A little container I wrote to automate my Borgbackup's using the excellent Borgmatic.
It uses cron to run the backups at a time you can configure in data/borgmatic.d/crontab.txt.
To set your backup timing and configuration, you will need to create crontab.txt and your borgmatic config.yaml and mount these files into the /etc/borgmatic.d/ directory. When the container starts it creates the crontab from crontab.txt and starts crond. By cloning this repo in /opt/docker/, you will have a working setup to get started.
If using remote repositories mount your .ssh to /root/.ssh within the container.
If you want to mail the results from cron:
/etc/msmtprc[email protected]docker run \
--detach --name borgmatic \
-v /home:/mnt/source:ro \
-v /opt/docker/docker-borgmatic/data/repository:/mnt/borg-repository \
-v /opt/docker/docker-borgmatic/data/borgmatic.d:/etc/borgmatic.d/ \
-v /opt/docker/docker-borgmatic/data/.borgmatic:/root/.borgmatic \
-v /opt/docker/docker-borgmatic/data/.config/borg:/root/.config/borg \
-v /opt/docker/docker-borgmatic/data/.ssh:/root/.ssh \
-v /opt/docker/docker-borgmatic/data/.cache/borg:/root/.cache/borg \
-e TZ=Europe/Berlin \
b3vis/borgmatic
While the parameters above are sufficient for regular backups, following additional privileges will be needed to mount an archive as FUSE filesystem:
--cap-add SYS_ADMIN \
--device /dev/fuse \
--security-opt label:disable \
--security-opt apparmor:unconfined
Depending on your security system, --security-opt parameters may not be neccessary. label:disable is needed for SELinux, while apparmor:unconfined is needed for AppArmor.
To init the repo with encryption, run:
docker exec borgmatic \
sh -c "borgmatic --init --encryption repokey-blake2"
Your data you wish to backup. For some safety you may want to mount read-only. Borgmatic is running as root so all files can be backed up.
Mount your borg backup repository here.
Where you need to create crontab.txt and your borgmatic config.yml
docker exec borgmatic \
sh -c "cd && generate-borgmatic-config -d /etc/borgmatic.d/config.yaml"
0 1 * * * PATH=$PATH:/usr/bin /usr/bin/borgmatic --stats -v 0 2>&1
A non-volatile path for borgmatic to store database dumps. Only needed if you are using that feature.
Here the borg config and keys for keyfile encryption modes are stored. Make sure to backup your keyfiles! Also needed when encryption is set to none.
Mount either your own .ssh here or create a new one with ssh keys in for your remote repo locations.
A non-volatile place to store the borg chunk cache.
Time zone, e.g. TZ="Europe/Berlin"'.
SSH parameters, e.g. BORG_RSH="ssh -i /root/.ssh/id_ed25519 -p 50221"
BORG_RSH="ssh -i /root/.ssh/id_ed25519 -p 50221"
Repository passphrase, e.g. BORG_PASSPHRASE="DonNotMissToChangeYourPassphrase"
Your mail relay host MAIL_RELAY_HOST=mail.example.com
Port of your mail relay MAIL_PORT=587
Username used to log in into your relay service [email protected]
Password for relay login MAIL_PASSWORD=SuperS3cretMailPw
From part in your log mail MAIL_FROM=borgmatic
cp .env.template .envdocker-compose up -ddocker-compose downdocker-compose -f docker-compose.yml -f docker-compose.restore.yml run borgmaticborg mount /mnt/borg-repository <mount_point>borg umount <mount_point> && exit.borg break-lock /mnt/repositoryContent type
Image
Digest
Size
45.8 MB
Last updated
over 6 years ago
docker pull leoverto/borgmatic