diff options
| author | Colin Wilk <colin@wilk.cx> | 2026-09-01 21:01:05 +0200 |
|---|---|---|
| committer | Colin Wilk <colin@wilk.cx> | 2026-09-01 21:43:57 +0200 |
| commit | 9c7586c7c3a235672ec6490d1a8bc44a222ce5d1 (patch) | |
| tree | 8b36c5ee3105da2ae769c0d9cd96683d213c949d /CHANGELOG.md | |
| parent | fa137a92e1084a07608a4008ec0cb891baa76774 (diff) | |
| download | ansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.tar.gz ansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.zip | |
Add borg prune and compact jobs
Run repository retention either after a successful backup or from a
dedicated systemd timer. Clean up script generation with templates and
expand molecule test coverage.
BREAKING CHANGE: Aggregate backup scripts are no longer managed, and
state=preset now requires at least one readable included directory.
Diffstat (limited to 'CHANGELOG.md')
| -rw-r--r-- | CHANGELOG.md | 105 |
1 files changed, 55 insertions, 50 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index 653cbcb..9b09d12 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ All notable changes to this project will be documented in this file. ### Breaking Changes -#### Decryption keys file format changed +#### Decryption keys file format changed (`a22ff18`) **Am I affected?** You have a `decryption_keys.yml` file with entries from previous versions. @@ -39,74 +39,79 @@ format. --- -#### Backup script block markers changed +#### Aggregate backup and prune scripts are no longer managed **Am I affected?** -Yes. +You manually run the unsuffixed `run_borg_backup` or `run_borg_prune` script +while `borg_backup_argument` is not empty. **What changed?** -Block markers in the backup script now include repository name to support -multiple repos per host. +The role now creates one complete script per repository at +`run_borg_backup@ARGUMENT` and, whenever pruning is enabled, +`run_borg_prune@ARGUMENT`. Systemd and manual runs use these repository-specific +scripts. Scripts are rendered atomically from templates instead of assembled +with `blockinfile`. -Old: - -```bash -## BEGIN ANSIBLE MANAGED BLOCK for server: backup-server -``` - -New: - -```bash -## BEGIN ANSIBLE MANAGED BLOCK for backup-server/my-repo -``` +Existing unsuffixed scripts are left untouched when `borg_backup_argument` is +not empty because the same path may belong to another repository configured +with an empty argument. If `borg_backup_argument` is empty, that repository's +script continues to use the unsuffixed path and is managed normally. **Migration:** - -<!-- TODO: We want to auto-migrate this --> - -Delete the script and re-run the role: +Run each repository-specific script explicitly, or invoke the corresponding +systemd service. For example: ```bash -rm /usr/local/bin/run_borg_backup -# Then run your playbook +/usr/local/bin/run_borg_backup@ARGUMENT +systemctl start borg_backup@ARGUMENT.service ``` +After confirming that no repository uses an empty `borg_backup_argument`, you +may manually remove legacy aggregate scripts. + --- -#### Default backup argument +#### Backup source validation is now enforced **Am I affected?** -You are using the default value of `borg_backup_argument`. +You use `state: present` with an empty `borg_included_dirs` list, or one of its +paths is missing or unreadable by `borg_client_user`. -**What will change?** -Default will change from `{{ borg_server_host_url }}` to -`{{ borg_server_host_url }}-{{ borg_repo_name }}`. +**What changed?** +The role now rejects empty `borg_included_dirs`, missing included paths, and +paths that `borg_client_user` cannot read. Previously, an empty list was +accepted. **Migration:** - -<!-- TODO: Consider if we want to migrate this automatically aswell --> - -Systemd unit names will change. Manually migrate: - -```bash -# Stop old units -systemctl stop borg_backup@OLD-VALUE.timer -systemctl disable borg_backup@OLD-VALUE.timer - -# Run role to create new units -# Then enable new units -systemctl enable borg_backup@NEW-VALUE.timer -systemctl start borg_backup@NEW-VALUE.timer -``` +Configure at least one existing path that `borg_client_user` can read in +`borg_included_dirs` whenever using `state: present`. ### Added - Multi-instance backup support (multiple repositories per client host) -- Non-root backup user support via `borg_client_user` variable -- Configurable SSH key type (`borg_ssh_key_type`) with support for - ed25519, rsa, and ecdsa -- Per-repo SSH key support (`borg_ssh_key_per_repo`) for independent keys per repository -- Storage quota support (`borg_storage_quota`) to limit repository size on server -- Comprehensive test suite including disaster recovery scenarios -- Negative security tests for cross-host repository isolation -- Appendix-only repository mode (`borg_mode_append_only`) + (`a22ff18`) +- Non-root backup user support via `borg_client_user` variable (`cce7d2d`) +- Configurable SSH key type (`borg_ssh_key_type`) with support for ed25519, + rsa, and ecdsa (`cce7d2d`) +- Per-repo SSH key support (`borg_ssh_key_per_repo`) for independent keys per + repository (`8d87206`) +- Storage quota support (`borg_storage_quota`) to limit repository size on + server (`8b0175c`) +- Option to disable decryption key export by setting + `borg_decryption_keys_yaml_path` to an empty string (`785e6c8`) +- Configurable server-side borg user via `borg_server_user` and + `borg_server_user_create` (`7d96c1a`) +- Custom `borg create` arguments via `borg_create_additional_arguments` + (`66e46df`) +- Repository removal support via `state: absent` and + `borg_dangerously_delete_backups` (`50b914e`) +- Automatic repository retention with `borg prune`, optional `borg compact`. + +### Changed + +- Declared `community.crypto` dependency in role metadata (`fa137a9`) + +### Fixed + +- Read `getent` user data from `ansible_facts`, restoring compatibility with + current Ansible fact injection behavior (`1143a27`). |