# Changelog All notable changes to this project will be documented in this file. ## [2.0.0] Version 2.0.0 expands into complete multi-repository backup management. It adds multi-instance and non-root client support, configurable repository security and quotas, automatic prune and compact jobs, and managed repository removal. The release also moves backup jobs to repository-specific scripts, adds configuration and backup-source validation, and changes the exported decryption key format. Review the breaking changes and migration instructions below before upgrading an existing installation. ### Breaking Changes #### Decryption keys file format changed (`a22ff18`) **Am I affected?** You have a `decryption_keys.yml` file with entries from previous versions. **What changed?** Keys now include the repository name to support multiple repos per host. Old format: ```yaml my-host: BORG_KEY_abc123... ``` New format: ```yaml my-host_repo-name: BORG_KEY_abc123... ``` Generally a harmless change, just leads to duplicate keys with old and new format. **Migration:** 1. Run the role with the new version (new keys created automatically) 2. Verify backups work correctly 3. Remove old hostname-only entries from `decryption_keys.yml` --- #### Aggregate backup and prune scripts are no longer managed **Am I affected?** You manually run the unsuffixed `run_borg_backup` or `run_borg_prune` script while `borg_backup_argument` is not empty. **What changed?** The role now creates one complete script per repository at `run_borg_backup@ARGUMENT` and, whenever pruning is enabled, `run_borg_prune@ARGUMENT`. Systemd and manual runs use these repository-specific scripts. Scripts are rendered atomically from templates instead of assembled with `blockinfile`. Existing unsuffixed scripts are left untouched when `borg_backup_argument` is not empty because the same path may belong to another repository configured with an empty argument. If `borg_backup_argument` is empty, that repository's script continues to use the unsuffixed path and is managed normally. **Migration:** Run each repository-specific script explicitly, or invoke the corresponding systemd service. For example: ```bash /usr/local/bin/run_borg_backup@ARGUMENT systemctl start borg_backup@ARGUMENT.service ``` After confirming that no repository uses an empty `borg_backup_argument`, you may manually remove legacy aggregate scripts. --- #### Backup source validation is now enforced **Am I affected?** You use `state: present` with an empty `borg_included_dirs` list, or one of its paths is missing or unreadable by `borg_client_user`. **What changed?** The role now rejects empty `borg_included_dirs`, missing included paths, and paths that `borg_client_user` cannot read. Previously, an empty list was accepted. **Migration:** Configure at least one existing path that `borg_client_user` can read in `borg_included_dirs` whenever using `state: present`. ### Added - Multi-instance backup support (multiple repositories per client host) (`a22ff18`) - Non-root backup user support via `borg_client_user` variable (`cce7d2d`) - Configurable SSH key type (`borg_ssh_key_type`) with support for ed25519, rsa, and ecdsa (`cce7d2d`) - Per-repo SSH key support (`borg_ssh_key_per_repo`) for independent keys per repository (`8d87206`) - Storage quota support (`borg_storage_quota`) to limit repository size on server (`8b0175c`) - Option to disable decryption key export by setting `borg_decryption_keys_yaml_path` to an empty string (`785e6c8`) - Configurable server-side borg user via `borg_server_user` and `borg_server_user_create` (`7d96c1a`) - Custom `borg create` arguments via `borg_create_additional_arguments` (`66e46df`) - Repository removal support via `state: absent` and `borg_dangerously_delete_backups` (`50b914e`) - Automatic repository retention with `borg prune`, optional `borg compact`. ### Changed - Declared `community.crypto` dependency in role metadata (`fa137a9`) ### Fixed - Read `getent` user data from `ansible_facts`, restoring compatibility with current Ansible fact injection behavior (`1143a27`).