3 ms·
As an example, I have a program for regularly backing up directories to cloud storage (with deduplication, encryption, key management, etc. it's just a wrapper
by eeh 6y ago
As an example, I have a program for regularly backing up directories to cloud storage (with deduplication, encryption, key management, etc. it's just a wrapper around Restic), which it does regularly via cron. I manage this in NixOS: different machines backup different directories, with different keys.
This program has a CLI mode for setting up keys and buckets, which I run locally, and it writes to backup-metadata.json .
So my workflow for adding a new directory to my system is:
1. Run CLI tool to create a new bucket, new API key with access to the bucket (with just the permissions it needs), and new encryption key. This writes to my backup-metadata.json file locally.
2. write some NixOS along the lines of:
let
metadata = (builtins.fromJSON "../backup-metadata.json").git;
in {
backup = {
git = {
path = "/var/lib/git-repositories";
frequency = "hourly";
bucket = metadata.bucket;
key = metadata.key;
apiKey = metadata.apiKey;
};
};
}
3. Hit deploy. This starts the backups, and some monitoring to check the cloud storage is being regularly written to.
The implementation of "backup" is private, but reuses parts of upstream NixOS (systemd.timer, Prometheus, ...)