From 24d07cd8d1a74d0a2a5994e1a68a42a7f41131b9 Mon Sep 17 00:00:00 2001 From: Bertrand Benjamin Date: Sun, 11 Nov 2018 09:01:21 +0100 Subject: [PATCH] Feat(Songe): Start songe borgbackup server --- files/sshpubs/id_rsa_poivre_borg.pub | 1 + tasks/borg_server.yml | 62 ++++++++++++++++++++++++++++ vars/Songe.yml | 18 ++++++++ 3 files changed, 81 insertions(+) create mode 100644 files/sshpubs/id_rsa_poivre_borg.pub diff --git a/files/sshpubs/id_rsa_poivre_borg.pub b/files/sshpubs/id_rsa_poivre_borg.pub new file mode 100644 index 0000000..676f6ef --- /dev/null +++ b/files/sshpubs/id_rsa_poivre_borg.pub @@ -0,0 +1 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDPuEcyD0F2z8hlPPFkVV0EcbCJR/SxO4ajpPnVhkJI++KCvZEIhII0S3j0nQcukzN3saiVzzzYACyoCUdDVQZV7eoQ2R4eWMDSd10ToHbQezlneWT+wLhsJ2H8lo+e5Ny1AzEAE4ho1wxeQN3lZX5g0S5HFx/bVpiQSoks8ItjnUjmbeMQmWWDM4F9kQeSpOu2WWWT5o7BCBmXCFNrmF5pXHsYiAV5LMnOSs7l1e0o4aVJJfv+529qrITVzSYCtKaTIFTNbmwZlrKOAjIjbM/rRUturBg/2ToaSzIKTwZOS4Wb9NuKYMOAFtOZ3rbFimjIOsGB13D1oG/qgOyZN3tX lafrite@Poivre diff --git a/tasks/borg_server.yml b/tasks/borg_server.yml index 720a7dc..a86f55e 100644 --- a/tasks/borg_server.yml +++ b/tasks/borg_server.yml @@ -3,3 +3,65 @@ apt: name: borgbackup state: present + +- name: Add borgbackup group + group: + name: "{{ borg_group }}" + state: present + +- name: Add borgbackup user + user: + name: "{{ borg_user }}" + shell: /bin/bash + home: "{{ borg_home }}" + createhome: yes + group: "{{ borg_group }}" + state: present + +- name: Fix permission on borgbackup home + file: + path: "{{ borg_home }}" + owner: "{{ borg_user }}" + group: "{{ borg_group }}" + mode: 0700 + state: directory + +- name: Fix .ssh permision + file: + path: "{{ borg_home }}/.ssh" + owner: "{{ borg_user }}" + group: "{{ borg_group }}" + mode: 0700 + state: directory + +- name: Fix pool permission + file: + path: "{{ borg_pool }}" + owner: "{{ borg_user }}" + group: "{{ borg_group }}" + mode: 0700 + state: directory + +- name: Add autorized backup user through $HOME/.ssh/authorized_keys + authorized_key: + user: "{{ borg_user }}" + key: "{{ item.key }}" + key_options: 'command="cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}",restrict' + with_items: "{{ borg_auth_users }}" + +- name: Fix permission on authorized_keys + file: + path: "{{ borg_home }}/.ssh/authorized_keys" + owner: "{{ borg_user }}" + group: "{{ borg_group }}" + mode: 0600 + state: file + +- name: Fix permission on each repo + file: + path: "{{ borg_pool }}/{{ item.host }}" + owner: "{{ borg_user }}" + group: "{{ borg_group }}" + mode: 0700 + state: directory + with_items: "{{ borg_auth_users }}" diff --git a/vars/Songe.yml b/vars/Songe.yml index e2a4f4e..b97f76c 100644 --- a/vars/Songe.yml +++ b/vars/Songe.yml @@ -19,3 +19,21 @@ nfs_shares: - { src: '/media/documents', name: '/export/documents', options: 'rw,no_subtree_check,nohide' } - { src: '/media/backup', name: '/export/backup', options: 'rw,no_subtree_check,nohide' } - { src: '/media/documents/musique', name: '/export/musique', options: 'ro,no_subtree_check,nohide' } + + +## J'en suis là!! +borg: + user: backup + group: backup + home: /media/backup/borgbackup + pool: /media/backup/borgbackup/repos + auth_users: + - host: Poivre + key: "{{ lookup('file', 'sshpubs/id_rsa_poivre_borg.pub') }}" + # - host: Choux + # key: "{{ lookup('file', '') }}" + # - host: localhost + # key: "{{ lookup('file', '') }}" + + +