diff --git a/hosts/glyph/default.nix b/hosts/glyph/default.nix index 1a6864eb..f5a29752 100644 --- a/hosts/glyph/default.nix +++ b/hosts/glyph/default.nix @@ -1,9 +1,4 @@ -{ - config, - lib, - pkgs, - ... -}: { +{...}: { imports = [ ./hardware.nix ./services @@ -56,5 +51,8 @@ time.timeZone = "America/Los_Angeles"; i18n.defaultLocale = "en_US.UTF-8"; + # Beets library database (beets configured in home-manager) + rc.backup.paths = ["/home/mu/.config/beets/library.db"]; + system.stateVersion = "24.05"; } diff --git a/hosts/glyph/services/default.nix b/hosts/glyph/services/default.nix index 01df5392..1f8ea9ea 100644 --- a/hosts/glyph/services/default.nix +++ b/hosts/glyph/services/default.nix @@ -73,6 +73,13 @@ }; services.basic-memory.enable = true; + rc.backup = { + enable = true; + paths = [ + "/var/lib/basic-memory" + "/var/lib/roon-server/backup" + ]; + }; services.mcp-nixos.enable = true; services.kagi-mcp = { enable = true; diff --git a/hosts/spore/backup.nix b/hosts/spore/backup.nix index 54b79073..381ff47b 100644 --- a/hosts/spore/backup.nix +++ b/hosts/spore/backup.nix @@ -1,27 +1,8 @@ -{ - config, - pkgs, - ... -}: { - age.secrets.restic-env.file = ./secrets/restic-env.age; - age.secrets.restic-password.file = ./secrets/restic-password.age; - services.restic.backups = { - daily = { - initialize = true; - - environmentFile = config.age.secrets.restic-env.path; - passwordFile = config.age.secrets.restic-password.path; - - repository = "s3:https://9c12166db465350c0f02410b390d0cbc.r2.cloudflarestorage.com/restic"; - paths = [ - config.services.postgresqlBackup.location - ]; - - pruneOpts = [ - "--keep-daily 7" - "--keep-weekly 5" - "--keep-monthly 12" - ]; - }; +{config, ...}: { + rc.backup = { + enable = true; + paths = [ + config.services.postgresqlBackup.location + ]; }; } diff --git a/hosts/spore/secrets/restic-env.age b/hosts/spore/secrets/restic-env.age deleted file mode 100644 index 5075587d..00000000 --- a/hosts/spore/secrets/restic-env.age +++ /dev/null @@ -1,7 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 2AxgaQ Es67hHdqNVSsIR+CsvLVGwfMxzck2MQ+6EToCefFxSU -Ak5UE+60lcx074UtIaxiDF9f8OhJAtOmmPmNkF6eqH0 --> ssh-ed25519 3EWhnQ IGHbBiKo+RHqioWNyVls+wyCS4ZfWRDuSLrxW/RISgc -dkn0WqBZLkDM3m3a8pdt3gR4jhieerUSPGOGvuvhYyE ---- BLYnA/KzBHV1wqkiyt4DAgfuSR2PSse3AZsYG2lkSVg -ILlü?Ê{Ž;0uÊòËšÖRËÎ� ¤Æ„!wR?î¿Oѧõ{Wb ¶¡9_ˆ®ò\’¥ÅmŸ¤}y?[.ÌÕ�µ<<€°Êíü?ŸQU·«ôgíñûäö’gv”"îûŒj Õ¸è'õ7ŽqòÈêÝ$ñ»»*Ö,S‰i‹¥²JeWïÃ=-NºjhQÂ!ñ€¯€¦æ{\NA5—�ÿQ‘Cní ²ê/ \ No newline at end of file diff --git a/hosts/spore/secrets/restic-password.age b/hosts/spore/secrets/restic-password.age deleted file mode 100644 index 69b76026..00000000 --- a/hosts/spore/secrets/restic-password.age +++ /dev/null @@ -1,8 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 2AxgaQ Fn3wMjiq3SNG6+zQ3UIcWvkCXR7/3dV4DFl3MiPi2XQ -pNnalVQSPAdghbNSLqFcKGNCpKTKpIivRInycB3NSeU --> ssh-ed25519 3EWhnQ 0VH0W2g6bmcT1vS8mmxGl2iLsBH8zOcEHmEx8TFX1S0 -92DM1pAuSRRJkARK7/Yv07QRqQD5KgN3yl1fYrnEaa4 ---- 5YlEepY3T7K68HHfCbtI9QdYwZRecpfOGrI26hWgEMc -4 -¦0dÐM7‹ƒµ´ÂhŒ�1œ/B¼ŽÚK½ú�ÿJ‡Õ—o’H¢gñ–R+º‘Y5�…½T›ÏlUÊ_?u \ No newline at end of file diff --git a/lib/secrets/default.nix b/lib/secrets/default.nix index 6e135138..d98e78ec 100644 --- a/lib/secrets/default.nix +++ b/lib/secrets/default.nix @@ -1,3 +1,7 @@ # Global secrets that multiple hosts need access to -# Currently empty - all secrets are host-specific -{} +let + keys = with (import ../keys.nix); [glyph spore Rhizome]; +in { + "secrets/restic-env.age".publicKeys = keys; + "secrets/restic-password.age".publicKeys = keys; +} diff --git a/lib/secrets/spore.nix b/lib/secrets/spore.nix index a9335320..c1814d85 100644 --- a/lib/secrets/spore.nix +++ b/lib/secrets/spore.nix @@ -12,7 +12,5 @@ in { "hosts/spore/secrets/notifier-smtp-password.age".publicKeys = keys; "hosts/spore/secrets/oauth2-proxy-env.age".publicKeys = keys; "hosts/spore/secrets/pocket-id-encryption-key.age".publicKeys = keys; - "hosts/spore/secrets/restic-env.age".publicKeys = keys; - "hosts/spore/secrets/restic-password.age".publicKeys = keys; "hosts/spore/secrets/tailscale-auth-key.age".publicKeys = keys; } diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index dedc1b46..6486c9c3 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -4,6 +4,7 @@ ./llm ./web ./filebrowser-quantum.nix + ./restic-backup.nix ./users.nix ./ssh.nix ./sudo.nix diff --git a/modules/nixos/restic-backup.nix b/modules/nixos/restic-backup.nix new file mode 100644 index 00000000..471eeddf --- /dev/null +++ b/modules/nixos/restic-backup.nix @@ -0,0 +1,42 @@ +{ + config, + lib, + ... +}: let + cfg = config.rc.backup; +in { + options.rc.backup = { + enable = lib.mkEnableOption "restic backup to Cloudflare R2"; + + paths = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = []; + description = "Paths to back up."; + }; + + pruneOpts = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ + "--keep-daily 7" + "--keep-weekly 5" + "--keep-monthly 12" + ]; + description = "Prune options for restic forget."; + }; + }; + + config = lib.mkIf cfg.enable { + age.secrets.restic-env.file = ../../secrets/restic-env.age; + age.secrets.restic-password.file = ../../secrets/restic-password.age; + + services.restic.backups.daily = { + initialize = true; + + environmentFile = config.age.secrets.restic-env.path; + passwordFile = config.age.secrets.restic-password.path; + + repository = "s3:https://9c12166db465350c0f02410b390d0cbc.r2.cloudflarestorage.com/restic"; + inherit (cfg) paths pruneOpts; + }; + }; +} diff --git a/secrets/restic-env.age b/secrets/restic-env.age new file mode 100644 index 00000000..9ed051be Binary files /dev/null and b/secrets/restic-env.age differ diff --git a/secrets/restic-password.age b/secrets/restic-password.age new file mode 100644 index 00000000..151e7c42 --- /dev/null +++ b/secrets/restic-password.age @@ -0,0 +1,9 @@ +age-encryption.org/v1 +-> ssh-ed25519 rSr+rA Z+9XxNGsbQouTkhq32ZBlkFYokGsmUCMLHeR5sP9tWk +qB/oBmbxbEFBAuSBhbpnD6eIUWTm6/c7fGiYQ/xKotI +-> ssh-ed25519 2AxgaQ qoh952wnvfuC5n+/SSsinOkCvKd54VHjpX88hOwzRwc +Be2yGLfBjsu+Cb2GBFmcXqk7G85WUGkepbY0aF3H8yI +-> ssh-ed25519 3EWhnQ cM+TTJ/BW6tb3XjbslHn+LF5wsMEcq/DY6hlwdVBGyk +Mr94UI7pJor2uQAuFP/8bBs8fcV9+LcIXV0iT5f92Hg +--- OFrrfEub5HYBAoHsGi38coK2Jw3qrDyl3sg1gIYYT3c +(–Ã>¶¥�íÊ|’Hp80k3Ô2!Ö¼DgЬ?5êÛ¨ÙÈ3òeA(¯v«,O’[dù“4@bí�¿ßŽ \ No newline at end of file