Restic Backup: S3 backend
Deploy a restic backup repository backed by MinIO S3. See Restic backup for the backend-agnostic overview, shared variables, and installation.
Ansible hosts group: restic
Variables: shared
Shared variables are documented on the Restic backup page.
Variables
| Option | Type | Description | Default |
|---|---|---|---|
cs_restic_s3_cluster_name | string | Name of deployed S3 cluster for restic backend | {{ cs_restic_cluster_name }} |
cs_restic_s3_node_name | string | Name of deployed S3 node for restic backend | {{ inventory_hostname }} |
Server-side setup (tasks/restic_setup_repositories/s3-main.yml, tasks/restic_setup_repositories/s3-repo.yml)
For each repository defined in cs_restic_repos, the following steps are performed:
- S3 root credentials and port are read from Vault at
{{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_s3_cluster_name }}/hosts/{{ cs_restic_s3_node_name }}/apps/minio-s3/config, and the S3 host from{{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_s3_cluster_name }}/hosts/{{ cs_restic_s3_node_name }}. - A random 64-character S3 user password, 20-character access key, and 20-character secret key are generated.
- S3 credentials are written to Vault (see Vault keys below).
- A MinIO bucket
restic-<repo_name>and userrestic-<repo_name>are created via therestic_minio_bucketcustom module, with the user granted access to the bucket. - An access key pair is created for the user via
mc admin accesskey create. - The bucket is listed to check whether a
configobject already exists (confirming whether the repository is already initialized). - If the repository does not exist, the repository password is written to Vault and
restic initis run withRESTIC_REPOSITORY=s3:https://<host>:<port>/restic-<repo_name>. - The repository is validated: the repository password is read back from Vault and
restic snapshots --verboseis run against the repository using the generated access key pair.
Backup and restore (restic_backup_restore_s3)
Module for performing a backup or restore operation against an S3-backed restic repository. The caller is responsible for reading S3 credentials and the repository password from Vault (see Vault keys below) and passing them to the module; the module runs the appropriate restic command, then runs restic snapshots and restic check to validate the repository once that command succeeds.
Behavior
- Backup: runs
restic backup --verbose --host <restic_host> <local_dir>withAWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEYset as environment variables. - Restore: runs
restic restore latest --verbose --target <local_dir> --host <restic_host>with the same credentials. RESTIC_REPOSITORYis constructed ass3:https://<s3_host>:<s3_port>/<s3_bucket>.restic snapshots --verboseandrestic check --verboserun after every successful backup or restore; their output is returned insnapshots_stdout_lines/check_stdout_lines.
Example
- name: App | Restic Backup | Backup
restic_backup_restore_s3:
ops: backup
local_dir: /var/lib/my-app
restic_host: '{{ inventory_hostname }}'
s3_host: '{{ restic_repo_access.s3_host }}'
s3_port: '{{ restic_repo_access.s3_port }}'
s3_bucket: '{{ restic_repo_access.s3_bucket }}'
s3_access_key: '{{ restic_repo_access.s3_access_key }}'
s3_secret_key: '{{ restic_repo_access.s3_secret_key }}'
repo_password: '{{ restic_repo_password.repository_password }}'
vars:
restic_repo_access: "{{ lookup('vault_kv_get',
cs_project_code + '/application-deployer/clusters/' + cs_restic_cluster_name + '/hosts/' + inventory_hostname
+ '/apps/restic/generated/s3-repository-access-my-repo') }}"
restic_repo_password: "{{ lookup('vault_kv_get',
cs_project_code + '/application-deployer/clusters/' + cs_restic_cluster_name + '/hosts/' + inventory_hostname
+ '/apps/restic/generated/s3-repository-password-my-repo') }}"
Vault keys
S3 access credentials
Key: {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_cluster_name }}/hosts/{{ inventory_hostname }}/apps/restic/generated/s3-repository-access-{{ repo_name }}
{
"s3_password": "S3 application user password.",
"s3_user": "restic-<repo_name>",
"s3_host": "S3 hostname or IP.",
"s3_port": "(int) S3 port.",
"s3_bucket": "restic-<repo_name>",
"s3_access_key": "S3 access key.",
"s3_secret_key": "S3 secret key."
}
Repository password
Key: {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_cluster_name }}/hosts/{{ inventory_hostname }}/apps/restic/generated/s3-repository-password-{{ repo_name }}
{
"repository_password": "Restic repository encryption password."
}