Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
114 lines
5.0 KiB
Markdown
114 lines
5.0 KiB
Markdown
# devicebackup stack
|
|
|
|
Full backups of the household laptops onto valhalla.
|
|
|
|
| Device | Disk | Tool | Cap |
|
|
|---|---|---|---|
|
|
| Windows laptop A | 1 TB | UrBackup image backups | shared 3.5 TB soft quota |
|
|
| Windows laptop B | 512 GB | UrBackup image backups | (same) |
|
|
| MacBook (hub) | 1 TB | Time Machine → `tm-hub` share | 1.5 TB |
|
|
| MacBook (wif) | 1 TB | Time Machine → `tm-wif` share | 1.5 TB |
|
|
|
|
Worst case (every disk full) that's ~6.5 TB on `storage1`. It had 16 TB free on 2026-10-01
|
|
(84% used); keep an eye on pool fill, since ZFS slows down past ~90%.
|
|
|
|
**storage1 has no redundancy.** Treat this as the *second* copy of each laptop, not the only one,
|
|
until the mirror rebuild is done.
|
|
|
|
## Windows: UrBackup
|
|
|
|
### Before first deploy (host)
|
|
|
|
```bash
|
|
sudo install -d -o ginnoir -g ginnoir /config/urbackup /storage1/labdata/urbackup
|
|
```
|
|
|
|
Register a new Portainer git stack → `stacks/devicebackup` (one-time), then push.
|
|
|
|
### Server settings (web UI → Settings)
|
|
|
|
- **General → Server:** backup storage path `/backups`.
|
|
- **General → Internet:** enable internet mode, server name `urbackup.ginnoir.com`, port `55415`;
|
|
tick **"Do image backups over internet"** and **"Do full file backups over internet"**.
|
|
- **General → Soft filesystem quota:** `3500G`.
|
|
- **Client defaults → Image backups:** incremental every 1 day, full every 30 days;
|
|
keep min 2 / max 4 full images, min 7 / max 30 incrementals. Volumes `ALL_NONUSB` (with ESP).
|
|
- **Client defaults → File backups:** off. Single-file restores come from mounting an image in the web UI, which needs guestmount; the stock image lacks it, so this stack runs a custom build (`urbackup/Dockerfile`) with `/dev/kvm` + `/dev/fuse`.
|
|
- **Applied 2026-10-01** via the web API (`/x?a=settings`, `sa=general_save`). These settings live in `/config/urbackup`, not in this repo.
|
|
- Leave UrBackup with **no admin user**: auth is Authentik forward_auth at Caddy, and 55414 is not
|
|
published. Adding a UrBackup user just means logging in twice.
|
|
|
|
### Each Windows laptop
|
|
|
|
1. Web UI → **Add client → Internet/active client**, name it, and download the per-client installer
|
|
(it embeds the server address + auth key).
|
|
2. Run it on the laptop. The first full image takes a long time on Wi-Fi, so do it at home, plugged in.
|
|
3. **Make the restore USB:** download the UrBackup restore ISO and keep a stick around. A bare-metal
|
|
restore boots it, connects to the server on the LAN, and writes the image back.
|
|
4. BitLocker: images contain the *decrypted* volume. The data is protected only by valhalla's own security.
|
|
|
|
## macOS: Time Machine (host smbd)
|
|
|
|
Host `smbd` already serves `[storage1]` on :445, so Time Machine goes on the host Samba rather than
|
|
a container (Macs handle SMB on a non-standard port poorly). This config is **host-managed**, not
|
|
deployed from this repo. Keep this section in sync with `/etc/samba/smb.conf`.
|
|
|
|
Add to `[global]` (fruit has to be global, because macOS negotiates the AAPL extensions on the
|
|
first tree connect):
|
|
|
|
```ini
|
|
vfs objects = catia fruit streams_xattr
|
|
fruit:metadata = stream
|
|
fruit:model = MacSamba
|
|
fruit:posix_rename = yes
|
|
fruit:veto_appledouble = no
|
|
fruit:nfs_aces = no
|
|
fruit:wipe_intentionally_left_blank_rfork = yes
|
|
fruit:delete_empty_adfiles = yes
|
|
```
|
|
|
|
One share per Mac, so each Mac gets its own 1.5 TB cap:
|
|
|
|
```ini
|
|
[tm-hub]
|
|
path = /storage1/labdata/timemachine/hub
|
|
valid users = timemachine
|
|
read only = No
|
|
fruit:time machine = yes
|
|
fruit:time machine max size = 1500G
|
|
|
|
[tm-wif]
|
|
path = /storage1/labdata/timemachine/wif
|
|
valid users = timemachine
|
|
read only = No
|
|
fruit:time machine = yes
|
|
fruit:time machine max size = 1500G
|
|
```
|
|
|
|
Done on 2026-10-01: `timemachine` user + Samba password (password is in `stack.env`), and
|
|
`/storage1/labdata/timemachine/{hub,wif}` (owned by `timemachine`, mode 0700).
|
|
|
|
The full target config is **staged** at `/etc/samba/smb.conf.timemachine-pending`, already
|
|
`testparm`-validated. It is *not* live yet, because smbd re-reads `smb.conf` automatically
|
|
whenever the file changes. Apply it when nothing is mid-copy on `[storage1]`:
|
|
|
|
```bash
|
|
sudo cp /etc/samba/smb.conf /etc/samba/smb.conf.bak-$(date +%F) && sudo mv /etc/samba/smb.conf.timemachine-pending /etc/samba/smb.conf && sudo systemctl reload smb
|
|
```
|
|
|
|
Samba registers the shares with avahi (already running), so on the LAN they show up directly in
|
|
**System Settings → General → Time Machine → Add Backup Disk**. Pick the share, enter the
|
|
`timemachine` credentials, and **turn on "Encrypt backup"**. Away from home, Bonjour doesn't cross
|
|
Tailscale, and valhalla has no MagicDNS name (the tailnet reaches it via the subnet route), so
|
|
when re-adding remotely use the LAN IP:
|
|
|
|
```bash
|
|
sudo tmutil setdestination -a "smb://timemachine@192.168.1.69/tm-hub"
|
|
```
|
|
|
|
## Verify
|
|
|
|
- [ ] Each Windows laptop: one full image completes, then **mount it in the UrBackup UI and open a file**.
|
|
- [ ] Each Mac: first backup completes, then **Enter Time Machine and restore one file**.
|
|
- [ ] Uptime Kuma: HTTP monitor on `https://urbackup.ginnoir.com`, TCP monitor on `valhalla:55415`.
|