Files
ginnoirandClaude Opus 5.5 be835cad90 feat(devicebackup): run the guestmount urbackup image with kvm + fuse
Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 13:17:57 -05:00

44 lines
1.6 KiB
YAML

# devicebackup stack — full backups of the household laptops onto valhalla.
#
# Windows laptops → UrBackup (this stack): incremental disk images, bare-metal restore.
# MacBooks → Time Machine over the HOST smbd (not in compose — host already owns
# :445, see README.md for the smb.conf shares).
#
# Clients run in UrBackup "internet mode" against urbackup.ginnoir.com:55415, which resolves
# to valhalla on the LAN and over the tailnet, so laptops keep backing up away from home.
# The web UI (55414) is only reachable through Caddy + Authentik forward_auth.
#
# Not part of the Kopia → B2 offsite set (stacks/backup) — this is copy #2 of each laptop.
services:
urbackup:
container_name: urbackup
# uroni/urbackup-server:2.5.x + libguestfs (guestmount) so image backups can be
# mounted for single-file restores. Built from urbackup/Dockerfile by
# .gitea/workflows/build-urbackup-server.yml.
image: registry.ginnoir.com/ginnoir/urbackup-server:latest
restart: unless-stopped
labels:
- "com.centurylabs.watchtower.enable=false"
networks: [edge]
env_file:
- stack.env
# guestmount boots a small KVM appliance and exposes the image over FUSE.
devices:
- /dev/fuse:/dev/fuse
- /dev/kvm:/dev/kvm
cap_add:
- SYS_ADMIN
security_opt:
- apparmor:unconfined
volumes:
- /config/urbackup:/var/urbackup
- /storage1/labdata/urbackup:/backups
ports:
- "55415:55415" # internet-mode clients (LAN + tailnet)
networks:
edge:
name: edge
external: true