From 279f26c23dc41fb2fa80afa3c17e53f2ab8d19eb Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Tue, 18 Nov 2025 01:15:10 -0500 Subject: [PATCH 01/10] kopia init --- kopia/docker-compose-init.yml | 78 +++++++++++++++++++++++++++++++++++ kopia/docker-compose.yml | 8 ++-- 2 files changed, 83 insertions(+), 3 deletions(-) create mode 100644 kopia/docker-compose-init.yml diff --git a/kopia/docker-compose-init.yml b/kopia/docker-compose-init.yml new file mode 100644 index 0000000..0015752 --- /dev/null +++ b/kopia/docker-compose-init.yml @@ -0,0 +1,78 @@ +# Run once: docker compose -f docker-compose-init.yml up --build --force-recreate + +services: + kopia_init: + image: kopia/kopia:latest + container_name: kopia_init + # Use the passwords from .env + environment: + - KOPIA_REPOSITORY_PASSWORD=${KOPIA_REPOSITORY_PASSWORD} + - PUID=1000 + - PGID=1000 + + # Volumes MUST match the server setup so the repository is initialized in the correct place. + volumes: + - kopia_config:/app/config + - kopia_cache:/app/cache + - kopia_logs:/app/logs + - g:/kopia-backups:/app/repository # CRITICAL: This is where the repo will be created + + # --- YOUR SOURCE DATA --- + # Maps your host's E:\installers and H:\immich-photos to specific paths inside the container. + # ':ro' (read-only) is a safety best practice. + - e:/installers:/source/installers:ro + - h:/immich-photos:/source/immich-photos:ro + + # Override the default Kopia ENTRYPOINT to use the standard shell. + entrypoint: /bin/sh + + # This command now runs 4 steps sequentially: + # 1. Create the repository. + # 2. Connect to it (so subsequent commands work). + # 3. SET POLICY for /source/installers (12h interval + retention). + # 4. SET POLICY for /source/immich-photos (12h interval + retention). + command: + - -c + - | + # 1. Create the Kopia Repository + echo 'Creating new Kopia repository at /app/repository...' + kopia repository create filesystem \ + --path=/app/repository \ + --password=${KOPIA_REPOSITORY_PASSWORD} \ + && \ + # 2. Explicitly connect to the repository non-interactively. + # This is CRITICAL for the policy commands to work. + echo 'Connecting to repository non-interactively...' && \ + kopia repository connect filesystem \ + --path=/app/repository \ + --password=${KOPIA_REPOSITORY_PASSWORD} \ + && \ + # 3. SET POLICY for installers (Schedule: 12h) + # This does NOT run a snapshot. It just saves the schedule. + echo 'Setting 12-hour schedule for /source/installers...' && \ + kopia policy set /source/installers \ + --snapshot-interval 12h \ + --keep-daily 7 \ + --keep-weekly 4 \ + --keep-monthly 12 \ + --password=${KOPIA_REPOSITORY_PASSWORD} \ + && \ + # 4. SET POLICY for immich-photos (Schedule: 12h) + echo 'Setting 12-hour schedule for /source/immich-photos...' && \ + kopia policy set /source/immich-photos \ + --snapshot-interval 12h \ + --keep-daily 7 \ + --keep-weekly 4 \ + --keep-monthly 12 \ + --password=${KOPIA_REPOSITORY_PASSWORD} + + echo 'Initialization complete. Repository created and policies set.' + + # Do not restart since it's a one-off command + restart: "no" + +# Re-using the same Docker-managed volumes +volumes: + kopia_config: + kopia_cache: + kopia_logs: diff --git a/kopia/docker-compose.yml b/kopia/docker-compose.yml index 7f0f717..d1d962c 100644 --- a/kopia/docker-compose.yml +++ b/kopia/docker-compose.yml @@ -24,14 +24,15 @@ services: - kopia_logs:/app/logs # --- YOUR BACKUP DESTINATION --- - # Maps your host's F:\test_backup to /app/repository inside the container. + # Maps your host's G:\kopia-backups to /app/repository inside the container. # Kopia will write its backup data here. - - f:/test_backup:/app/repository + - g:/kopia-backups:/app/repository # --- YOUR SOURCE DATA --- - # Maps your host's E:\installers to /source/installers inside the container. + # Maps your host's E:\installers and H:\immich-photos to /source/installers inside the container. # ':ro' (read-only) is a safety best practice. - e:/installers:/source/installers:ro + - h:/immich-photos:/source/immich-photos:ro command: - server @@ -39,6 +40,7 @@ services: - --ui - --address=0.0.0.0:51515 - --insecure + - --password=${KOPIA_REPOSITORY_PASSWORD} - --server-username=${KOPIA_SERVER_USERNAME} - --server-password=${KOPIA_SERVER_PASSWORD} restart: unless-stopped From f28d9781ff6419319f661757bd37234ca12b6865 Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Tue, 18 Nov 2025 02:34:43 -0500 Subject: [PATCH 02/10] tried autorestic, no success --- .gitignore | 1 + autorestic/config/.autorestic.yml | 26 ++++++++++++++++++++++++++ autorestic/docker-compose.yml | 26 ++++++++++++++++++++++++++ 3 files changed, 53 insertions(+) create mode 100644 autorestic/config/.autorestic.yml create mode 100644 autorestic/docker-compose.yml diff --git a/.gitignore b/.gitignore index 20e36df..f436d28 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,4 @@ .env swag filebrowser-docker +autorestic/config/.autorestic.lock.yml diff --git a/autorestic/config/.autorestic.yml b/autorestic/config/.autorestic.yml new file mode 100644 index 0000000..9d0f7ef --- /dev/null +++ b/autorestic/config/.autorestic.yml @@ -0,0 +1,26 @@ +version: 2 + +locations: + home: + from: + - /data/installers + # Or multiple + # from: + # - /foo + # - /bar + to: + - hdd + +backends: + # remote: + # type: s3 + # path: 's3.amazonaws.com/bucket_name' + # key: some-random-password-198rc79r8y1029c8yfewj8f1u0ef87yh198uoieufy + # env: + # AWS_ACCESS_KEY_ID: account_id + # AWS_SECRET_ACCESS_KEY: account_key + + hdd: + type: local + path: /repo/autorestic_repo + key: 'if not key is set it will be generated for you' diff --git a/autorestic/docker-compose.yml b/autorestic/docker-compose.yml new file mode 100644 index 0000000..c12a364 --- /dev/null +++ b/autorestic/docker-compose.yml @@ -0,0 +1,26 @@ +services: + autorestic: + image: cupcakearmy/autorestic + container_name: autorestic + hostname: autorestic-backup + # We mount the autorestic config file into the container. + # We mount the data you want to back up (E:\installers) into the container at /data/installers. + # We mount the repository location (G:\autorestic-backups) into the container at /repo/autorestic_repo. + # We use a named volume for the restic cache for persistence and performance. + volumes: + - ./config:/config + - e:/installers:/data/installers:ro + - g:/autorestic-backups:/repo/autorestic_repo + - autorestic_cache:/root/.cache/restic + # Pass secrets as environment variables. + environment: + - RESTIC_PASSWORD=YOUR_STRONG_REPOSITORY_PASSWORD + # This command will automatically run backups, checks, and prunes + # based on the cron schedules defined in your .autorestic.yml + command: > + /bin/sh -c "while true; do autorestic --config /config/.autorestic.yml cron; sleep 3600; done" + restart: unless-stopped + +# Define the named volume for the cache +volumes: + autorestic_cache: From 6c1ba18bf28391d726858185fe0b888655b0f379 Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Tue, 18 Nov 2025 02:34:53 -0500 Subject: [PATCH 03/10] simple restic, seems to work --- restic/docker-compose.yml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 restic/docker-compose.yml diff --git a/restic/docker-compose.yml b/restic/docker-compose.yml new file mode 100644 index 0000000..4872b50 --- /dev/null +++ b/restic/docker-compose.yml @@ -0,0 +1,20 @@ +# init with +# docker run --rm -e RESTIC_PASSWORD=yourpassword -v G:/restic-backups:/backup restic/restic init --repo /backup + +services: + restic-backup: + image: restic/restic:latest + container_name: restic-backup + environment: + - RESTIC_REPOSITORY=/backup + - RESTIC_PASSWORD=yourpassword + volumes: + - E:/installers:/data:ro + - G:/restic-backups:/backup + entrypoint: > + sh -c "while true; do + restic backup /data && + restic forget --prune --keep-last 7; + sleep 43200; + done" + restart: unless-stopped From f51a0f47fe42ba058c4f67c9be43a4516dffd2f2 Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Tue, 18 Nov 2025 03:19:04 -0500 Subject: [PATCH 04/10] Add immich-photos to restic --- restic/docker-compose.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/restic/docker-compose.yml b/restic/docker-compose.yml index 4872b50..4f65a8c 100644 --- a/restic/docker-compose.yml +++ b/restic/docker-compose.yml @@ -9,11 +9,13 @@ services: - RESTIC_REPOSITORY=/backup - RESTIC_PASSWORD=yourpassword volumes: - - E:/installers:/data:ro + - E:/installers:/data/installers:ro + - H:/immich-photos:/data/immich-photos:ro - G:/restic-backups:/backup entrypoint: > sh -c "while true; do - restic backup /data && + restic backup /data/installers && + restic backup /data/immich-photos && restic forget --prune --keep-last 7; sleep 43200; done" From 09b7d0bceec6a30943442bc2d05bc158aea7171b Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Wed, 19 Nov 2025 02:35:41 -0500 Subject: [PATCH 05/10] do local and remote backups --- restic/docker-compose.yml | 50 ++++++++++++++++++++++++++++++++------- 1 file changed, 41 insertions(+), 9 deletions(-) diff --git a/restic/docker-compose.yml b/restic/docker-compose.yml index 4f65a8c..47641ee 100644 --- a/restic/docker-compose.yml +++ b/restic/docker-compose.yml @@ -1,4 +1,4 @@ -# init with +# init REPOSITORY 1 with # docker run --rm -e RESTIC_PASSWORD=yourpassword -v G:/restic-backups:/backup restic/restic init --repo /backup services: @@ -6,17 +6,49 @@ services: image: restic/restic:latest container_name: restic-backup environment: - - RESTIC_REPOSITORY=/backup - - RESTIC_PASSWORD=yourpassword + # --- REPOSITORY 1: REMOTE REST SERVER --- + - RESTIC_REPOSITORY_REMOTE=${RESTIC_REPOSITORY_REMOTE} + - RESTIC_PASSWORD_REMOTE=${RESTIC_PASSWORD_REMOTE} + + # --- REPOSITORY 2: LOCAL FOLDER --- + - RESTIC_REPOSITORY_LOCAL=${RESTIC_REPOSITORY_LOCAL} + - RESTIC_PASSWORD_LOCAL=${RESTIC_PASSWORD_LOCAL} + volumes: - - E:/installers:/data/installers:ro + # Data to backup (Read-Only) + - F:/roms/megadrive:/data/roms:ro - H:/immich-photos:/data/immich-photos:ro + + # REPOSITORY 1: Local Backup Folder - G:/restic-backups:/backup + entrypoint: > - sh -c "while true; do - restic backup /data/installers && - restic backup /data/immich-photos && - restic forget --prune --keep-last 7; - sleep 43200; + sh -c "while true; do \ + \ + echo '--- Starting Remote Backup ---' && \ + export RESTIC_REPOSITORY=$RESTIC_REPOSITORY_REMOTE && \ + export RESTIC_PASSWORD=$RESTIC_PASSWORD_REMOTE && \ + restic backup /data/roms && \ + \ + echo '--- Starting Remote Prune ---' && \ + restic forget --prune --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --keep-yearly 0; \ + \ + echo '--- Starting Local Backup ---' && \ + export RESTIC_REPOSITORY=$RESTIC_REPOSITORY_LOCAL && \ + export RESTIC_PASSWORD=$RESTIC_PASSWORD_LOCAL && \ + restic backup /data/roms && \ + \ + echo '--- Starting Local Prune ---' && \ + restic forget --prune --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --keep-yearly 0; \ + \ + echo '--- Cleanup and Sleep ---' && \ + unset RESTIC_REPOSITORY && \ + unset RESTIC_PASSWORD && \ + echo '--- Backup Cycle Complete. Sleeping... ---' && \ + sleep 43200; \ done" + restart: unless-stopped + +# restic backup /data/roms /data/immich-photos && +# restic backup /data/roms /data/immich-photos && From 7298153fc78a26c34ba482535ca1fa9c4a292c2a Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Sun, 11 Jan 2026 17:26:40 -0500 Subject: [PATCH 06/10] Create backup_immich.bat --- immich-app/backup_immich.bat | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 immich-app/backup_immich.bat diff --git a/immich-app/backup_immich.bat b/immich-app/backup_immich.bat new file mode 100644 index 0000000..4907cd2 --- /dev/null +++ b/immich-app/backup_immich.bat @@ -0,0 +1,15 @@ +:: Backup Immich Photos to Islensku +D:\restic\restic_0.18.1_windows_amd64.exe ^ + --password-file=D:\restic\pwd_restic_repo.txt ^ + -r rest:https://backup138.dawsonst.ca/immich-photos-d ^ + backup ^ + D:\immich-photos + +:: Backup Immich Photos to Boss +D:\restic\restic_0.18.1_windows_amd64.exe ^ + --password-file=D:\restic\pwd_restic_repo.txt ^ + -r rest:http://192.168.68.53:7378/immich-photos ^ + backup ^ + D:\immich-photos + +pause From c936c7c645ea84bdf06e304f194099711133c4ab Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Sun, 11 Jan 2026 17:26:59 -0500 Subject: [PATCH 07/10] Sync with nextcloud --- .gitignore | 4 ++++ Desktop.ini | 2 ++ 2 files changed, 6 insertions(+) create mode 100644 Desktop.ini diff --git a/.gitignore b/.gitignore index f436d28..5339293 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,7 @@ swag filebrowser-docker autorestic/config/.autorestic.lock.yml +.nextcloudsync.log +.sync_cd2c53ad47df.db +.sync_cd2c53ad47df.db-shm +.sync_cd2c53ad47df.db-wal diff --git a/Desktop.ini b/Desktop.ini new file mode 100644 index 0000000..a1fd697 --- /dev/null +++ b/Desktop.ini @@ -0,0 +1,2 @@ +[.ShellClassInfo] +IconResource=C:\Program Files\Nextcloud\nextcloud.exe,1 From 291f4adad44e52555373360894720076e5221861 Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Sun, 11 Jan 2026 17:27:30 -0500 Subject: [PATCH 08/10] Upgrade postgres vectorchord to 0.4.3 and rename network --- immich-app/docker-compose.yml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/immich-app/docker-compose.yml b/immich-app/docker-compose.yml index 5a2f78c..cc1fbef 100644 --- a/immich-app/docker-compose.yml +++ b/immich-app/docker-compose.yml @@ -25,7 +25,7 @@ services: ports: - '2283:2283' networks: - - caddy-network + - immich-net depends_on: - redis - database @@ -46,7 +46,7 @@ services: env_file: - .env networks: - - caddy-network + - immich-net restart: always healthcheck: disable: false @@ -57,12 +57,12 @@ services: healthcheck: test: redis-cli ping || exit 1 networks: - - caddy-network + - immich-net restart: always database: container_name: immich_postgres - image: ghcr.io/immich-app/postgres:14-vectorchord0.4.1-pgvectors0.2.0 + image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0 environment: POSTGRES_PASSWORD: ${DB_PASSWORD} POSTGRES_USER: ${DB_USERNAME} @@ -73,14 +73,14 @@ services: volumes: # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file - ${DB_DATA_LOCATION}:/var/lib/postgresql/data + shm_size: 1gb networks: - - caddy-network + - immich-net restart: always networks: - caddy-network: + immich-net: external: true - # driver: bridge volumes: model-cache: From d421392e97e720cc325cbb59de5f49239d744a38 Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Mon, 12 Jan 2026 23:07:31 -0500 Subject: [PATCH 09/10] Create immich-db-dump.sh --- immich-app-islensku/immich-db-dump.sh | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 immich-app-islensku/immich-db-dump.sh diff --git a/immich-app-islensku/immich-db-dump.sh b/immich-app-islensku/immich-db-dump.sh new file mode 100644 index 0000000..5f78667 --- /dev/null +++ b/immich-app-islensku/immich-db-dump.sh @@ -0,0 +1,3 @@ +# This is actually added as a hook to backrest + +docker exec -t immich_postgres pg_dumpall -c -U $DB_USERNAME > /tmp/immich-dump.sql From 2c6dfbdb0952bfb7afa4db3e086abb2a2100f2af Mon Sep 17 00:00:00 2001 From: deceivedhornet Date: Mon, 12 Jan 2026 23:07:46 -0500 Subject: [PATCH 10/10] Disable healthcheck for Unraid --- immich-app/docker-compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/immich-app/docker-compose.yml b/immich-app/docker-compose.yml index cc1fbef..d42187a 100644 --- a/immich-app/docker-compose.yml +++ b/immich-app/docker-compose.yml @@ -31,7 +31,7 @@ services: - database restart: always healthcheck: - disable: false + disable: true immich-machine-learning: container_name: immich_machine_learning