tapirnase`. | Rotate before first scheduled run completes; `restic key passwd` re-encrypts in place. Store in Vaultwarden. |
|
||||||
| 6 | LOW | `litellm` DB password is the placeholder literal `litellm_password_here`. | Generate real password; update `ai/.env`, `litellm-config/config.yaml`, CT 113 user. |
|
| 6 | LOW | `litellm` DB password is the placeholder literal `litellm_password_here`. | Generate real password; update `ai/.env`, `litellm-config/config.yaml`, CT 113 user. |
|
||||||
| 7 | LOW | Migration dumps at `/mnt/pve/unas/dump/*-migration-20260521.sql` not in any plan. | Decide: keep as manual archive or delete now that WAL-G is archiving. |
|
| 7 | LOW | Migration dumps at `/mnt/pve/unas/dump/*-migration-20260521.sql` not in any plan. | Decide: keep as manual archive or delete now that WAL-G is archiving. |
|
||||||
|
| 8 | LOW | Stale paths in `services-backup-plan`: `arcane`, `arr-stack`, `gluetun` (services gone/moved). | Remove from plan to reduce noise and snapshot size. |
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user