Sign inSign up

zsdima/ghost-backup

By zsdima

•Updated 8 months ago

MySQL Restic Backup - one-shot backup job that runs `mysqldump`, streams it through gzip to restic.

Image
0

2.4K

zsdima/ghost-backup repository overview

⁠MySQL Restic Backup

Containerized, one-shot backup job that runs mysqldump, streams it through gzip to restic, optionally backs up extra paths, then exits.

⁠Run (Docker)

docker run --rm --name mysql-backup \
  --tmpfs /tmp:mode=1777,size=256m \
  --network <mysql-network> \
  -e RESTIC_REPOSITORY='s3:https://HOST/BUCKET/PREFIX' \
  -e RESTIC_PASSWORD_FILE=/run/secrets/restic_password \
  -e MYSQL_HOST=<mysql-host> \
  -e MYSQL_USER=<mysql-user> \
  -e MYSQL_DATABASE=<mysql-db> \
  -e MYSQL_PASSWORD_FILE=/run/secrets/mysql_password \
  -v /path/to/restic_password:/run/secrets/restic_password:ro \
  -v /path/to/mysql_password:/run/secrets/mysql_password:ro \
  zsdima/ghost-backup:latest

Use *_FILE for secrets. Supported: RESTIC_PASSWORD, MYSQL_PASSWORD, S3_ACCESS_KEY, S3_SECRET_KEY, S3_SESSION_TOKEN, BACKUP_PATHS.

⁠Env vars

VarRequiredDefaultDescription
RESTIC_REPOSITORYyes—Restic repo URL (e.g. s3:https://HOST/BUCKET/PREFIX).
RESTIC_PASSWORD / RESTIC_PASSWORD_FILEyes—Restic repository password (value or file).
MYSQL_HOSTyes—MySQL host to connect to.
MYSQL_USERyes—MySQL user for dump.
MYSQL_DATABASEyes—MySQL database name.
RESTIC_HOSTNAME / RESTIC_HOSTconditional—Backup host label; required if hostname can’t be determined.
MYSQL_PORTno3306MySQL port.
MYSQL_PASSWORD / MYSQL_PASSWORD_FILEno—MySQL password (value or file).
MYSQL_WAIT_SECONDSno60Max time to wait for MySQL.
MYSQL_WAIT_INTERVAL_SECONDSno5Wait interval between pings.
MYSQL_PLUGIN_DIRno/usr/lib/mariadb/pluginMySQL auth plugin dir.
MYSQL_CLIENT_EXTRA_ARGSno—Extra args for mariadb-admin/client.
MYSQLDUMP_BINnoautoPath to mariadb-dump/mysqldump.
MYSQLDUMP_ARGSnosafe defaultsExtra args for dump command.
TMPDIRno/tmpTemp dir for FIFO and restic.
BACKUP_PATHS / BACKUP_PATHS_FILEno—Comma‑separated extra paths to back up.
RESTIC_TAGSno—Comma‑separated user tags.
RESTIC_EXTRA_ARGSno—Extra args for restic backup.
RESTIC_ONE_FILE_SYSTEMnofalseAdd --one-file-system.
RESTIC_FORGET_ARGSnodefaultsOverrides retention policy.
RESTIC_CHECK_READ_DATA_SUBSETno—Enable restic check with subset.
SKIP_INITnofalseSkip restic init.
SKIP_FORGETnofalseSkip retention step.
SKIP_CHECKnofalseSkip restic check.
S3_ACCESS_KEY / S3_SECRET_KEYno—S3 access key pair (both required if either set).
S3_SESSION_TOKENno—Optional session token.

⁠Restore

Set the same repo credentials you use for backups (RESTIC_REPOSITORY, RESTIC_PASSWORD, plus any S3/AWS env your repo needs).

Database (dump file is named <db>-<UTC timestamp>.sql.gz):

docker run --rm \
  -e RESTIC_REPOSITORY='s3:https://HOST/BUCKET/PREFIX' \
  -e RESTIC_PASSWORD='<restic-password>' \
  --entrypoint /usr/local/bin/restic \
  zsdima/ghost-backup:latest snapshots --tag "db:<db>"

docker run --rm \
  -e RESTIC_REPOSITORY='s3:https://HOST/BUCKET/PREFIX' \
  -e RESTIC_PASSWORD='<restic-password>' \
  --entrypoint /usr/local/bin/restic \
  zsdima/ghost-backup:latest dump <snapshot-id> '<db>-<timestamp>.sql.gz' > dump.sql.gz

gunzip -c dump.sql.gz | mysql -h <mysql-host> -u <mysql-user> -p <db>

Files:

docker run --rm \
  -e RESTIC_REPOSITORY='s3:https://HOST/BUCKET/PREFIX' \
  -e RESTIC_PASSWORD='<restic-password>' \
  --entrypoint /usr/local/bin/restic \
  zsdima/ghost-backup:latest restore <snapshot-id> --target /restore --include /path/in/backup

Tag summary

Content type

Image

Digest

sha256:d2c77af6e…

Size

17.3 MB

Last updated

8 months ago

docker pull zsdima/ghost-backup