Phase 0.5: Aegis appdata + /boot/config backup to luna-pbs #61
No reviewers
Labels
No labels
blocked
borg-backup
ceph
forgejo
in-progress
infra
netdata
nextcloud
p:high
p:low
p:medium
searxng
service-onboard
swarm-nodes
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
copper/ccnet-prod-devops!61
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "worktree-phase-0.5-appdata-pbs-backup"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds
ccnet-unraid-appdata-pbs-backup/— a Docker-packagedproxmox-backup-clientfor UnraidAegis, closing the appdata/boot-config backup gap left whenccnet-borg-backupwas retired (2026-08-16). Prerequisite for the*arrmedia stack (issue #59).What's here
Dockerfile—debian:trixie-slim+ Proxmoxpbs-clientapt repo (same keyring/suite asccnet-pbs-backup-swarm-data/pbs-backup.yml), pinnedproxmox-backup-clientversion, built on Aegis.backup.sh— oneproxmox-backup-client backupper run:primary→appdata.pxar+bootconfig.pxar,--backup-id aegis,--exclude /pbs-backup(keeps the reused PVE encryption key out of a snapshot it encrypts)cold→appdata-cold.pxar, separate--backup-id aegis-appdata-coldso no backup group has a varying archive setpbs-browse.sh— read-onlylist/files/mount/restorehelper (entrypoint override).user-scripts/— two User Scripts cron payloads (daily 03:30 primary, Sunday 02:45 cold), notify-on-failure.keys/— only.exampletemplates tracked; real key + token-secret are hand-placed in/boot/config/pbs-backup/on Aegis and gitignored.CLAUDE.md— new Map entry.Reuses the existing PVE encryption key and inherits prune/GC/verify/offsite-sync from the
copperparent namespace on luna-pbs — nothing new to create server-side beyond the namespace + token + ACL.Not done in this PR (user-gated — credentials must not pass through an automated session)
copper/aegis-appdata, generate tokencoppercore@pbs!aegis-appdata-backup, grant bothDatastoreBackup+DatastoreAuditencryption-key.json+token-secret, firstdocker build(pin the version), install the User Scripts, configure CA Appdata Backup*arrcontainers🤖 Generated with Claude Code