Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5.0 KiB
devicebackup stack
Full backups of the household laptops onto valhalla.
| Device | Disk | Tool | Cap |
|---|---|---|---|
| Windows laptop A | 1 TB | UrBackup image backups | shared 3.5 TB soft quota |
| Windows laptop B | 512 GB | UrBackup image backups | (same) |
| MacBook (hub) | 1 TB | Time Machine → tm-hub share |
1.5 TB |
| MacBook (wif) | 1 TB | Time Machine → tm-wif share |
1.5 TB |
Worst case (every disk full) that's ~6.5 TB on storage1. It had 16 TB free on 2026-10-01
(84% used); keep an eye on pool fill, since ZFS slows down past ~90%.
storage1 has no redundancy. Treat this as the second copy of each laptop, not the only one, until the mirror rebuild is done.
Windows: UrBackup
Before first deploy (host)
sudo install -d -o ginnoir -g ginnoir /config/urbackup /storage1/labdata/urbackup
Register a new Portainer git stack → stacks/devicebackup (one-time), then push.
Server settings (web UI → Settings)
- General → Server: backup storage path
/backups. - General → Internet: enable internet mode, server name
urbackup.ginnoir.com, port55415; tick "Do image backups over internet" and "Do full file backups over internet". - General → Soft filesystem quota:
3500G. - Client defaults → Image backups: incremental every 1 day, full every 30 days;
keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes
ALL_NONUSB(with ESP). - Client defaults → File backups: off. Single-file restores come from mounting an image in the web UI, which needs guestmount; the stock image lacks it, so this stack runs a custom build (
urbackup/Dockerfile) with/dev/kvm+/dev/fuse. - Applied 2026-10-01 via the web API (
/x?a=settings,sa=general_save). These settings live in/config/urbackup, not in this repo. - Leave UrBackup with no admin user: auth is Authentik forward_auth at Caddy, and 55414 is not published. Adding a UrBackup user just means logging in twice.
Each Windows laptop
- Web UI → Add client → Internet/active client, name it, and download the per-client installer (it embeds the server address + auth key).
- Run it on the laptop. The first full image takes a long time on Wi-Fi, so do it at home, plugged in.
- Make the restore USB: download the UrBackup restore ISO and keep a stick around. A bare-metal restore boots it, connects to the server on the LAN, and writes the image back.
- BitLocker: images contain the decrypted volume. The data is protected only by valhalla's own security.
macOS: Time Machine (host smbd)
Host smbd already serves [storage1] on :445, so Time Machine goes on the host Samba rather than
a container (Macs handle SMB on a non-standard port poorly). This config is host-managed, not
deployed from this repo. Keep this section in sync with /etc/samba/smb.conf.
Add to [global] (fruit has to be global, because macOS negotiates the AAPL extensions on the
first tree connect):
vfs objects = catia fruit streams_xattr
fruit:metadata = stream
fruit:model = MacSamba
fruit:posix_rename = yes
fruit:veto_appledouble = no
fruit:nfs_aces = no
fruit:wipe_intentionally_left_blank_rfork = yes
fruit:delete_empty_adfiles = yes
One share per Mac, so each Mac gets its own 1.5 TB cap:
[tm-hub]
path = /storage1/labdata/timemachine/hub
valid users = timemachine
read only = No
fruit:time machine = yes
fruit:time machine max size = 1500G
[tm-wif]
path = /storage1/labdata/timemachine/wif
valid users = timemachine
read only = No
fruit:time machine = yes
fruit:time machine max size = 1500G
Done on 2026-10-01: timemachine user + Samba password (password is in stack.env), and
/storage1/labdata/timemachine/{hub,wif} (owned by timemachine, mode 0700).
The full target config is staged at /etc/samba/smb.conf.timemachine-pending, already
testparm-validated. It is not live yet, because smbd re-reads smb.conf automatically
whenever the file changes. Apply it when nothing is mid-copy on [storage1]:
sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak-$(date +%F) && sudo mv /etc/samba/smb.conf.timemachine-pending /etc/samba/smb.conf && sudo systemctl reload smb
Samba registers the shares with avahi (already running), so on the LAN they show up directly in
System Settings → General → Time Machine → Add Backup Disk. Pick the share, enter the
timemachine credentials, and turn on "Encrypt backup". Away from home, Bonjour doesn't cross
Tailscale, and valhalla has no MagicDNS name (the tailnet reaches it via the subnet route), so
when re-adding remotely use the LAN IP:
sudo tmutil setdestination -a "smb://timemachine@192.168.1.69/tm-hub"
Verify
- Each Windows laptop: one full image completes, then mount it in the UrBackup UI and open a file.
- Each Mac: first backup completes, then Enter Time Machine and restore one file.
- Uptime Kuma: HTTP monitor on
https://urbackup.ginnoir.com, TCP monitor onvalhalla:55415.