feat(devicebackup): run the guestmount urbackup image with kvm + fuse

Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
ginnoirandClaude Opus 5.5 committed 2026-10-01 13:17:57 -05:00
1 parent 3615c9b3d8
commit be835cad90
2 files changed
+14 -2

No files matched your search

+2 -1
View File
@@ -33,7 +33,8 @@ Register a new Portainer git stack → `stacks/devicebackup` (one-time), then pu
- **General → Soft filesystem quota:** `3500G`. - **General → Soft filesystem quota:** `3500G`.
- **Client defaults → Image backups:** incremental every 1 day, full every 30 days; - **Client defaults → Image backups:** incremental every 1 day, full every 30 days;
keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes `ALL_NONUSB` (with ESP). keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes `ALL_NONUSB` (with ESP).
- **Client defaults → File backups:** off (images are browsable and mountable for single-file restores). - **Client defaults → File backups:** off. Single-file restores come from mounting an image in the web UI, which needs guestmount; the stock image lacks it, so this stack runs a custom build (`urbackup/Dockerfile`) with `/dev/kvm` + `/dev/fuse`.
- **Applied 2026-10-01** via the web API (`/x?a=settings`, `sa=general_save`). These settings live in `/config/urbackup`, not in this repo.
- Leave UrBackup with **no admin user**: auth is Authentik forward_auth at Caddy, and 55414 is not - Leave UrBackup with **no admin user**: auth is Authentik forward_auth at Caddy, and 55414 is not
published. Adding a UrBackup user just means logging in twice. published. Adding a UrBackup user just means logging in twice.
+12 -1
View File
@@ -13,13 +13,24 @@
services: services:
urbackup: urbackup:
container_name: urbackup container_name: urbackup
image: uroni/urbackup-server:2.5.x # uroni/urbackup-server:2.5.x + libguestfs (guestmount) so image backups can be
# mounted for single-file restores. Built from urbackup/Dockerfile by
# .gitea/workflows/build-urbackup-server.yml.
image: registry.ginnoir.com/ginnoir/urbackup-server:latest
restart: unless-stopped restart: unless-stopped
labels: labels:
- "com.centurylabs.watchtower.enable=false" - "com.centurylabs.watchtower.enable=false"
networks: [edge] networks: [edge]
env_file: env_file:
- stack.env - stack.env
# guestmount boots a small KVM appliance and exposes the image over FUSE.
devices:
- /dev/fuse:/dev/fuse
- /dev/kvm:/dev/kvm
cap_add:
- SYS_ADMIN
security_opt:
- apparmor:unconfined
volumes: volumes:
- /config/urbackup:/var/urbackup - /config/urbackup:/var/urbackup
- /storage1/labdata/urbackup:/backups - /storage1/labdata/urbackup:/backups