Files
ginnoirandClaude Opus 5.5 be835cad90 feat(devicebackup): run the guestmount urbackup image with kvm + fuse
Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 13:17:57 -05:00
..

devicebackup stack

Full backups of the household laptops onto valhalla.

Device Disk Tool Cap
Windows laptop A 1 TB UrBackup image backups shared 3.5 TB soft quota
Windows laptop B 512 GB UrBackup image backups (same)
MacBook (hub) 1 TB Time Machine → tm-hub share 1.5 TB
MacBook (wif) 1 TB Time Machine → tm-wif share 1.5 TB

Worst case (every disk full) that's ~6.5 TB on storage1. It had 16 TB free on 2026-10-01 (84% used); keep an eye on pool fill, since ZFS slows down past ~90%.

storage1 has no redundancy. Treat this as the second copy of each laptop, not the only one, until the mirror rebuild is done.

Windows: UrBackup

Before first deploy (host)

sudo install -d -o ginnoir -g ginnoir /config/urbackup /storage1/labdata/urbackup

Register a new Portainer git stack → stacks/devicebackup (one-time), then push.

Server settings (web UI → Settings)

  • General → Server: backup storage path /backups.
  • General → Internet: enable internet mode, server name urbackup.ginnoir.com, port 55415; tick "Do image backups over internet" and "Do full file backups over internet".
  • General → Soft filesystem quota: 3500G.
  • Client defaults → Image backups: incremental every 1 day, full every 30 days; keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes ALL_NONUSB (with ESP).
  • Client defaults → File backups: off. Single-file restores come from mounting an image in the web UI, which needs guestmount; the stock image lacks it, so this stack runs a custom build (urbackup/Dockerfile) with /dev/kvm + /dev/fuse.
  • Applied 2026-10-01 via the web API (/x?a=settings, sa=general_save). These settings live in /config/urbackup, not in this repo.
  • Leave UrBackup with no admin user: auth is Authentik forward_auth at Caddy, and 55414 is not published. Adding a UrBackup user just means logging in twice.

Each Windows laptop

  1. Web UI → Add client → Internet/active client, name it, and download the per-client installer (it embeds the server address + auth key).
  2. Run it on the laptop. The first full image takes a long time on Wi-Fi, so do it at home, plugged in.
  3. Make the restore USB: download the UrBackup restore ISO and keep a stick around. A bare-metal restore boots it, connects to the server on the LAN, and writes the image back.
  4. BitLocker: images contain the decrypted volume. The data is protected only by valhalla's own security.

macOS: Time Machine (host smbd)

Host smbd already serves [storage1] on :445, so Time Machine goes on the host Samba rather than a container (Macs handle SMB on a non-standard port poorly). This config is host-managed, not deployed from this repo. Keep this section in sync with /etc/samba/smb.conf.

Add to [global] (fruit has to be global, because macOS negotiates the AAPL extensions on the first tree connect):

	vfs objects = catia fruit streams_xattr
	fruit:metadata = stream
	fruit:model = MacSamba
	fruit:posix_rename = yes
	fruit:veto_appledouble = no
	fruit:nfs_aces = no
	fruit:wipe_intentionally_left_blank_rfork = yes
	fruit:delete_empty_adfiles = yes

One share per Mac, so each Mac gets its own 1.5 TB cap:

[tm-hub]
	path = /storage1/labdata/timemachine/hub
	valid users = timemachine
	read only = No
	fruit:time machine = yes
	fruit:time machine max size = 1500G

[tm-wif]
	path = /storage1/labdata/timemachine/wif
	valid users = timemachine
	read only = No
	fruit:time machine = yes
	fruit:time machine max size = 1500G

Done on 2026-10-01: timemachine user + Samba password (password is in stack.env), and /storage1/labdata/timemachine/{hub,wif} (owned by timemachine, mode 0700).

The full target config is staged at /etc/samba/smb.conf.timemachine-pending, already testparm-validated. It is not live yet, because smbd re-reads smb.conf automatically whenever the file changes. Apply it when nothing is mid-copy on [storage1]:

sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak-$(date +%F) && sudo mv /etc/samba/smb.conf.timemachine-pending /etc/samba/smb.conf && sudo systemctl reload smb

Samba registers the shares with avahi (already running), so on the LAN they show up directly in System Settings → General → Time Machine → Add Backup Disk. Pick the share, enter the timemachine credentials, and turn on "Encrypt backup". Away from home, Bonjour doesn't cross Tailscale, and valhalla has no MagicDNS name (the tailnet reaches it via the subnet route), so when re-adding remotely use the LAN IP:

sudo tmutil setdestination -a "smb://timemachine@192.168.1.69/tm-hub"

Verify

  • Each Windows laptop: one full image completes, then mount it in the UrBackup UI and open a file.
  • Each Mac: first backup completes, then Enter Time Machine and restore one file.
  • Uptime Kuma: HTTP monitor on https://urbackup.ginnoir.com, TCP monitor on valhalla:55415.