BorgBackup with systemd Timers: Deduplicated, Encrypted - 夜莺博客

BorgBackup with systemd Timers: Deduplicated, Encrypted

BorgBackup halves the storage cost of backups by de-duplicating content-addressed chunks and encrypts everything client-side before it leaves the host. Its distinguishing feature against alternatives is the append-only repository model: a compromised server can push new archives to the backup server but cannot delete existing ones, which is exactly the property you want against ransomware. This guide sets up a repository, the retention policy that keeps it from growing forever, and systemd units that actually run.

Initialise the repository

sudo apt-get install borgbackup
export BORG_REPO=/mnt/backup/borg-repo
export BORG_PASSPHRASE='use-a-vault-backed-secret'

borg init --encryption=repokey-blake2 "$BORG_REPO"
borg list "$BORG_REPO"

repokey-blake2 keeps the key in the repository while still requiring the passphrase, and gives authenticated AES-256 encryption. For the strongest posture use keyfile-blake2 and store the key file separately - and remember that losing the passphrase plus key means the data is unrecoverable by design.

Append-only remote repository

# server side, ~backup/.ssh/authorized_keys
command="borg serve --append-only --restrict-to-repository /var/borg/host-01",restrict ssh-ed25519 AAAA... host01

# client side
borg init --encryption=repokey-blake2 ssh://backup@10.0.9.20/var/borg/host-01

With this restriction, borg delete and borg prune fail from the protected host. Retention is then enforced from a separate trusted account with an unrestricted key - a different key pair, on a different schedule.

Backup, prune and compact

borg create --stats --compression lz4   "$BORG_REPO::$(hostname)-{now:%Y-%m-%dT%H:%M:%S}"   /etc /home /var/lib /opt   --exclude '*.log' --exclude '/home/*/.cache' --exclude '/var/cache/*'

borg prune --list --glob-archives "$(hostname)-*"   --keep-daily 7 --keep-weekly 4 --keep-monthly 6 --keep-yearly 2 "$BORG_REPO"

borg compact "$BORG_REPO"     # Borg 1.2+: required to actually free space

Prune only marks archives as removable; without borg compact the repository keeps consuming disk and the monitoring graph looks broken. Run the three commands as one unit so they cannot drift apart.

systemd service and timer

# /etc/systemd/system/borg-backup.service
[Unit]
Description=BorgBackup daily backup
After=network-online.target
Wants=network-online.target

[Service]
Type=oneshot
User=root
EnvironmentFile=/etc/borg/backup.env
ExecStart=/usr/local/bin/borg-backup.sh
NoNewPrivileges=yes
PrivateTmp=yes

# /etc/systemd/system/borg-backup.timer
[Unit]
Description=Run BorgBackup daily
[Timer]
OnCalendar=*-*-* 02:30:00
RandomizedDelaySec=30min
Persistent=true
[Install]
WantedBy=timers.target

Persistent=true is the reason to prefer timers over cron: a run missed because the host was down executes at next boot. RandomizedDelaySec prevents every server in the fleet from hitting the backup target at the same second.

Verify, do not assume

  • borg info - watch "Storage size" against the volume of data protected; that ratio is what dedup actually bought you.
  • borg check --verify-data monthly - data-level integrity, not just repository metadata.
  • systemctl list-timers 'borg*' and journalctl -u borg-backup.service --since=yesterday - the run happened and exited cleanly.
  • Restore a file at least once a quarter; a backup you have never restored is a hypothesis. Storage-side verification such as ZFS Send and Receive: Snapshot Replication Guide complements this but does not replace it.

Related reading on this site: ZFS Send and Receive: Snapshot Replication Guide and restic Backup Retention: forget, prune and S3 Repos.

原文链接:https://linuxjunkies.org/guides/back-up-with-borg-or-restic