summaryrefslogtreecommitdiff
path: root/hosts/vidhar/borg/default.nix
blob: 05cc74d57dc4a2a9f4a16ef206906e0daf177cca (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
{ config, pkgs, lib, ... }:

with lib;

let
  copyService = { repo, repoEscaped }: let
    serviceName = "copy-borg@${repoEscaped}";
    sshConfig = pkgs.writeText "config" ''
      Include /etc/ssh/ssh_config

      Host yggdrasil.borgbase
        HostName nx69hpl8.repo.borgbase.com
        User nx69hpl8
        IdentityFile /run/credentials/${serviceName}.service/ssh-identity
        IdentitiesOnly yes

        BatchMode yes
        ServerAliveInterval 10
        ServerAliveCountMax 30
    '';
  in nameValuePair serviceName {
    serviceConfig = {
      Type = "oneshot";
      ExecStart = "${copyBorg}/bin/copy ${escapeShellArg repo} yggdrasil.borgbase:repo";
      User = "borg";
      Group = "borg";
      StateDirectory = "borg";
      Environment = [
        "BORG_RSH=\"${pkgs.openssh}/bin/ssh -F ${sshConfig}\""
        "BORG_BASE_DIR=/var/lib/borg"
        "BORG_CONFIG_DIR=/var/lib/borg/config"
        "BORG_CACHE_DIR=/var/lib/borg/cache"
        "BORG_SECURITY_DIR=/var/lib/borg/security"
        "BORG_KEYS_DIR=/var/lib/borg/keys"
        "BORG_KEY_FILE=/run/credentials/${serviceName}.service/keyfile"
        "BORG_UNKNOWN_UNENCRYPTED_REPO_ACCESS_IS_OK=yes"
      ];
      LoadCredential = [
        "ssh-identity:${config.sops.secrets."append.borgbase".path}"
        "keyfile:${config.sops.secrets."yggdrasil.borgkey".path}"
      ];
    };
  };

  copyBorg = pkgs.stdenv.mkDerivation let
    packageOverrides = pkgs.callPackage ./pyprctl-packages.nix {};
    inpPython = pkgs.python39.override { inherit packageOverrides; };
  in rec {
    name = "copy";
    src = ./copy.py;

    phases = ["buildPhase" "checkPhase" "installPhase"];

    buildInputs = with pkgs; [makeWrapper];

    python = inpPython.withPackages (ps: with ps; [humanize tqdm dateutil xdg python-unshare pyprctl halo]);

    buildPhase = ''
      substitute $src copy \
        --subst-var-by python ${escapeShellArg python}
    '';

    doCheck = true;
    checkPhase = ''
      ${python}/bin/python -m py_compile copy
    '';

    installPhase = ''
      install -m 0755 -D -t $out/bin \
        copy

      wrapProgram $out/bin/copy \
        --prefix PATH : ${config.security.wrapperDir}:${makeBinPath (with pkgs; [borgbackup])}
    '';
  };
in {
  config = {
    services.borgbackup.repos.jotnar = {
      path = "/srv/backup/borg/jotnar";
      authorizedKeysAppendOnly = let
        dir = ./jotnar;
        toAuthKey = fname: ftype: if ftype != "regular" || !(hasSuffix ".pub" fname) then null else builtins.readFile (dir + "/${fname}");
      in filter (v: v != null) (mapAttrsToList toAuthKey (builtins.readDir dir));
    };

    boot.postBootCommands = mkBefore ''
      ${pkgs.findutils}/bin/find /srv/backup/borg -type d -empty -delete
    '';

    users.users.borg.extraGroups = ["ssh"];

    services.openssh.extraConfig = ''
      Match User borg
        ClientAliveInterval 10
        ClientAliveCountMax 30

      Match All
    '';

    sops.secrets."append.borgbase" = {
      format = "binary";
      sopsFile = ./append.borgbase;
    };
    sops.secrets."yggdrasil.borgkey" = {
      format = "binary";
      sopsFile = ./yggdrasil.borgkey;
    };

    systemd.services = listToAttrs (map copyService [{ repo = "/srv/backup/borg/jotnar"; repoEscaped = "srv-backup-borg-jotnar"; }]);

    # systemd.timers."copy-borg@srv-backup-borg-jotnar" = {
    #   wantedBy = ["multi-user.target"];
      
    #   timerConfig = {
    #     OnCalendar = "*-*-* 00/4:00:00 Europe/Berlin";
    #   };
    # };
  };
}