--- # Restores the latest restic snapshot from home's nextcloud-pvc-sync # CronJob (apps/nextcloud/manifests/pvc-sync-cronjob.yaml, which backs up # to VPS MinIO's nextcloud-files/restic-repo daily at 02:00) into this # standby's own Nextcloud PVC. Runs daily at 04:00 - enough margin after # home's job to be sure that day's snapshot has landed. # # `restic restore latest --target /` restores into /data/... because # home's backup stored an absolute /data path (`restic backup /data ...`) # - mounting the destination PVC at /data here mirrors that exactly. # # nextcloud-restic-password must be the SAME password used to init the # repo at home (it's the decryption key for the whole restic repository, # not something that can differ per-consumer) - copied here manually # (kubectl, not git): # kubectl -n nextcloud create secret generic nextcloud-restic-password \ # --from-literal=password= # # Nextcloud itself isn't running (replicas: 0, see values.yaml) so there's # no live-write conflict risk overwriting the PVC on every run. apiVersion: batch/v1 kind: CronJob metadata: name: nextcloud-pvc-restore namespace: nextcloud spec: schedule: "0 4 * * *" concurrencyPolicy: Forbid successfulJobsHistoryLimit: 3 failedJobsHistoryLimit: 3 jobTemplate: spec: backoffLimit: 2 template: spec: restartPolicy: Never securityContext: runAsNonRoot: true runAsUser: 65534 fsGroup: 33 # matches the real nextcloud Deployment's fsGroup, same reasoning as home's pvc-sync-cronjob seccompProfile: type: RuntimeDefault containers: - name: restic-restore image: restic/restic:0.16.4 securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] command: - /bin/sh - -c - | set -eu export RESTIC_REPOSITORY="s3:http://vps-minio.minio.svc.cluster.local:9000/nextcloud-files/restic-repo" export RESTIC_PASSWORD_FILE=/restic-secret/password export AWS_ACCESS_KEY_ID="${MINIO_ACCESS_KEY}" export AWS_SECRET_ACCESS_KEY="${MINIO_SECRET_KEY}" export RESTIC_CACHE_DIR=/tmp/restic-cache if ! restic snapshots >/dev/null 2>&1; then echo "No repo/snapshots reachable yet - nothing to restore." exit 0 fi echo "==> Restoring latest snapshot into /data..." restic restore latest --tag nextcloud --host nextcloud-k8s --target / echo "==> Done." env: - name: MINIO_ACCESS_KEY valueFrom: secretKeyRef: name: vps-minio-secret key: accesskey - name: MINIO_SECRET_KEY valueFrom: secretKeyRef: name: vps-minio-secret key: secretkey volumeMounts: - name: nextcloud-data mountPath: /data - name: restic-secret mountPath: /restic-secret readOnly: true volumes: - name: nextcloud-data persistentVolumeClaim: # Chart-generated PVC name, follows the Helm release name # (Application metadata.name: vps-nextcloud) - same # release-name-based naming gotcha hit with vault-0/ # vps-vault-0 and gitea-http/vps-gitea-http. Verify against # `kubectl -n nextcloud get pvc` after first deploy. claimName: vps-nextcloud-nextcloud - name: restic-secret secret: secretName: nextcloud-restic-password items: - key: password path: password