<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ansible-role-borgbackup/tasks/client_create_scripts_each.yml, branch v2.0.0</title>
<subtitle>Ansible role for deploying scheduled borgbackup configurations</subtitle>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/'/>
<entry>
<title>Add borg prune and compact jobs</title>
<updated>2026-09-01T19:43:57+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-09-01T19:01:05+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=9c7586c7c3a235672ec6490d1a8bc44a222ce5d1'/>
<id>9c7586c7c3a235672ec6490d1a8bc44a222ce5d1</id>
<content type='text'>
Run repository retention either after a successful backup or from a
dedicated systemd timer. Clean up script generation with templates and
expand molecule test coverage.

BREAKING CHANGE: Aggregate backup scripts are no longer managed, and
state=preset now requires at least one readable included directory.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Run repository retention either after a successful backup or from a
dedicated systemd timer. Clean up script generation with templates and
expand molecule test coverage.

BREAKING CHANGE: Aggregate backup scripts are no longer managed, and
state=preset now requires at least one readable included directory.
</pre>
</div>
</content>
</entry>
<entry>
<title>Support custom arguments for borg create</title>
<updated>2026-06-29T18:56:50+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-29T18:56:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=66e46df3d2a840bf62ef8084ad171041772db65e'/>
<id>66e46df3d2a840bf62ef8084ad171041772db65e</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Parametrize server-side borg user</title>
<updated>2026-06-28T21:18:35+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-28T20:47:11+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=7d96c1a11fc442b4efddf9ce5250cf0a9dfaf02e'/>
<id>7d96c1a11fc442b4efddf9ce5250cf0a9dfaf02e</id>
<content type='text'>
Adds option to choose a non-default borg backup user on the server.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Adds option to choose a non-default borg backup user on the server.
</pre>
</div>
</content>
</entry>
<entry>
<title>feat: add per-repo SSH key support</title>
<updated>2026-06-27T21:05:21+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-27T21:01:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=8d872069976c5445c4396804ef3a0196f10eb14b'/>
<id>8d872069976c5445c4396804ef3a0196f10eb14b</id>
<content type='text'>
Add borg_ssh_key_per_repo option to generate unique SSH keypairs per
(server, repo) combination. When enabled, each repository gets its own
authorized_keys entry, enabling:

- Independent --append-only settings per repository
- Per-repo storage quotas
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add borg_ssh_key_per_repo option to generate unique SSH keypairs per
(server, repo) combination. When enabled, each repository gets its own
authorized_keys entry, enabling:

- Independent --append-only settings per repository
- Per-repo storage quotas
</pre>
</div>
</content>
</entry>
<entry>
<title>Add support for non-root backup clients</title>
<updated>2026-06-27T19:25:37+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-27T19:25:37+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=cce7d2d258292c283d64ce8da14a6d1e366b564d'/>
<id>cce7d2d258292c283d64ce8da14a6d1e366b564d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>backup_script!: ensure unique blockinfile marker</title>
<updated>2026-06-27T13:43:21+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-26T21:42:26+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=b8d11180605fbf193e76fba04bb63b5ea4908dcf'/>
<id>b8d11180605fbf193e76fba04bb63b5ea4908dcf</id>
<content type='text'>
The blockinfile marker was only keyed by borg_server_host_url, causing
backup blocks to overwrite each other when running the role multiple
times on the same host with different repositories.

This change includes borg_repo_name in the marker, allowing multiple
backup blocks to coexist in the base script. Now running the role
twice with different borg_repo_name values creates separate blocks
instead of overwriting.

This ensures idempotent behavior and allows the base script to
accumulate all backup targets as documented.

Before: marker for "borg-server" (overwrites on second run)
After:  marker for "borg-server/configs" and "borg-server/home-data"
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The blockinfile marker was only keyed by borg_server_host_url, causing
backup blocks to overwrite each other when running the role multiple
times on the same host with different repositories.

This change includes borg_repo_name in the marker, allowing multiple
backup blocks to coexist in the base script. Now running the role
twice with different borg_repo_name values creates separate blocks
instead of overwriting.

This ensures idempotent behavior and allows the base script to
accumulate all backup targets as documented.

Before: marker for "borg-server" (overwrites on second run)
After:  marker for "borg-server/configs" and "borg-server/home-data"
</pre>
</div>
</content>
</entry>
<entry>
<title>Update and fix pre-commit hooks</title>
<updated>2026-06-26T20:11:18+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin@wilk.cx</email>
</author>
<published>2026-06-26T20:11:18+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=bd022f046651d287309b26164cd60a3d6d38471c'/>
<id>bd022f046651d287309b26164cd60a3d6d38471c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Handle special characters around BORG_PASSPHRASE variable</title>
<updated>2026-01-23T15:24:02+00:00</updated>
<author>
<name>Magnus Kühne</name>
<email>73171182+magkue@users.noreply.github.com</email>
</author>
<published>2026-01-23T15:24:02+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=f6294fe0b2bb4ec2be2587434da60dc187ee59b4'/>
<id>f6294fe0b2bb4ec2be2587434da60dc187ee59b4</id>
<content type='text'>
If passphrase contains special characters like (!, $, &amp;, ^, *, @), this needs to be escaped.

Co-authored-by: Colin Wilk &lt;colin@wilk.cx&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If passphrase contains special characters like (!, $, &amp;, ^, *, @), this needs to be escaped.

Co-authored-by: Colin Wilk &lt;colin@wilk.cx&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>Migrate role from cron to systemd</title>
<updated>2023-11-04T13:02:38+00:00</updated>
<author>
<name>Colin Wilk</name>
<email>colin.wilk@tum.de</email>
</author>
<published>2023-11-03T18:45:20+00:00</published>
<link rel='alternate' type='text/html' href='http://git.wilk.cx/ansible/ansible-role-borgbackup.git/commit/?id=50a2795c3a6c72203262400db5029f5afdf1d49c'/>
<id>50a2795c3a6c72203262400db5029f5afdf1d49c</id>
<content type='text'>
Systemd gives us the ability to monitor backup job status using existing
monitoring solutions (node exporter) and allows us greater control over
the scheduling of the backup jobs.

This introduces a breaking change that requires users to manually remove
the old repositories from the clients and redeploying them with the
role. You will have to remove the Cron job that was created by the
Ansible script, everything else will be overwritten with a run from the
newer version.

- name: Remove backup cron jobs
  ansible.builtin.cron:
    name: BORG (Application level backups)
    state: absent
  become: true
- name: Remove env for backup cron job
  ansible.builtin.cron:
    name: BORG_PASSPHRASE
    env: true
    state: absent
  become: true

Performing manual migrations on the Borg server is not required.

We now additionally support multiple Borg repositories per client host
using the `borg_backup_argument` variable.

Signed-off-by: Colin Wilk &lt;colin.wilk@tum.de&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Systemd gives us the ability to monitor backup job status using existing
monitoring solutions (node exporter) and allows us greater control over
the scheduling of the backup jobs.

This introduces a breaking change that requires users to manually remove
the old repositories from the clients and redeploying them with the
role. You will have to remove the Cron job that was created by the
Ansible script, everything else will be overwritten with a run from the
newer version.

- name: Remove backup cron jobs
  ansible.builtin.cron:
    name: BORG (Application level backups)
    state: absent
  become: true
- name: Remove env for backup cron job
  ansible.builtin.cron:
    name: BORG_PASSPHRASE
    env: true
    state: absent
  become: true

Performing manual migrations on the Borg server is not required.

We now additionally support multiple Borg repositories per client host
using the `borg_backup_argument` variable.

Signed-off-by: Colin Wilk &lt;colin.wilk@tum.de&gt;
</pre>
</div>
</content>
</entry>
</feed>
