Skip to content

feat(roles/duplicity): back up the data of all LFOps applications by default - #407

Merged
NavidSassan merged 2 commits into
mainfrom
feat/duplicity-default-sources
Oct 2, 2026
Merged

NavidSassan merged 2 commits into
mainfrom
feat/duplicity-default-sources

Conversation

@NavidSassan

Copy link
Copy Markdown
Member

Summary

The default duplicity sources only covered /backup, /etc, /home, /opt, /root, /var/lib/aide and /var/spool/cron, and no role or playbook injected further paths. Application data such as /var/lib/grafana (grafana.db), /var/lib/icinga2 (the Icinga2 CA), the Nextcloud/Moodle data in /data or the web roots in /var/www/html was not backed up.

This adds to duplicity__backup_sources__role_var:

  • /data (Nextcloud, Moodle)
  • /srv, /var/lib/shiny-server (Shiny Server)
  • /var/lib/grafana
  • /var/lib/icinga2
  • /var/lib/turn (coturn)
  • /var/mail and /var/spool/mail (both, since one of them is a symlink depending on the distribution, and duplicity only stores the link of a symlinked source path)
  • /var/named (BIND)
  • /var/solr/data
  • /var/www/html, excluding the repository mirrors github-repos and reposync-repos

duba skips paths that do not exist, so hosts without these applications are not affected. Databases stay covered by their dumps in /backup, not by their live data directories.

The setup_* playbooks do not run the duplicity role, so injecting via duplicity__backup_sources__dependent_var would have no effect; the role defaults are the only place that works. CONTRIBUTING.md now says so, so new roles extend the list.

Testing

  • Rendered duba.json with the new defaults via Ansible; a host-level state: 'absent' for /data removes the entry.
  • Not tested: a real duplicity run against the new paths, including the per-path excludes for the mirrors. The setup_basic Molecule scenario skips duplicity.

…default

Add /data, /srv, /var/lib/{grafana,icinga2,shiny-server,turn}, /var/mail,
/var/named, /var/solr/data, /var/spool/mail and /var/www/html (without the
repository mirrors) to duplicity__backup_sources__role_var. The setup_*
playbooks do not run duplicity, so a __dependent_var injection would have
no effect; the role defaults are the only place that works.

Document the rule in CONTRIBUTING.md so new roles extend the list.
@markuslf

markuslf commented Oct 2, 2026

Copy link
Copy Markdown
Member

/var/www/html should be /var/www

@NavidSassan
NavidSassan merged commit c517152 into main Oct 2, 2026
13 checks passed
@NavidSassan
NavidSassan deleted the feat/duplicity-default-sources branch October 2, 2026 08:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants