aboutsummaryrefslogtreecommitdiffstats
path: root/CHANGELOG.md
diff options
context:
space:
mode:
authorColin Wilk <colin@wilk.cx>2026-09-01 21:01:05 +0200
committerColin Wilk <colin@wilk.cx>2026-09-01 21:43:57 +0200
commit9c7586c7c3a235672ec6490d1a8bc44a222ce5d1 (patch)
tree8b36c5ee3105da2ae769c0d9cd96683d213c949d /CHANGELOG.md
parentfa137a92e1084a07608a4008ec0cb891baa76774 (diff)
downloadansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.tar.gz
ansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.zip
Add borg prune and compact jobs
Run repository retention either after a successful backup or from a dedicated systemd timer. Clean up script generation with templates and expand molecule test coverage. BREAKING CHANGE: Aggregate backup scripts are no longer managed, and state=preset now requires at least one readable included directory.
Diffstat (limited to 'CHANGELOG.md')
-rw-r--r--CHANGELOG.md105
1 files changed, 55 insertions, 50 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 653cbcb..9b09d12 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -8,7 +8,7 @@ All notable changes to this project will be documented in this file.
### Breaking Changes
-#### Decryption keys file format changed
+#### Decryption keys file format changed (`a22ff18`)
**Am I affected?**
You have a `decryption_keys.yml` file with entries from previous versions.
@@ -39,74 +39,79 @@ format.
---
-#### Backup script block markers changed
+#### Aggregate backup and prune scripts are no longer managed
**Am I affected?**
-Yes.
+You manually run the unsuffixed `run_borg_backup` or `run_borg_prune` script
+while `borg_backup_argument` is not empty.
**What changed?**
-Block markers in the backup script now include repository name to support
-multiple repos per host.
+The role now creates one complete script per repository at
+`run_borg_backup@ARGUMENT` and, whenever pruning is enabled,
+`run_borg_prune@ARGUMENT`. Systemd and manual runs use these repository-specific
+scripts. Scripts are rendered atomically from templates instead of assembled
+with `blockinfile`.
-Old:
-
-```bash
-## BEGIN ANSIBLE MANAGED BLOCK for server: backup-server
-```
-
-New:
-
-```bash
-## BEGIN ANSIBLE MANAGED BLOCK for backup-server/my-repo
-```
+Existing unsuffixed scripts are left untouched when `borg_backup_argument` is
+not empty because the same path may belong to another repository configured
+with an empty argument. If `borg_backup_argument` is empty, that repository's
+script continues to use the unsuffixed path and is managed normally.
**Migration:**
-
-<!-- TODO: We want to auto-migrate this -->
-
-Delete the script and re-run the role:
+Run each repository-specific script explicitly, or invoke the corresponding
+systemd service. For example:
```bash
-rm /usr/local/bin/run_borg_backup
-# Then run your playbook
+/usr/local/bin/run_borg_backup@ARGUMENT
+systemctl start borg_backup@ARGUMENT.service
```
+After confirming that no repository uses an empty `borg_backup_argument`, you
+may manually remove legacy aggregate scripts.
+
---
-#### Default backup argument
+#### Backup source validation is now enforced
**Am I affected?**
-You are using the default value of `borg_backup_argument`.
+You use `state: present` with an empty `borg_included_dirs` list, or one of its
+paths is missing or unreadable by `borg_client_user`.
-**What will change?**
-Default will change from `{{ borg_server_host_url }}` to
-`{{ borg_server_host_url }}-{{ borg_repo_name }}`.
+**What changed?**
+The role now rejects empty `borg_included_dirs`, missing included paths, and
+paths that `borg_client_user` cannot read. Previously, an empty list was
+accepted.
**Migration:**
-
-<!-- TODO: Consider if we want to migrate this automatically aswell -->
-
-Systemd unit names will change. Manually migrate:
-
-```bash
-# Stop old units
-systemctl stop borg_backup@OLD-VALUE.timer
-systemctl disable borg_backup@OLD-VALUE.timer
-
-# Run role to create new units
-# Then enable new units
-systemctl enable borg_backup@NEW-VALUE.timer
-systemctl start borg_backup@NEW-VALUE.timer
-```
+Configure at least one existing path that `borg_client_user` can read in
+`borg_included_dirs` whenever using `state: present`.
### Added
- Multi-instance backup support (multiple repositories per client host)
-- Non-root backup user support via `borg_client_user` variable
-- Configurable SSH key type (`borg_ssh_key_type`) with support for
- ed25519, rsa, and ecdsa
-- Per-repo SSH key support (`borg_ssh_key_per_repo`) for independent keys per repository
-- Storage quota support (`borg_storage_quota`) to limit repository size on server
-- Comprehensive test suite including disaster recovery scenarios
-- Negative security tests for cross-host repository isolation
-- Appendix-only repository mode (`borg_mode_append_only`)
+ (`a22ff18`)
+- Non-root backup user support via `borg_client_user` variable (`cce7d2d`)
+- Configurable SSH key type (`borg_ssh_key_type`) with support for ed25519,
+ rsa, and ecdsa (`cce7d2d`)
+- Per-repo SSH key support (`borg_ssh_key_per_repo`) for independent keys per
+ repository (`8d87206`)
+- Storage quota support (`borg_storage_quota`) to limit repository size on
+ server (`8b0175c`)
+- Option to disable decryption key export by setting
+ `borg_decryption_keys_yaml_path` to an empty string (`785e6c8`)
+- Configurable server-side borg user via `borg_server_user` and
+ `borg_server_user_create` (`7d96c1a`)
+- Custom `borg create` arguments via `borg_create_additional_arguments`
+ (`66e46df`)
+- Repository removal support via `state: absent` and
+ `borg_dangerously_delete_backups` (`50b914e`)
+- Automatic repository retention with `borg prune`, optional `borg compact`.
+
+### Changed
+
+- Declared `community.crypto` dependency in role metadata (`fa137a9`)
+
+### Fixed
+
+- Read `getent` user data from `ansible_facts`, restoring compatibility with
+ current Ansible fact injection behavior (`1143a27`).