3 ms·
I have 2 VM with Debian on Contabo in 2 datacenters in 2 different physical locations connected via VPN with Wireguard. The two servers are in sync for high ava
by Daril 2y ago
I have 2 VM with Debian on Contabo in 2 datacenters in 2 different physical locations connected via VPN with Wireguard.
The two servers are in sync for high availability : MariaDB servers are replicated in a master-master configuration, Unison keeps in sync the files.
In case one server is not available, ClouDNS automatically switches the DNS records to the other server.
I created a mesh VPN with Wireguard between the 2 VMs and my office and home serversc (Minisforum PC with Debian) (this is important for my backup and to not open external ports. The VPNs at home at office are provided by 2 Fritz!Box routers)
Just finished yesterday to re-engineering my backups as follow :
- Contabo provides 2 snapshots per VM (on my current plan), I create manually a snapshot every week (for the future I'd like to make this automatic)
- I use bot restic and borg for redundancy as follow :
-- An automysqlbackup cron job creates the encrypted data dumps every day
-- I created two bash scripts that make archives of /etc, /root (contains acme.sh ssl certificates). These archives are encrypted with my public GPG key. They are scheduled via a cron
-- The others directories I backup are /var/vmail (mail files already compressed and encrypted by vmail) and /var/www (websites and web applications), but I don't create archives of them
-- I created different repositories for : /etc, /root/, databases, vmail, sites. In case a repository or a single backup fails for every reason I don't loose everything, but only a part of the full backup
-- Restic sends the backups to iDrive e2 S3 storage : I'll replace part of the procedure using resticprofile in the near future
-- Borg sends the same backups both to home and office servers : I use borgmatic, but have different configurations, and cron jobs, for every destination, otherwise, if a backup fails on one destination, fails on both
-- If one backup fails fo every reason I receive an alert via Pushover : I'd like to substitute it with a self hosted instance of ntfy.sh
I have two additional offline external disks I sync (every week manually) with the main backup disks using rsync
Still to improve / change :
- automatic snapshots creation (via cron jobs)
- use resticprofile for restic
- use backrest to check and access the restic backups
- use Vorta to check and access the borg backups
- use self hosted ntfy.sh for notifications