Switch the urbackup service to registry.ginnoir.com/ginnoir/urbackup-server
(built in 3615c9b) and pass /dev/fuse, /dev/kvm and SYS_ADMIN so the server
enables image mounting for single-file restores.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
44 lines
1.6 KiB
YAML
44 lines
1.6 KiB
YAML
# devicebackup stack — full backups of the household laptops onto valhalla.
|
|
#
|
|
# Windows laptops → UrBackup (this stack): incremental disk images, bare-metal restore.
|
|
# MacBooks → Time Machine over the HOST smbd (not in compose — host already owns
|
|
# :445, see README.md for the smb.conf shares).
|
|
#
|
|
# Clients run in UrBackup "internet mode" against urbackup.ginnoir.com:55415, which resolves
|
|
# to valhalla on the LAN and over the tailnet, so laptops keep backing up away from home.
|
|
# The web UI (55414) is only reachable through Caddy + Authentik forward_auth.
|
|
#
|
|
# Not part of the Kopia → B2 offsite set (stacks/backup) — this is copy #2 of each laptop.
|
|
|
|
services:
|
|
urbackup:
|
|
container_name: urbackup
|
|
# uroni/urbackup-server:2.5.x + libguestfs (guestmount) so image backups can be
|
|
# mounted for single-file restores. Built from urbackup/Dockerfile by
|
|
# .gitea/workflows/build-urbackup-server.yml.
|
|
image: registry.ginnoir.com/ginnoir/urbackup-server:latest
|
|
restart: unless-stopped
|
|
labels:
|
|
- "com.centurylabs.watchtower.enable=false"
|
|
networks: [edge]
|
|
env_file:
|
|
- stack.env
|
|
# guestmount boots a small KVM appliance and exposes the image over FUSE.
|
|
devices:
|
|
- /dev/fuse:/dev/fuse
|
|
- /dev/kvm:/dev/kvm
|
|
cap_add:
|
|
- SYS_ADMIN
|
|
security_opt:
|
|
- apparmor:unconfined
|
|
volumes:
|
|
- /config/urbackup:/var/urbackup
|
|
- /storage1/labdata/urbackup:/backups
|
|
ports:
|
|
- "55415:55415" # internet-mode clients (LAN + tailnet)
|
|
|
|
networks:
|
|
edge:
|
|
name: edge
|
|
external: true
|