Skip to main content

Restic Backup: S3 backend

Deploy a restic backup repository backed by MinIO S3. See Restic backup for the backend-agnostic overview, shared variables, and installation.

Ansible hosts group: restic​

Variables: shared​

Shared variables are documented on the Restic backup page.

Variables​

OptionTypeDescriptionDefault
cs_restic_s3_cluster_namestringName of deployed S3 cluster for restic backend{{ cs_restic_cluster_name }}
cs_restic_s3_node_namestringName of deployed S3 node for restic backend{{ inventory_hostname }}

Server-side setup (tasks/restic_setup_repositories/s3-main.yml, tasks/restic_setup_repositories/s3-repo.yml)​

For each repository defined in cs_restic_repos, the following steps are performed:

  • S3 root credentials and port are read from Vault at {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_s3_cluster_name }}/hosts/{{ cs_restic_s3_node_name }}/apps/minio-s3/config, and the S3 host from {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_s3_cluster_name }}/hosts/{{ cs_restic_s3_node_name }}.
  • A random 64-character S3 user password, 20-character access key, and 20-character secret key are generated.
  • S3 credentials are written to Vault (see Vault keys below).
  • A MinIO bucket restic-<repo_name> and user restic-<repo_name> are created via the restic_minio_bucket custom module, with the user granted access to the bucket.
  • An access key pair is created for the user via mc admin accesskey create.
  • The bucket is listed to check whether a config object already exists (confirming whether the repository is already initialized).
  • If the repository does not exist, the repository password is written to Vault and restic init is run with RESTIC_REPOSITORY=s3:https://<host>:<port>/restic-<repo_name>.
  • The repository is validated: the repository password is read back from Vault and restic snapshots --verbose is run against the repository using the generated access key pair.

Backup and restore (restic_backup_restore_s3)​

Module for performing a backup or restore operation against an S3-backed restic repository. The caller is responsible for reading S3 credentials and the repository password from Vault (see Vault keys below) and passing them to the module; the module runs the appropriate restic command, then runs restic snapshots and restic check to validate the repository once that command succeeds.

Behavior​

  • Backup: runs restic backup --verbose --host <restic_host> <local_dir> with AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY set as environment variables.
  • Restore: runs restic restore latest --verbose --target <local_dir> --host <restic_host> with the same credentials.
  • RESTIC_REPOSITORY is constructed as s3:https://<s3_host>:<s3_port>/<s3_bucket>.
  • restic snapshots --verbose and restic check --verbose run after every successful backup or restore; their output is returned in snapshots_stdout_lines / check_stdout_lines.

Example​

- name: App | Restic Backup | Backup
restic_backup_restore_s3:
ops: backup
local_dir: /var/lib/my-app
restic_host: '{{ inventory_hostname }}'
s3_host: '{{ restic_repo_access.s3_host }}'
s3_port: '{{ restic_repo_access.s3_port }}'
s3_bucket: '{{ restic_repo_access.s3_bucket }}'
s3_access_key: '{{ restic_repo_access.s3_access_key }}'
s3_secret_key: '{{ restic_repo_access.s3_secret_key }}'
repo_password: '{{ restic_repo_password.repository_password }}'
vars:
restic_repo_access: "{{ lookup('vault_kv_get',
cs_project_code + '/application-deployer/clusters/' + cs_restic_cluster_name + '/hosts/' + inventory_hostname
+ '/apps/restic/generated/s3-repository-access-my-repo') }}"
restic_repo_password: "{{ lookup('vault_kv_get',
cs_project_code + '/application-deployer/clusters/' + cs_restic_cluster_name + '/hosts/' + inventory_hostname
+ '/apps/restic/generated/s3-repository-password-my-repo') }}"

Vault keys​

S3 access credentials​

Key: {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_cluster_name }}/hosts/{{ inventory_hostname }}/apps/restic/generated/s3-repository-access-{{ repo_name }}

{
"s3_password": "S3 application user password.",
"s3_user": "restic-<repo_name>",
"s3_host": "S3 hostname or IP.",
"s3_port": "(int) S3 port.",
"s3_bucket": "restic-<repo_name>",
"s3_access_key": "S3 access key.",
"s3_secret_key": "S3 secret key."
}

Repository password​

Key: {{ cs_project_code }}/application-deployer/clusters/{{ cs_restic_cluster_name }}/hosts/{{ inventory_hostname }}/apps/restic/generated/s3-repository-password-{{ repo_name }}

{
"repository_password": "Restic repository encryption password."
}