aboutsummaryrefslogtreecommitdiffstats
path: root/molecule/default/converge.yml
diff options
context:
space:
mode:
authorColin Wilk <colin@wilk.cx>2026-09-01 21:01:05 +0200
committerColin Wilk <colin@wilk.cx>2026-09-01 21:43:57 +0200
commit9c7586c7c3a235672ec6490d1a8bc44a222ce5d1 (patch)
tree8b36c5ee3105da2ae769c0d9cd96683d213c949d /molecule/default/converge.yml
parentfa137a92e1084a07608a4008ec0cb891baa76774 (diff)
downloadansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.tar.gz
ansible-role-borgbackup-9c7586c7c3a235672ec6490d1a8bc44a222ce5d1.zip
Add borg prune and compact jobs
Run repository retention either after a successful backup or from a dedicated systemd timer. Clean up script generation with templates and expand molecule test coverage. BREAKING CHANGE: Aggregate backup scripts are no longer managed, and state=preset now requires at least one readable included directory.
Diffstat (limited to 'molecule/default/converge.yml')
-rw-r--r--molecule/default/converge.yml164
1 files changed, 164 insertions, 0 deletions
diff --git a/molecule/default/converge.yml b/molecule/default/converge.yml
index 90b3258..0e9fbf0 100644
--- a/molecule/default/converge.yml
+++ b/molecule/default/converge.yml
@@ -6,6 +6,8 @@
- borg-client-multi
- borg-client-nonroot
- borg-client-multi-keys
+ - borg-client-transition
+ - borg-client-validation
vars:
borg_server_host: borg-server
@@ -64,6 +66,11 @@
- /opt
- /var
- /reee reeee
+ borg_prune_enabled: true
+ borg_prune_keep_last: "2"
+ borg_prune_glob_archives: "{hostname}-*"
+ borg_prune_compact_enabled: true
+ borg_compact_threshold: 1
- name: Converge - borg-client-2 (custom server user)
hosts: borg-client-2
@@ -93,6 +100,17 @@
- /opt
- /var
- /reee reeee
+ borg_prune_enabled: true
+ borg_prune_trigger: timer
+ borg_prune_keep_daily: "7"
+ borg_prune_keep_weekly: "4"
+ borg_prune_glob_archives: "{hostname}-*"
+ borg_prune_compact_enabled: true
+ borg_compact_threshold: 10
+ borg_prune_service_successful_exit_status:
+ - 1
+ - TEMPFAIL
+ borg_prune_systemd_oncalendar: "*-*-* 05:00:00"
- name: Converge - Multi-instance backup (same host, different repos)
hosts: borg-client-multi
@@ -190,3 +208,149 @@
borg_excluded_dirs:
- /home/*/.cache
borg_systemd_oncalendar: "*-*-* 04:00:00"
+
+- name: Converge - Transition host in stable after_backup state
+ hosts: borg-client-transition
+
+ pre_tasks:
+ - name: Seed legacy aggregate backup script
+ ansible.builtin.copy:
+ dest: /usr/local/bin/run_borg_backup
+ content: |
+ #!/bin/bash
+ ## BEGIN ANSIBLE MANAGED BLOCK for borg-server/transition-repo
+ echo legacy-backup-block
+ ## END ANSIBLE MANAGED BLOCK for borg-server/transition-repo
+ owner: root
+ group: root
+ mode: "0711"
+ force: false
+ become: true
+
+ roles:
+ - role: kliwniloc.borgbackup
+ vars:
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: transition-repo
+ borg_backup_argument: transition-repo
+ borg_included_dirs:
+ - /etc
+ borg_excluded_dirs: []
+ borg_prune_enabled: true
+ borg_prune_trigger: after_backup
+ borg_prune_keep_last: "2"
+ borg_prune_glob_archives: "{hostname}-*"
+
+- name: Converge - Validation guard coverage
+ hosts: borg-client-validation
+
+ tasks:
+ - name: Verify prune with append-only fails validation
+ block:
+ - name: Run role with incompatible append-only pruning
+ ansible.builtin.include_role:
+ name: kliwniloc.borgbackup
+ vars:
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: validation-append-only
+ borg_backup_argument: validation-append-only
+ borg_included_dirs:
+ - /etc
+ borg_prune_enabled: true
+ borg_mode_append_only: true
+ borg_prune_keep_last: "2"
+ borg_prune_glob_archives: "{hostname}-*"
+
+ - name: Fail when append-only prune validation unexpectedly passes
+ ansible.builtin.fail:
+ msg: Append-only prune validation unexpectedly passed
+ rescue:
+ - name: Assert append-only prune validation failed as expected
+ ansible.builtin.assert:
+ that:
+ - >-
+ 'incompatible with borg_mode_append_only'
+ in (ansible_failed_result.msg | default(''))
+
+ - name: Verify prune without a retention policy fails validation
+ block:
+ - name: Run role without a prune retention policy
+ ansible.builtin.include_role:
+ name: kliwniloc.borgbackup
+ vars:
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: validation-no-retention
+ borg_backup_argument: validation-no-retention
+ borg_included_dirs:
+ - /etc
+ borg_prune_enabled: true
+ borg_prune_glob_archives: "{hostname}-*"
+
+ - name: Fail when missing retention validation unexpectedly passes
+ ansible.builtin.fail:
+ msg: Missing retention validation unexpectedly passed
+ rescue:
+ - name: Assert missing retention validation failed as expected
+ ansible.builtin.assert:
+ that:
+ - >-
+ 'Prune requires at least one retention rule'
+ in (ansible_failed_result.msg | default(''))
+
+ - name: Prune with retention only in additional arguments should succeed
+ ansible.builtin.include_role:
+ name: kliwniloc.borgbackup
+ vars:
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: validation-additional-args
+ borg_backup_argument: validation-additional-args
+ borg_included_dirs:
+ - /etc
+ borg_prune_enabled: true
+ borg_prune_glob_archives: "{hostname}-*"
+ borg_prune_additional_arguments: --keep-last 2
+ register: prune_additional_args_result
+
+ - name: Assert additional-arguments prune validation passes
+ ansible.builtin.assert:
+ that:
+ - prune_additional_args_result is succeeded
+
+ - name: Converge disabled pruning baseline
+ ansible.builtin.include_role:
+ name: kliwniloc.borgbackup
+ vars:
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: validation-disable-prune
+ borg_backup_argument: validation-disable-prune
+ borg_included_dirs:
+ - /etc
+ borg_prune_enabled: false
+
+ - name: Absent state with empty prune script path should succeed
+ ansible.builtin.include_role:
+ name: kliwniloc.borgbackup
+ vars:
+ state: absent
+ borg_server_host: borg-server
+ borg_server_user_home: /opt/borg
+ borg_decryption_keys_yaml_path: "{{ playbook_dir }}/decryption_keys.yml"
+ borg_repo_name: validation-absent-empty-prune-path
+ borg_backup_argument: validation-absent-empty-prune-path
+ borg_prune_script_location: ""
+ register: absent_empty_prune_path_result
+
+ - name: Assert absent with empty prune script path passes
+ ansible.builtin.assert:
+ that:
+ - absent_empty_prune_path_result is succeeded