From be835cad908a934754cffa4f7ac9eeda49be7424 Mon Sep 17 00:00:00 2001 From: ginnoir Date: Thu, 1 Oct 2026 13:17:57 -0500 Subject: [PATCH] feat(devicebackup): run the guestmount urbackup image with kvm + fuse Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server (built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server enables image mounting for single-file restores. Co-Authored-By: Claude Opus 5.5 --- stacks/devicebackup/README.md | 3 ++- stacks/devicebackup/docker-compose.yml | 13 ++++++++++++- 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/stacks/devicebackup/README.md b/stacks/devicebackup/README.md index a235dfa..7521f81 100644 --- a/stacks/devicebackup/README.md +++ b/stacks/devicebackup/README.md @@ -33,7 +33,8 @@ Register a new Portainer git stack → `stacks/devicebackup` (one-time), then pu - **General → Soft filesystem quota:** `3500G`. - **Client defaults → Image backups:** incremental every 1 day, full every 30 days; keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes `ALL_NONUSB` (with ESP). -- **Client defaults → File backups:** off (images are browsable and mountable for single-file restores). +- **Client defaults → File backups:** off. Single-file restores come from mounting an image in the web UI, which needs guestmount; the stock image lacks it, so this stack runs a custom build (`urbackup/Dockerfile`) with `/dev/kvm` + `/dev/fuse`. +- **Applied 2026-10-01** via the web API (`/x?a=settings`, `sa=general_save`). These settings live in `/config/urbackup`, not in this repo. - Leave UrBackup with **no admin user**: auth is Authentik forward_auth at Caddy, and 55414 is not published. Adding a UrBackup user just means logging in twice. diff --git a/stacks/devicebackup/docker-compose.yml b/stacks/devicebackup/docker-compose.yml index a4b0a3d..df90e47 100644 --- a/stacks/devicebackup/docker-compose.yml +++ b/stacks/devicebackup/docker-compose.yml @@ -13,13 +13,24 @@ services: urbackup: container_name: urbackup - image: uroni/urbackup-server:2.5.x + # uroni/urbackup-server:2.5.x + libguestfs (guestmount) so image backups can be + # mounted for single-file restores. Built from urbackup/Dockerfile by + # .gitea/workflows/build-urbackup-server.yml. + image: registry.ginnoir.com/ginnoir/urbackup-server:latest restart: unless-stopped labels: - "com.centurylabs.watchtower.enable=false" networks: [edge] env_file: - stack.env + # guestmount boots a small KVM appliance and exposes the image over FUSE. + devices: + - /dev/fuse:/dev/fuse + - /dev/kvm:/dev/kvm + cap_add: + - SYS_ADMIN + security_opt: + - apparmor:unconfined volumes: - /config/urbackup:/var/urbackup - /storage1/labdata/urbackup:/backups