feat(devicebackup): UrBackup for the Windows laptops, Time Machine staging for the Macs
Deploy Caddyfile to valhalla / deploy (push) Successful in 1m42s

New devicebackup stack: UrBackup 2.5.x (pinned, watchtower off) in internet
mode on :55415 so laptops back up on the LAN and over the tailnet; web UI
only via Caddy + Authentik forward_auth (provider homelab-urbackup, pk 41).

MacBooks (tm-hub, tm-wif) use Time Machine on the host smbd, which already
owns :445. Shares are staged in /etc/samba/smb.conf.timemachine-pending and
not yet applied; README has the apply command and client setup.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
ginnoirandClaude Opus 5.5 committed 2026-10-01 12:45:32 -05:00
1 parent 1028bc3a74
commit a55cfd2b35
5 files changed
+169 -5

No files matched your search

+32
View File
@@ -0,0 +1,32 @@
# devicebackup stack — full backups of the household laptops onto valhalla.
#
# Windows laptops → UrBackup (this stack): incremental disk images, bare-metal restore.
# MacBooks → Time Machine over the HOST smbd (not in compose — host already owns
# :445, see README.md for the smb.conf shares).
#
# Clients run in UrBackup "internet mode" against urbackup.ginnoir.com:55415, which resolves
# to valhalla on the LAN and over the tailnet, so laptops keep backing up away from home.
# The web UI (55414) is only reachable through Caddy + Authentik forward_auth.
#
# Not part of the Kopia → B2 offsite set (stacks/backup) — this is copy #2 of each laptop.
services:
urbackup:
container_name: urbackup
image: uroni/urbackup-server:2.5.x
restart: unless-stopped
labels:
- "com.centurylabs.watchtower.enable=false"
networks: [edge]
env_file:
- stack.env
volumes:
- /config/urbackup:/var/urbackup
- /storage1/labdata/urbackup:/backups
ports:
- "55415:55415" # internet-mode clients (LAN + tailnet)
networks:
edge:
name: edge
external: true